Commission, supported by ENISA, CERT-EU and with the expertise of its Joint Research
Centre, will facilitate the creation and ensure the sustainability of the hub.
In addition, a regular high-level advisory group14 on cybersecurity – composed of experts and
decision-makers from industry, academia, civil society and other relevant organisations –
should be set up at EU level. The group would enable the Commission to get external
expertise and input, in an open and transparent way, for its cybersecurity strategy policies and
on potential regulatory or other public policy actions. It would complement and connect with
other structures on cybersecurity15 .
Moreover, the Commission is required to evaluate ENISA by 20 June 2018 and the possible
modification or renewal of ENISA's mandate must be adopted by 19 June 202016. In view of
the current cybersecurity landscape, the Commission aims to advance the evaluation and,
subject to its results, present a proposal as soon as possible.
When assessing the possible need to change ENISA’s mandate, the Commission will take into
account the cybersecurity challenges described above and the overall effort to step up
cooperation and knowledge sharing. This process will provide an opportunity to look into the
possible enhancement of the Agency’s capabilities and capacities to support Member States in
a sustainable manner in achieving cybersecurity resilience. The reflection on ENISA’s
mandate would furthermore need to take into account the Agency’s new responsibilities under
the NIS Directive, new policy objectives to support cybersecurity industry (the DSM strategy
and in particular the cPPP), evolving needs in securing critical sectors, and new challenges
linked to cross-border incidents, including coordinated response to cyber crises.
The Commission will:
-
submit for consideration a cooperation blueprint to handle large-scale cyber
incidents on the EU level in the first half of 2017;
facilitate the creation of an ‘information hub’ to support the exchange of
information between EU bodies and Member States;
create a high-level advisory group on cybersecurity; and
finalise the evaluation of ENISA by end of 2017. Such evaluation will address the
need to modify or extend the mandate of ENISA, aiming for a possible proposal as
soon as possible.
2.2 Increase efforts in cybersecurity education, training and exercises
Adequate skills and training, related both to preventing cybersecurity incidents and to dealing
with and mitigating their impacts, are some of the key aspects of achieving cybersecurity
resilience.
14
Commission expert groups are subject to the horizontal rules established by Commission decision C(2016)3301.
E.g. the NIS Platform, cPPP on cybersecurity and sectoral platforms such as the Energy Expert Cyber Security Platform (EECSP). It
should also link to the high-level roundtable announced in the Communication on Digitising European Industry: COM(2016) 180.
16
Regulation (EU) No 526/2013 repealing Regulation (EC) No 460/2004.
15
5