COMMUNICATION FROM THE COMMISSION TO THE EUROPEAN
PARLIAMENT, THE COUNCIL, THE EUROPEAN ECONOMIC AND SOCIAL
COMMITTEE AND THE COMMITTEE OF THE REGIONS
on Critical Information Infrastructure Protection
"Protecting Europe from large scale cyber-attacks and disruptions: enhancing
preparedness, security and resilience"
1.
INTRODUCTION
Information and Communication Technologies (ICTs) are increasingly intertwined in our
daily activities. Some of these ICT systems, services, networks and infrastructures (in short,
ICT infrastructures) form a vital part of European economy and society, either providing
essential goods and services or constituting the underpinning platform of other critical
infrastructures. They are typically regarded as critical information infrastructures (CIIs)1 as
their disruption or destruction would have a serious impact on vital societal functions. Recent
examples include the large-scale cyber-attacks targeting Estonia in 2007 and the breaks of
transcontinental cables in 2008.
The World Economic Forum estimated in 2008 that there is a 10 to 20% probability of a
major CII breakdown in the next 10 years, with a potential global economic cost of
approximately 250 billion US$.2
This Communication focuses on prevention, preparedness and awareness and defines a plan
of immediate actions to strengthen the security and resilience of CIIs. This focus is consistent
with the debate launched at the request of the Council and the European Parliament to
addresses the challenges and priorities for network and information security (NIS) policy and
the most appropriate instruments needed at EU level to tackle them. The proposed actions are
also complementary to those to prevent, fight and prosecute criminal and terrorist activities
targeting CIIs and synergetic with current and prospective EU research efforts in the field of
network and information security, as well as with international initiatives in this area.
2.
THE POLICY CONTEXT
This Communication develops the European policy to strengthen the security of and the trust
in the information society. Already in 2005, the Commission3 highlighted the urgent need to
coordinate efforts to build trust and confidence of stakeholders in electronic communications
and services. To this end a strategy for a secure information society4 was adopted in 2006. Its
main elements, including the security and resilience of ICT infrastructures, were endorsed in
Council Resolution 2007/068/01. However, ownership and implementation by stakeholders
appear insufficient. This strategy also strengthens the role, on tactical and operational levels,
1
2
3
4
EN
A definition of CIIs was proposed in COM(2005) 576 final
Global Risks 2008
COM(2005) 229
COM(2006) 251
2
EN