Friday

28th Apr 2017

EU cyber-security legislation on the horizon

The European Commission will propose binding EU legislation before the end of the year to help member states plug huge gaps in their cyber-security defences.

Speaking at a cyber-security debate organised by the Security & Defence Agenda in Brussels on Thursday (10 May), the commission said ill-equipped member states are totally unprepared for future cyber threats.

Dear EUobserver reader

Subscribe now for unrestricted access to EUobserver.

Sign up for 30 days' free trial, no obligation. Full subscription only 15 € / month or 150 € / year.

  1. Unlimited access on desktop and mobile
  2. All premium articles, analysis, commentary and investigations
  3. EUobserver archives

EUobserver is the only independent news media covering EU affairs in Brussels and all 28 member states.

♡ We value your support.

If you already have an account click here to login.

  • Cyber crime generates €388 billion illegal revenue annually worldwide. (Photo: *n3wjack's world in pixels)

"The level of preparedness across the EU is not high-enough," said Antoaneta Angelova-Krasteva, a commission information security network expert. Angelova-Krasteva voiced alarm at the increasing sophistication of threats and their number.

In the past four years, only 10 member states have or put in place or are in the process of developing cyber security strategies. Estonia was the first member state to publish a broad national cyber security strategy in 2008, followed by Finland, Slovakia and the Czech Republic.

In comparison, the United States published theirs in 2003 and it was updated in 2011.

"We are like in the 1940s when people had no idea about the power of the atom," warned Heli Tiirmaa-Klaar, a cyber security adviser at the European External Action Service.

An estimated 1 million viruses are introduced into circulation every year, while cyber-crime income - some €388 billion a year - far outweighs the risk of getting caught.

Among some innovations in member state protocols, security breach notifications - currently issued only in the telecoms industry - may in the future also apply to transport, water, food supply, energy and the financial banking sectors.

Such notifications were originally introduced in 2002 as part of a larger EU directive on privacy and electronic communications.

Digital agenda commissioner Neelie Kroes' spokesperson told EUobserver it is too early to provide details on the legislative proposal. But Kroes has already dropped hints on what such a strategy would look like.

At a speech delivered at a cyber-security Security and Defence Agenda dinner in February, she spoke of obliging private companies to notify authorities of cyber security breaches, incidents or attacks.

Her ideas reflect an MEP vote on Tuesday, calling on the commission to propose an EU framework for the notification of security breaches before the end of the year. Separately, the MEPs claim the EU is too far behind in international cooperation on cyber-security issues.

Meanwhile in Crete, the European network and information security agency (Enisa) aims to play an increasing role.

The agency is broadly tasked with building-up information security within the EU but its five-year mandate is set to expire in September 2013. Earlier this year, the European Parliament's committee on industry, research and energy voted to extend it to another seven years.

“It [cyber-security] is very much down to the individual countries. Different approaches are needed in different locations but we are recommending a common approach and a common bench mark," Enisa's Greame Cooper told EUobserver.

Troels Oerting, who heads the new cyber crime center at the EU's joint police agency Europol, envisions Enisa having a direct role in its work. But contacts did not elaborate on what such role would look like.

A Europol-based cyber centre should be operational early next year, with representatives from Interpol expected to sit on its governing board. For its part, Interpol is expected to launch its own cyber centre in Singapore sometime in 2015, said Oerting.

EU cyber directive 'nearly finished'

The EU executive will release a draft directive on cyber security in 2013, in the latest indication that the bloc is moving towards a harmonised online rulebook.

News in Brief

  1. Vote of no confidence prepared against Spanish PM
  2. Syria to buy Russian anti-missile system
  3. Germany seeks partial burka ban
  4. Libya has no plan to stop migration flows
  5. EU has no evidence of NGO-smuggler collusion in Libya
  6. Poland gets 'final warning' on logging in ancient forest
  7. Commission gives Italy final warning on air pollution
  8. Romania and Slovenia taken to court over environment policies

Stakeholders' Highlights

  1. European Healthy Lifestyle AllianceCharlotte Hornets' Nicolas Batum Tells Kids to "Eat Well, Drink Well, Move!"
  2. ECR GroupSyed Kamall: We Need a New, More Honest Relationship With Turkey
  3. Counter BalanceParliament Sends Strong Signal to the EIB: Time to Act on Climate Change
  4. ACCARisks and Opportunities of Blockchain and Shared Ledgers Technologies in Financial Services
  5. UNICEFRace Against Time to Save Millions of Lives in Yemen
  6. Nordic Council of MinistersDeveloping Independent Russian-Language Media in the Baltic Countries
  7. Swedish EnterprisesReform of the European Electricity Market: Lessons from the Nordics, Brussels 2 May
  8. Malta EU 2017Green Light Given for New EU Regulation to Bolster External Border Checks
  9. Counter BalanceCall for EU Commission to Withdraw Support of Trans-Adriatic Pipeline
  10. ACCAEconomic Confidence at Highest Since 2015
  11. European Federation of Allergy and Airways60%-90% of Your Life Is Spent Indoors. How Does Poor Indoor Air Quality Affect You?
  12. European Gaming and Betting AssociationCJEU Confirms Obligation for a Transparent Licensing Process

Latest News

  1. EP chief faces questions after homophobic 'summit'
  2. EU signals Northern Ireland could join if united with Ireland
  3. One year later: EU right to open Internet still virtual
  4. Rethinking Europe's relationship with Turkey
  5. Mob storms Macedonian parliament
  6. MEPs retain secrecy on office spending
  7. May accuses EU-27 of 'lining up against Britain'
  8. Resurrected Renzi to regain leadership of Italy's ruling party