evolving cyber-threat landscape10. In this context, the EU needs to prepare itself for the possibility of a large-scale cyber crisis11, including for instance simultaneous attacks on critical information systems in several Member States12. EU level cooperation is therefore essential for dealing with both smaller-scale but potentially proliferating cyber incidents, and a possible large-scale cyber-attack in multiple Member States. The EU needs to integrate cyber aspects into existing crisis management mechanisms. It also needs to ensure effective cooperation and swift information-sharing mechanisms among sectors and Member States to respond to, and contain, such incidents. Furthermore, these mechanisms should operate coherently, thus contributing to the fight against terrorism, organised crime and cybercrime. This would also increase the EU’s ability to coordinate with its international partners in responding effectively to global threats and incidents. 2.1. Making the most of NIS cooperation mechanisms and moving towards ENISA 2.0 An essential part of national capabilities required by the NIS Directive are Computer Incident Response Teams (CSIRTs) responsible for rapid reaction to cyber threats and cyber incidents. They will form the CSIRTs Network to promote effective operational cooperation on specific cybersecurity incidents and sharing information about risks. Furthermore, the Directive will create a Cooperation Group to support and facilitate strategic cooperation among Member States and to build trust among them. Given the nature and multitude of cyber threats, the Commission encourages Member States to make the most out of the NIS cooperation mechanisms and to enhance cross-border cooperation related to preparedness for a large-scale cyber incident. Such additional cooperation for a significant cyber incident would benefit from a coordinated approach to crisis cooperation across the various elements of the cyber ecosystem. Such an approach can be set out in a ‘blueprint’ that should also ensure synergies and coherence with existing crisis management mechanisms13. It should then be regularly tested in cyber and other crisis management exercises. It would include a role for EU-level bodies such as ENISA, CERT-EU and the European Cybercrime Centre (EC3) at Europol, and use tools developed in the context of the CSIRTs Network. In the first half of 2017, the Commission will present such a cooperation blueprint for consideration by the Cooperation Group, the CSIRTs Network and other relevant stakeholders. Currently, knowledge and expertise on cybersecurity is available at the EU level, but in a dispersed and unstructured way. To support the NIS cooperation mechanisms, information should be pooled in an ‘information hub’ to make it easily available on request to all Member States. This ‘hub’ would become a central resource allowing the EU institutions and Member States to exchange information as appropriate. Easier access to better structured information on cybersecurity risks and potential remedies should help Member States to increase their capacities and align their practices, and thereby enhance overall resilience to attacks. The 10 See SWD(2016) 216. See e.g. ENISA Report: Common practices of EU-level crisis management and applicability to cyber crises (April 2016). 12 See SWD(2016) 216. 13 Notably the Integrated Political Crisis Response Arrangements including the decision on the arrangements for the implementation by the Union of the solidarity clause (24 July 2014) and the Common Security and Defence Policy decision-making processes. 11 4

Select target paragraph3