III. CYBERSECURITY IN THE EU INSTITUTIONS, BODIES AND AGENCIES Given their high political profile, their critical missions to coordinate highly sensitive issues, and their role in managing large sums of public money, the EU institutions, bodies and agencies are regular targets of cyberattacks, particularly cyber-espionage. However, the level of cyber resilience and ability to detect and respond to malicious cyber activities varies significantly across these entities in terms of maturity. It is thus necessary to improve the overall level of cybersecurity through consistent and homogeneous rules. In the area of information security, progress has been made towards more consistency of the rules for the protection of EU classified information as well as sensitive nonclassified information. However, the interoperability of classified information systems remains limited, preventing a seamless transfer of information between the different entities. Further progress should be made to enable an inter-institutional approach to the handling of EU classified information and sensitive non-classified information, which could also serve as a model for interoperability across Member States. A baseline should also be established to simplify procedures with Member States. The EU should also further develop its ability to communicate in a secure manner with relevant partners, building to the extent possible on existing arrangements and procedures. As announced in the Security Union Strategy, the Commission will therefore make proposals for common binding rules on information security and for common binding rules on cybersecurity for all EU institutions, bodies and agencies in 2021, based on ongoing EU inter-institutional discussions on cybersecurity118. Current and future trends of teleworking will also necessitate further investments in secure equipment, infrastructures and tools that allow to work remotely on sensitive and classified files. In addition, the increasingly hostile cyber threat landscape and the increased incidence of more sophisticated cyberattacks affecting the EU institutions, bodies and agencies drives the need for increased investments to reach a high level of cyber maturity. A Cyber Awareness Programme is being set up for all EU institutions, bodies and agencies to raise staff’s awareness, cyber hygiene and support a common cyber security culture. The reinforcement of CERT-EU with an improved funding mechanism is necessary to increase its ability to help EU institutions, bodies and agencies to apply the new cybersecurity rules, improve their cyber resilience. The mandate of CERT-EU must also be strengthened to provide it with a stable means to meet these objectives. Strategic initiatives 1. Regulation on Information Security in the EU institutions bodies and agencies 2. Regulation on Common Cybersecurity Rules for EU institutions, bodies and agencies 118 A regular EU inter-institutional discussions on cybersecurity form part of wider exchanges on the opportunities and challenges of digital transformation for the EU institutions. 24

Select target paragraph3