III.
CYBERSECURITY IN THE EU INSTITUTIONS, BODIES AND
AGENCIES
Given their high political profile, their critical missions to coordinate highly sensitive issues,
and their role in managing large sums of public money, the EU institutions, bodies and
agencies are regular targets of cyberattacks, particularly cyber-espionage. However, the
level of cyber resilience and ability to detect and respond to malicious cyber activities varies
significantly across these entities in terms of maturity. It is thus necessary to improve the
overall level of cybersecurity through consistent and homogeneous rules.
In the area of information security, progress has been made towards more consistency of
the rules for the protection of EU classified information as well as sensitive nonclassified information. However, the interoperability of classified information systems
remains limited, preventing a seamless transfer of information between the different entities.
Further progress should be made to enable an inter-institutional approach to the handling of
EU classified information and sensitive non-classified information, which could also serve as
a model for interoperability across Member States. A baseline should also be established to
simplify procedures with Member States. The EU should also further develop its ability to
communicate in a secure manner with relevant partners, building to the extent possible on
existing arrangements and procedures.
As announced in the Security Union Strategy, the Commission will therefore make proposals
for common binding rules on information security and for common binding rules on
cybersecurity for all EU institutions, bodies and agencies in 2021, based on ongoing EU
inter-institutional discussions on cybersecurity118.
Current and future trends of teleworking will also necessitate further investments in secure
equipment, infrastructures and tools that allow to work remotely on sensitive and classified
files.
In addition, the increasingly hostile cyber threat landscape and the increased incidence of
more sophisticated cyberattacks affecting the EU institutions, bodies and agencies drives the
need for increased investments to reach a high level of cyber maturity. A Cyber Awareness
Programme is being set up for all EU institutions, bodies and agencies to raise staff’s
awareness, cyber hygiene and support a common cyber security culture.
The reinforcement of CERT-EU with an improved funding mechanism is necessary to
increase its ability to help EU institutions, bodies and agencies to apply the new cybersecurity
rules, improve their cyber resilience. The mandate of CERT-EU must also be strengthened to
provide it with a stable means to meet these objectives.
Strategic initiatives
1. Regulation on Information Security in the EU institutions bodies and agencies
2. Regulation on Common Cybersecurity Rules for EU institutions, bodies and
agencies
118
A regular EU inter-institutional discussions on cybersecurity form part of wider exchanges on the
opportunities and challenges of digital transformation for the EU institutions.
24