The EU coordinated risk assessment report highlights a number of important security challenges
which are likely to appear or become more prominent in 5G networks. These security challenges are
mainly linked to:
-
Increasing security concerns related to the availability and integrity of the networks, in
addition to the confidentiality and privacy concerns;
-
Key innovations in the 5G technology (which will also bring a number of specific security
improvements), in particular the increased important role of software and the wide range of
services and applications enabled by 5G networks; and
-
The role of suppliers in building and operating 5G networks, the complexity of the
interlinkages between suppliers and operators, and the degree of dependency on individual
suppliers.
The report further concludes that these challenges create a new security paradigm, making it
necessary to reassess the current policy and security framework applicable to the sector and its
ecosystem, and making it essential for Member States to take the necessary mitigating measures.
The EU coordinated risk assessment report provides the basis to identify mitigation measures that
can be applied at national and European level.
2. Objectives of the toolbox
The objectives of this toolbox are to identify a possible common set of measures which are able to
mitigate the main cybersecurity risks of 5G networks, as they have been identified in the EU
coordinated risk assessment report, and to provide guidance for the selection of measures which
should be prioritised in mitigation plans at national and at Union level. It does this in order to create
a robust framework of measures with a view to ensure an adequate level of cybersecurity of 5G
networks across the EU and coordinated approaches among Member States.
The EU coordinated risk assessment identifies a number of categories of risks of strategic
importance from an EU perspective illustrated by concrete risk scenarios. These reflect relevant
combinations of vulnerabilities, threats and threat actors and the identified assets.
4