further reinforce the cooperation around the Blueprint architecture and harness the progress
achieved notably within the NIS Cooperation Group and the CyCLONe Network.
This could address two main gaps that currently increase vulnerabilities and create
inefficiencies in the response to cross-border threats and incidents affecting the Union.
Firstly, civilian, diplomatic, law enforcement and defence cybersecurity communities do not
yet have a common space to nurture structured cooperation and facilitate operational and
technical cooperation. Secondly, relevant cybersecurity stakeholders have not yet been able
to tap into the full potential of operational cooperation and mutual assistance within existing
networks and communities. This includes the absence of a platform allowing for operational
cooperation with the private sector. The Unit should improve and accelerate coordination and
allow the EU to face up and respond to large-scale cyber incidents and crises.
The Joint Cyber Unit would not be an additional, standalone body, nor would it affect the
competences and powers of national cybersecurity authorities or EU participants. Rather, the
Unit would act as a backstop where the participants can draw on one another’s support and
expertise, especially in the event that various cyber communities are required to work closely
together. At the same time, recent events show the necessity for the EU to step up its level of
ambition and readiness to face the cyber threats landscape and realities. As part of their
contribution to the JCU, the EU actors (Commission and EU agencies and bodies) will
therefore be ready to increase significantly their resources and capabilities, so as to level up
their preparedness and resilience.
The Joint Cyber Unit would fulfil three main objectives. Firstly, it would ensure
preparedness across cybersecurity communities; secondly, through information sharing it
would provide continuous shared situational awareness; thirdly, it would reinforce
coordinated response and recovery. To achieve these objectives, the Unit should build on
well-defined blocks and goals, such as guaranteeing secure and rapid information
sharing, improving cooperation among participants, including interaction between Member
States and relevant EU entities, establishing structured partnerships with a trusted industry
base and facilitating a coordinated approach to cooperation with external partners. In order
to do so, based on a mapping of available capabilities at national and EU level, the Unit could
facilitate the development of a cooperation framework.
For the Joint Cyber Unit to become the heart of EU cybersecurity operational cooperation,
the Commission will work with Member States and relevant EU institutions, bodies and
agencies, including ENISA, CERT-EU and Europol, to promote an incremental and
inclusive approach, in full respect of competences and mandates of all those involved. In
line with this approach, the Unit could contribute to further cooperation between constituents
of a specific cyber community, where those constituents deem it necessary.
Four main steps are proposed to deliver the Joint Cyber Unit:
Define, by mapping available capabilities at national and EU level;
Prepare, by establishing a framework for structured cooperation and assistance;
Deploy, by implementing the framework drawing on resources provided by
participants so that the Joint Cyber Unit becomes operational;
Expand, by strengthening coordinated response capacity with input from industry and
partners.
14