development lifecycle processes, as well as developing updates and patches to address
previously undiscovered vulnerabilities and fast update and repair.24 This would also increase
consumers' trust in digital products.
Furthermore, the important role of third party security researchers in discovering
vulnerabilities in existing products and services needs to be acknowledged and conditions to
enable coordinated vulnerability disclosure25 should be created across Member States,
building on best practices26 and relevant standards.27
At the same time, specific sectors face specific issues and should be encouraged to develop
their own approach. In this way, general cybersecurity strategies would be complemented by
sector-specific cybersecurity strategies in areas like financial services28, energy, transport and
health.29
The Commission has already highlighted the specific issues concerning liability raised by
new digital technologies30 and work is under way to analyse the implications; next steps will
be concluded by June 2018. Cybersecurity raises issues around the attribution of damage for
businesses and supply chains and failure to address these issues will hamper the development
of a strong single market in cybersecurity products and services.
Finally, the development of the EU single market is also dependent on factoring cybersecurity
into policy on trade and investment. The effect of foreign acquisitions on critical technologies
– of which cybersecurity is an important example – is a key aspect in the framework for the
screening of foreign direct investment in the European Union31, which aims to enable the
screening of investments from third countries on the grounds of security and public order. By
the same token, cybersecurity requirements have already created trade barriers for EU goods
and services in important sectors in a number of third country economies. The EU
cybersecurity certification framework will further strengthen Europe's international position,
and should be complemented by continued efforts towards the development of high-security
global standards and mutual recognition agreements.
2.3
Implementing the Directive on the Security of Network and Information Systems
in full
With the main tools to combat cybersecurity today in national hands, the EU has recognised
the need to drive standards higher. Large-scale cybersecurity incidents rarely affect only one
Member State due to the increasingly globalised, digitally-reliant and interconnected nature of
key sectors such as banking, energy or transport.
24
25
26
27
28
29
30
31
Cybersecurity in the European Digital Single Market, High level group of Scientific Advisors, March 2017
Coordinated vulnerability disclosure is a form of cooperation which facilitates and enables security
researchers to report vulnerabilities to the owner or vendor of the information system, allowing the
organisation the opportunity to diagnose and remedy the vulnerability in a correct and timely fashion before
detailed vulnerability information is disclosed to third parties or the public.
For example Good Practice Guide on Vulnerability Disclosure. From challenges to recommendations,
ENISA, 2016.
ISO/IEC 29147:2014 Information technology -- Security techniques -- Vulnerability disclosure.
The Commission's forthcoming work on financial technology will cover cybersecurity for the financial
sector.
In the energy sector for instance, combining very old and cutting edge information technologies, particularly
with the real-time requirements of the power grid.
COM(2017) 228.
COM(2017) 478.
6