201813. The impact of a cyberattack often cannot be isolated, and can trigger chain reactions throughout the economy and society, affecting millions of individuals14. The investigation of nearly all types of crime has a digital component. In 2019, the number of year-on-year incidents was reported to have trebled. There are an estimated 700 million new samples of malware – the most frequent means of furthering a cyberattack15. The annual cost of cybercrime to the global economy in 2020 is estimated to be €5.5 trillion, double that of 201516. This represents the largest transfer of economic wealth in history, greater than the global drugs trade. For one major incident, the WannaCry ransomware attack in 2017, the cost to the global economy was estimated at over €6.5 billion17. Digital services and the finance sector are among the most frequent targets of cyberattacks, along with the public sector and manufacturing, yet cyber readiness and awareness among businesses and individuals remain low18, and there is a major shortage of cybersecurity skills in the workforce19. There were almost 450 cybersecurity incidents in 2019 involving European critical infrastructures like finance and energy20. Healthcare organisations and professionals have been hit especially hard during the pandemic. As technology becomes inextricable from the physical world, cyberattacks put lives and the wellbeing of the most vulnerable at risk21. Over two-thirds of companies, in particular SMEs, are considered ‘novices’ in cybersecurity, and European companies are considered less well prepared than companies in Asia and America22. An estimated 291 000 posts for cybersecurity professionals in Europe remain unfilled. Hiring and training cybersecurity experts is a slow process leading to greater cybersecurity risks for organisations23. The EU lacks collective situational awareness of cyber threats. This is because national authorities do not systematically gather and share information - such as that available from the private sector - which could help assess the state of cybersecurity in the EU. Only a fraction of incidents are reported by Member States, and information sharing is neither 13 Annual Cost of a Data Breach Report, 2020 Ponemon Institute, and based on quantitative analysis of 524 recent breaches across 17 geographies and 17 industries; https://www.capita.com/sites/g/files/nginej146/files/2020-08/Ponemon-Global-Cost-of-Data-Breach-Study2020.pdf 14 Report from Joint Research Centre (JRC), ‘Cybersecurity, our digital anchor’; https://ec.europa.eu/jrc/en/publication/eur-scientific-and-technical-research-reports/cybersecurity-our-digitalanchor 15 Source: AV-TEST, https://www.av-test.org/en/statistics/malware/ 16 JRC, Cybersecurity – Our Digital Anchor. 17 Source: Cyence. 18 Business awareness remains low also with respect to the cyber-theft of trade secrets, especially among SMEs; PwC, Study on the scale and impact of industrial espionage and theft of trade secrets through cyber: Dissemination report on measures to tackle and prevent cyber-theft of trade secrets, 2018. 19 See ENISA Threat Landscape 2020. Also, Verizon Data Breach Investigations Report 2020; https://enterprise.verizon.com/resources/reports/dbir/ 20 https://ec.europa.eu/eurostat/documents/2995521/10335060/9-13012020-BP-EN.pdf/f1060f2b-b141-b2507f51-85c9704a5a5f 21 Ransomware has been used to target hospitals and health records, e.g. Romania (June 2020), Düsseldorf (September 2020) and Vastaamo (October 2020). 22 PwC, The Global State of Information Security 2018; ESI Thoughtlab, The Cybersecurity Imperative, 2019. 23 EU Agency for Cybersecurity, Cybersecurity Skills Development in the EU: The certification of cybersecurity degrees and ENISA’s Higher Education Database, December 2019. 3

Select target paragraph3