3. WHAT IS AT STAKE 3.1. Critical information infrastructures are vital for the economy and societal growth of the EU The economic and societal role of the ICT sector and ICT infrastructures is highlighted in recent reports on innovation and economic growth. This includes the Communication on i2010 mid-term review16, the Aho Group report17 and the European Union yearly economic reports.18 The OECD underlines the importance of ICTs and the Internet "to boost economic performance and social well-being, and to strengthen societies’ capacity to improve the quality of life for citizens worldwide"19. It further recommends policies that strengthen confidence in the Internet infrastructure. The ICT sector is vital for all segments of society. Businesses rely on the ICT sector both in terms of direct sales and for the efficiency of internal processes. ICTs are a critical component of innovation and are responsible for nearly 40% of productivity growth.20 ICTs are also pervasive for the work of governments and public administrations: the uptake of eGovernment services at all levels, as well as new applications such as innovative solutions related to health, energy and political participation, make the public sector heavily dependent on ICTs. Last, not least, citizens increasingly rely on and use ICTs in their daily activities: strengthening CII security would increase citizens' trust in ICTs, not least thanks to a better protection of personal data and privacy. 3.2. The risks to critical information infrastructures The risks due to man-made attacks, natural disasters or technical failures are often not fully understood and/or sufficiently analysed. Consequently, the level of awareness across stakeholders is insufficient to devise effective safeguards and countermeasures. Cyber-attacks have risen to an unprecedented level of sophistication. Simple experiments are now turning into sophisticated activities performed for profit or political reasons. The recent large scale cyber-attacks on Estonia, Lithuania and Georgia are the most widely covered examples of a general trend. The huge number of viruses, worms and other forms of malware, the expansion of botnets and the continuous rise of spam confirm the severity of the problem.21 The high dependence on CIIs, their cross-border interconnectedness and interdependencies with other infrastructures, as well as the vulnerabilities and threats they face raise the need to address their security and resilience in a systemic perspective as the frontline of defence against failures and attacks. 16 17 18 19 20 21 EN COM(2008) 199 final http://ec.europa.eu/invest-in-research/action/2006_ahogroup_en.htm EU Economy 2007 Review http://ec.europa.eu/economy_finance/publications/publication10130_en.pdf http://www.oecd.org/dataoecd/1/29/40821707.pdf http://epp.eurostat.ec.europa.eu/ - Science and Technology/Information Society COM(2006) 688 final 4 EN

Select target paragraph3