1. Introduction According to Europol`s 2016 Internet Organised Crime Threat Assessment (IOCTA), cybercrime is becoming more aggressive and confrontational. This can be seen in various forms of cybercrime, including attacks against information systems1. Some serious forms of attacks that Europol mentions are the use of malicious software and social engineering to infiltrate and gain control over an information system or to intercept communications and the launch of wide-scale network attacks, including on critical infrastructure. These attacks are identified as key threats to our society. With more and more information stored in clouds and information and criminals now highly mobile, cross-border cooperation between law enforcement authorities has become crucial for most cybercrime investigations. To fight these crimes effectively, Member States need to commonly define what acts should be considered attacks against information systems. They also need to have approximated levels of sanctions and the operational means to report offences and exchange information between authorities. Accordingly, on 12 August 2013, the European Parliament and the Council adopted Directive 2013/40/EU (the 'Directive') on attacks against information systems and replacing Council Framework Decision 2005/222/JHA.2 1.1. Objectives and scope of the Directive The objectives of the Directive are to approximate the criminal law of the Member States3 in the area of attacks against information systems and to improve cooperation between competent authorities. This is done by establishing minimum rules concerning the definition of criminal offences and sanctions in the area of attacks against information systems and by requiring operational 24/7 points of contact. On the definition of relevant terms, the Directive refers to:    1 2 3 4 An 'information system' in Article 2(a)4. The definition is close to the definition of a computer system as provided by Article 1(a) of the Council of Europe Convention on Cybercrime of 23 November 2001 (the 'Budapest Convention'), with the exception that the Directive also explicitly covers computer data itself. 'Computer data' in Article 2(b). The definition follows the one of Article 1(b) of the Budapest Convention, referring to an information system instead of a computer system. A 'legal person' in Article 2(c). The definition aims to ensure liability of both natural and legal persons while excluding States, public bodies or public international organisations. Europol, 2016 Internet Organised Crime Threat Assessment (IOCTA), available at https://www.europol.europa.eu/sites/default/files/documents/europol_iocta_web_2016.pdf. http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=OJ:L:2013:218:0008:0014:en:pdf. From this point onwards and unless explicitly indicated differently, ‘Member States’ or ‘all Member States’ refer to the Member States bound by the Directive, i.e. all EU Member States except Denmark, which did not take part in the Directive's adoption, in accordance with Articles 1 and 2 of the Protocol on the position of Denmark annexed to the Treaty on the European Union and to the Treaty on the Functioning of the European Union (TFEU). In accordance with Article 3 of Protocol 21 on the position of the United Kingdom and Ireland, both took part in the Directive's adoption and are bound by it. All Articles mentioned refer to those of the Directive unless indicated otherwise. 3

Select target paragraph3