Cyber Situation Centre The planned Cyber Situation Centre will be responsible for tackling major cyber incidents in the public administration as well as for special crisis and disaster situations at national level. The services of the Austrian Federal Army (Österreichisches Bundesheer/ÖBH) will round off the activities of the Cyber Situation Centre. In “normal operations”, the Cyber Situation Centre prepares public and nonpublic analyses on network security in Austria and is responsible for simulations and reporting. Early warning is one major task of the Cyber Situation Centre. The capacity for forensic activities will be created to support enterprises on request. It is therefore necessary to monitor the situation 24 hours a day, 7 days a week (24/7) to ensure that clients, notably critical infrastructures (also usually operating 24/7) obtain the required information on time. The networks of public administration and critical infrastructures are equipped with sensors in order to gather securityrelevant information in real time. Networks without such sensor systems will be obliged to report cyber anomalies (to be defined). The legal framework will need to be analysed and adapted as a first step. Legal provisions have to be adopted defining the responsibilities and powers of Cyber Situation Centres, their reporting duties and requirements concerning data disclosure. Stakeholders playing similar roles are to be involved in the organisation of Cyber Situation Centres. Strategic and organisational decisions must be taken jointly by a Situation Council together with the most important public cyber security stakeholders. The involvement of private stakeholders is highly recommended. The main recipients of services provided by Cyber Situation Centres are various bodies of the public administration and critical infrastructure enterprises. Objective 2: Networking of stakeholders and structures Hypothesis: Cyber security is important where ICT systems are connected to the Internet—and this means practically everywhere since connected digital devices are used directly or indirectly in our information society. Unfortunately such digital omnipresence also provides a fertile breeding ground for all kinds of criminal wheeling and dealing. The establishment of networks among all stakeholders and cyber structures is essential in order to react fast after the occurrence of harmful incidents, or to disseminate the lessons learned after overcoming harmful incidents. Only by establishing a tightly knit network of contacts between stakeholders will Austria be able to benefit from robust cyber security structures. Strategic objective: Incentives, support measures and a legal basis must be created to promote densely knit networks between Austrian cyber security stakeholders and structures. The aim is to establish an automated cyber networking procedure so as to promote a comprehensive and self-learning cyber security culture in Austria based on information-exchanging control loops. Measures Promoting existing and new networks between stakeholders and structures in Austria: Fostering networking between stakeholders—within cyber activity areas by means of focused expert meetings; beyond the boundaries of activity areas (sensitisation, education, research and development, security prevention, emergency and crisis management, public information and criminal prosecution) and across sectors (public administration, economy, universities, interest representations, citizens). Exchanges between cyber security stakeholders with representatives of sectors with only indirect or no cyber security responsibility must be 11

Select target paragraph3