L 218/10
EN
Official Journal of the European Union
(18)
Cyber attacks could be facilitated by various circum
stances, such as where the offender has access to
security systems inherent in the affected information
systems within the scope of his or her employment. In
the context of national law, such circumstances should
be taken into account in the course of criminal
proceedings as appropriate.
(19)
Member States should provide for aggravating circum
stances in their national law in accordance with the
applicable rules established by their legal systems on
aggravating circumstances. They should ensure that
those aggravating circumstances are available for judges
to consider when sentencing offenders. It remains within
the discretion of the judge to assess those circumstances
together with the other facts of the particular case.
(20)
This Directive does not govern conditions for exercising
jurisdiction over any of the offences referred to herein,
such as a report by the victim in the place where the
offence was committed, a denunciation from the State of
the place where the offence was committed, or the nonprosecution of the offender in the place where the
offence was committed.
(21)
In the context of this Directive, States and public bodies
remain fully bound to guarantee respect for human rights
and fundamental freedoms, in accordance with existing
international obligations.
(22)
This Directive strengthens the importance of networks,
such as the G8 or the Council of Europe’s network of
points of contact available on a 24 hour, seven-day-aweek basis. Those points of contact should be able to
deliver effective assistance thus, for example, facilitating
the exchange of relevant information available and the
provision of technical advice or legal information for the
purpose of investigations or proceedings concerning
criminal offences relating to information systems and
associated data involving the requesting Member State.
In order to ensure the smooth operation of the
networks, each contact point should have the capacity
to communicate with the point of contact of another
Member State on an expedited basis with the support,
inter alia, of trained and equipped personnel. Given the
speed with which large-scale cyber attacks can be carried
out, Member States should be able to respond promptly
to urgent requests from this network of contact points.
In such cases, it may be expedient that the request for
information be accompanied by telephone contact in
order to ensure that the request is processed swiftly by
the requested Member State and that feedback is
provided within eight hours.
(23)
Cooperation between public authorities on the one hand,
and the private sector and civil society on the other, is of
14.8.2013
great importance in preventing and combating attacks
against information systems. It is necessary to foster
and improve cooperation between service providers,
producers, law enforcement bodies and judicial auth
orities, while fully respecting the rule of law. Such
cooperation could include support by service providers
in helping to preserve potential evidence, in providing
elements helping to identify offenders and, as a last
resort, in shutting down, completely or partially, in
accordance with national law and practice, information
systems or functions that have been compromised or
used for illegal purposes. Member States should also
consider setting up cooperation and partnership
networks with service providers and producers for the
exchange of information in relation to the offences
within the scope of this Directive.
(24)
There is a need to collect comparable data on the
offences laid down in this Directive. Relevant data
should be made available to the competent specialised
Union agencies and bodies, such as Europol and
ENISA, in line with their tasks and information needs,
in order to gain a more complete picture of the problem
of cybercrime and network and information security at
Union level and thereby to contribute to formulating a
more effective response. Member States should submit
information on the modus operandi of the offenders to
Europol and its European Cybercrime Centre for the
purpose of conducting threat assessments and strategic
analyses of cybercrime in accordance with Council
Decision 2009/371/JHA of 6 April 2009 establishing
the European Police Office (Europol) (1). Providing
information can facilitate a better understanding of
present and future threats and thus contribute to more
appropriate and targeted decision-making on combating
and preventing attacks against information systems.
(25)
The Commission should submit a report on the appli
cation of this Directive and make necessary legislative
proposals which could lead to broadening its scope,
taking into account developments in the field of cyber
crime. Such developments could include technological
developments, for example those enabling more
effective enforcement in the area of attacks against
information systems or facilitating prevention or mini
mising the impact of such attacks. For that purpose,
the Commission should take into account the available
analyses and reports produced by relevant actors and, in
particular, Europol and ENISA.
(26)
In order to fight cybercrime effectively, it is necessary to
increase the resilience of information systems by taking
appropriate measures to protect them more effectively
against cyber attacks. Member States should take the
necessary measures to protect their critical infrastructure
from cyber attacks, as part of which they should consider
the protection of their information systems and
associated data. Ensuring an adequate level of protection
(1) OJ L 121, 15.5.2009, p. 37.