evolving cyber-threat landscape10. In this context, the EU needs to prepare itself for the
possibility of a large-scale cyber crisis11, including for instance simultaneous attacks on
critical information systems in several Member States12.
EU level cooperation is therefore essential for dealing with both smaller-scale but potentially
proliferating cyber incidents, and a possible large-scale cyber-attack in multiple Member
States. The EU needs to integrate cyber aspects into existing crisis management mechanisms.
It also needs to ensure effective cooperation and swift information-sharing mechanisms
among sectors and Member States to respond to, and contain, such incidents. Furthermore,
these mechanisms should operate coherently, thus contributing to the fight against terrorism,
organised crime and cybercrime. This would also increase the EU’s ability to coordinate with
its international partners in responding effectively to global threats and incidents.
2.1. Making the most of NIS cooperation mechanisms and moving towards ENISA 2.0
An essential part of national capabilities required by the NIS Directive are Computer Incident
Response Teams (CSIRTs) responsible for rapid reaction to cyber threats and cyber incidents.
They will form the CSIRTs Network to promote effective operational cooperation on specific
cybersecurity incidents and sharing information about risks. Furthermore, the Directive will
create a Cooperation Group to support and facilitate strategic cooperation among Member
States and to build trust among them.
Given the nature and multitude of cyber threats, the Commission encourages Member States
to make the most out of the NIS cooperation mechanisms and to enhance cross-border
cooperation related to preparedness for a large-scale cyber incident. Such additional
cooperation for a significant cyber incident would benefit from a coordinated approach to
crisis cooperation across the various elements of the cyber ecosystem. Such an approach can
be set out in a ‘blueprint’ that should also ensure synergies and coherence with existing crisis
management mechanisms13. It should then be regularly tested in cyber and other crisis
management exercises. It would include a role for EU-level bodies such as ENISA, CERT-EU
and the European Cybercrime Centre (EC3) at Europol, and use tools developed in the context
of the CSIRTs Network. In the first half of 2017, the Commission will present such a
cooperation blueprint for consideration by the Cooperation Group, the CSIRTs Network and
other relevant stakeholders.
Currently, knowledge and expertise on cybersecurity is available at the EU level, but in a
dispersed and unstructured way. To support the NIS cooperation mechanisms, information
should be pooled in an ‘information hub’ to make it easily available on request to all Member
States. This ‘hub’ would become a central resource allowing the EU institutions and Member
States to exchange information as appropriate. Easier access to better structured information
on cybersecurity risks and potential remedies should help Member States to increase their
capacities and align their practices, and thereby enhance overall resilience to attacks. The
10
See SWD(2016) 216.
See e.g. ENISA Report: Common practices of EU-level crisis management and applicability to cyber crises (April 2016).
12
See SWD(2016) 216.
13
Notably the Integrated Political Crisis Response Arrangements including the decision on the arrangements for the implementation by the
Union of the solidarity clause (24 July 2014) and the Common Security and Defence Policy decision-making processes.
11
4