Building on the outcome of the consultation with Member States, EU institutions, bodies and
agencies77, the Commission, with the involvement of the High Representative, in line with his
competences, will by February 2021 present the process, milestones and timeline for
defining, preparing, deploying and expanding the Joint Cyber Unit.
2.2
Tackling cybercrime
Our dependence on online tools has exponentially increased the attack surface for cyber
criminals, and led to a situation where the investigation of nearly all types of crime has a
digital component. Furthermore, core parts of our society are threatened by cyber actors and
by those using cyber tools to plan and execute their illegal actions. There are therefore close
links to the EU’s overall security policy, as reflected in the cyber elements in its 2020
Security Union Strategy and in the EU’s Counter-Terrorism Agenda78.
Tackling cybercrime effectively is a key factor in ensuring cybersecurity: deterrence cannot
be achieved through resilience alone but also requires identification and prosecution of
offenders. It is therefore essential to foster the cooperation and exchange between
cybersecurity actors and law enforcement. At EU level, therefore, Europol and ENISA have
already built strong cooperation where they have organised joint conferences and workshops
and provided joint reports to the Commission, Member States and other stakeholders on
cybersecurity threats and technological challenges. The Commission will continue to support
this integrated approach to ensure a coherent and effective response, based on a
comprehensive information picture.
As one important element of that response, EU and national authorities need to expand and
improve the capacity of law enforcement to investigate cybercrime, fully respecting
fundamental rights and pursuing the required balance between various rights and interests.
The EU should be able to tackle cybercrime through fully implemented legislation that is fitfor-purpose, with a particular focus on combating child sexual abuse online, and on digital
investigations, including criminality on the ‘darknet’. Law enforcement must be fully
equipped for digital investigations. The Commission will therefore put forward an action plan
to improve digital capacity for law enforcement agencies, by providing them with the
necessary skills and tools. In addition, Europol will further develop its role as a centre of
expertise to support national law enforcement authorities combatting cyber-enabled and
cyber-dependent crime, contributing to the definition of common forensic standards (through
Europol’s Innovation Lab and Hub).All these activities require appropriate take-up by
Member States, which are encouraged to make use of the Internal Security Fund’s national
programmes and to propose projects in response to calls for proposals as part of the Thematic
Facility.
The Commission will use all appropriate means, including infringement proceedings, to
ensure that the 2013 Directive on attacks against information systems 79 is fully transposed
and implemented, including the provision of statistics by Member States. It will better
prevent the abuse of domain names, including where appropriate for the distribution of illegal
77
Consultation of Member States (including during the Blue OLEx20 exercise gathering the heads of national
cybersecurity authorities), EU institutions, bodies and agencies conducted between July-November 2020.
78
Communication A Counter-Terrorism Agenda for the EU: Anticipate, Prevent, Protect, Respond, 9.12.2020,
COM(2020) 795 final..
79
Directive 2013/40/EU on attacks against information systems.
15