for the private sector to invest in the protection of CIIs at the level that governments would
normally demand.
To address this governance problem public-private partnerships (PPPs) have emerged at the
national level as the reference model. However, despite the consensus that PPPs would also
be desirable on a European level, European PPPs have not materialised so far. A Europe-wide
multi-stakeholder governance framework, which may include an enhanced role of ENISA,
could foster the involvement of the private sector in the definition of strategic public policy
objectives as well as operational priorities and measures. This framework would bridge the
gap between national policy-making and operational reality on the ground.
3.4.3.
Limited European early warning and incident response capability
Governance mechanisms will be truly effective only if all participants have reliable
information to act upon. This is particularly relevant for governments that have the ultimate
responsibility to ensure the security and well-being of citizens.
However, processes and practices for monitoring and reporting network security incidents
differ significantly across Member States. Some do not have a reference organisation as a
monitoring point. More importantly, cooperation and information sharing between Member
States of reliable and actionable data on security incidents appears underdeveloped, being
either informal or limited to bilateral or limitedly multilateral exchanges. In addition,
simulating incidents and running exercises to test response capabilities are strategic in
enhancing the security and resilience of CIIs, in particular by focusing on flexible strategies
and processes for dealing with the unpredictability of potential crises. In the EU, cybersecurity exercises are still in an embryonic state. Exercises running across national boundaries
are very limited. As recent events23 showed, mutual aid is an essential element of a proper
response to large-scale threats and attacks to CIIs.
A strong European early warning and incident response capability has to rely on wellfunctioning National/Governmental Computer Emergency Response Teams (CERTs), i.e.
having a common baseline in terms of capabilities. These bodies need to act as national
catalysers of stakeholders' interests and capacity for public policy activities (including those
related to information and alert sharing systems reaching out to citizens and SMEs) and to
engage in effective cross-border cooperation and information exchange, possibly leveraging
existing organisations such as the European Governmental CERTs Group (EGC).24
3.4.4.
International cooperation
The rise of the Internet as a key CII requires particular attention to its resilience and stability.
The Internet, thanks to its distributed, redundant design has proven to be a very robust
infrastructure. However, its phenomenal growth produced a rising physical and logical
complexity and the emergence of new services and uses: it is fair to question the capability of
the Internet to withstand the rising number of disruptions and cyber-attacks.
The divergence of views on the criticality of the elements making up the Internet partly
explains the diversity of governmental positions expressed in international fora and the often
contradicting perceptions of the importance of this matter. This could hinder a proper
23
24
EN
http://ec.europa.eu/information_society/policy/nis/strategy/activities/ciip/large_scale/
http://www.egc-group.org/
6
EN