1. Introduction
According to Europol`s 2016 Internet Organised Crime Threat Assessment (IOCTA),
cybercrime is becoming more aggressive and confrontational. This can be seen in various
forms of cybercrime, including attacks against information systems1. Some serious forms of
attacks that Europol mentions are the use of malicious software and social engineering to
infiltrate and gain control over an information system or to intercept communications and the
launch of wide-scale network attacks, including on critical infrastructure. These attacks are
identified as key threats to our society.
With more and more information stored in clouds and information and criminals now highly
mobile, cross-border cooperation between law enforcement authorities has become crucial for
most cybercrime investigations.
To fight these crimes effectively, Member States need to commonly define what acts should
be considered attacks against information systems. They also need to have approximated
levels of sanctions and the operational means to report offences and exchange information
between authorities. Accordingly, on 12 August 2013, the European Parliament and the
Council adopted Directive 2013/40/EU (the 'Directive') on attacks against information
systems and replacing Council Framework Decision 2005/222/JHA.2
1.1. Objectives and scope of the Directive
The objectives of the Directive are to approximate the criminal law of the Member States3 in
the area of attacks against information systems and to improve cooperation between
competent authorities. This is done by establishing minimum rules concerning the definition
of criminal offences and sanctions in the area of attacks against information systems and by
requiring operational 24/7 points of contact.
On the definition of relevant terms, the Directive refers to:
1
2
3
4
An 'information system' in Article 2(a)4. The definition is close to the definition of a
computer system as provided by Article 1(a) of the Council of Europe Convention on
Cybercrime of 23 November 2001 (the 'Budapest Convention'), with the exception that
the Directive also explicitly covers computer data itself.
'Computer data' in Article 2(b). The definition follows the one of Article 1(b) of the
Budapest Convention, referring to an information system instead of a computer
system.
A 'legal person' in Article 2(c). The definition aims to ensure liability of both natural
and legal persons while excluding States, public bodies or public international
organisations.
Europol, 2016 Internet Organised Crime Threat Assessment (IOCTA), available at
https://www.europol.europa.eu/sites/default/files/documents/europol_iocta_web_2016.pdf.
http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=OJ:L:2013:218:0008:0014:en:pdf.
From this point onwards and unless explicitly indicated differently, ‘Member States’ or ‘all Member States’
refer to the Member States bound by the Directive, i.e. all EU Member States except Denmark, which did not
take part in the Directive's adoption, in accordance with Articles 1 and 2 of the Protocol on the position of
Denmark annexed to the Treaty on the European Union and to the Treaty on the Functioning of the European
Union (TFEU). In accordance with Article 3 of Protocol 21 on the position of the United Kingdom and
Ireland, both took part in the Directive's adoption and are bound by it.
All Articles mentioned refer to those of the Directive unless indicated otherwise.
3