development lifecycle processes, as well as developing updates and patches to address previously undiscovered vulnerabilities and fast update and repair.24 This would also increase consumers' trust in digital products. Furthermore, the important role of third party security researchers in discovering vulnerabilities in existing products and services needs to be acknowledged and conditions to enable coordinated vulnerability disclosure25 should be created across Member States, building on best practices26 and relevant standards.27 At the same time, specific sectors face specific issues and should be encouraged to develop their own approach. In this way, general cybersecurity strategies would be complemented by sector-specific cybersecurity strategies in areas like financial services28, energy, transport and health.29 The Commission has already highlighted the specific issues concerning liability raised by new digital technologies30 and work is under way to analyse the implications; next steps will be concluded by June 2018. Cybersecurity raises issues around the attribution of damage for businesses and supply chains and failure to address these issues will hamper the development of a strong single market in cybersecurity products and services. Finally, the development of the EU single market is also dependent on factoring cybersecurity into policy on trade and investment. The effect of foreign acquisitions on critical technologies – of which cybersecurity is an important example – is a key aspect in the framework for the screening of foreign direct investment in the European Union31, which aims to enable the screening of investments from third countries on the grounds of security and public order. By the same token, cybersecurity requirements have already created trade barriers for EU goods and services in important sectors in a number of third country economies. The EU cybersecurity certification framework will further strengthen Europe's international position, and should be complemented by continued efforts towards the development of high-security global standards and mutual recognition agreements. 2.3 Implementing the Directive on the Security of Network and Information Systems in full With the main tools to combat cybersecurity today in national hands, the EU has recognised the need to drive standards higher. Large-scale cybersecurity incidents rarely affect only one Member State due to the increasingly globalised, digitally-reliant and interconnected nature of key sectors such as banking, energy or transport. 24 25 26 27 28 29 30 31 Cybersecurity in the European Digital Single Market, High level group of Scientific Advisors, March 2017 Coordinated vulnerability disclosure is a form of cooperation which facilitates and enables security researchers to report vulnerabilities to the owner or vendor of the information system, allowing the organisation the opportunity to diagnose and remedy the vulnerability in a correct and timely fashion before detailed vulnerability information is disclosed to third parties or the public. For example Good Practice Guide on Vulnerability Disclosure. From challenges to recommendations, ENISA, 2016. ISO/IEC 29147:2014 Information technology -- Security techniques -- Vulnerability disclosure. The Commission's forthcoming work on financial technology will cover cybersecurity for the financial sector. In the energy sector for instance, combining very old and cutting edge information technologies, particularly with the real-time requirements of the power grid. COM(2017) 228. COM(2017) 478. 6

Select target paragraph3