recognising the economic cost in the European semester), legislation, and funding programmes. Actions: - Extending the work of the EU Policy Cycle to neighbouring countries; Reviewing possible measures for non-conviction based confiscation; Reviewing legislation on firearms with proposals in 2016; Adopting a post-2016 strategy on human trafficking; Launching joint actions and cooperation strategies with key third countries to combat smuggling of migrants; Reviewing existing policy and legislation on environmental crime, for proposals in 2016. 3.3 Fighting cybercrime Cybersecurity is the first line of defence against cybercrime. The 2013 EU Cybersecurity Strategy focuses on identifying high-risk areas, working with the private sector to close loopholes, and providing specialised training. An important element in implementing the Strategy will be the swift adoption of the proposal for a Directive on network and information security.38 The implementation of this Directive would not only promote better cooperation between law enforcement and cybersecurity authorities, but also provide for cyber-security capacity building of competent Member States' authorities and cross-border incident notification. The EU Agency for Network and Information Security also contributes to the EU's response to cybersecurity issues by working towards a high level of network and information security. Ensuring full implementation of existing EU legislation is the first step in confronting cybercrime. The 2013 Directive39 on attacks against information systems criminalises the use of tools such as malicious software and strengthens the framework for information exchange on attacks. The 2011 Directive40 on child sexual exploitation approximates national legislation to prevent child sexual abuse online. The Commission is working with the Member States to ensure correct implementation of these Directives. Rules also have to be kept up to date. Citizens are concerned about issues like payment fraud. However, the 2001 framework decision combating fraud and counterfeiting of non-cash means of payments41 no longer reflects today’s realities and new challenges such as virtual currencies and mobile payment. The Commission will assess the level of implementation of the current legislation, consult relevant stakeholders and assess the need for further measures. Cybercrime is by its nature borderless, flexible and innovative. In prevention, detection and prosecution, law enforcement has to be able to match and anticipate the ingenuity of the criminals. Cyber criminality requires competent judicial authorities to rethink the way they cooperate within their jurisdiction and applicable law to ensure swifter cross-border access to evidence and information, taking into account current and future technological developments such as cloud computing and Internet of Things. Gathering electronic evidence in real time from other jurisdictions on issues like owners of IP addresses or other e-evidence, and ensuring its admissibility in court, are key issues. It also requires 38 39 40 41 COM(2013) 48 final of 7.2.2013. Directive 2013/40/EU of 12.8.2013. Directive 2011/92/EU of 13.12.2011. Council Framework Decision 2001/413/JHA of 28.5.2001. 19

Select target paragraph3