Thursday

21st Sep 2023

Opinion

On cybersecurity, Europe must act now

  • Estonia managed to keep the impact of WannaCry to almost zero by a large-scale targeted campaign in cooperation with the private sector (Photo: Blogtrepreneur)

A spectre is haunting the world – the cyber spectre.

This menace can reveal itself under different faces, taking the form of criminality, terrorism or state-sponsored activity – often using several faces together and masking its true intentions.

Read and decide

Join EUobserver today

Become an expert on Europe

Get instant access to all articles — and 20 years of archives. 14-day free trial.

... or subscribe as a group

Over 200,000 victims in more than 150 countries across the globe were hit last year by Wannacry, probably the most significant cyber attack to date.

Among them were large corporations such as Telefonica and hospitals in the UK, which had to cancel or delay medical procedures.

The NotPetya attack a month later is estimated to have cost companies more than $1.2bn (€975,000). We have seen election campaign hacks in 2016 and 2017 where attacks were used to delegitimise the electoral process or cast a shadow over elected representatives.

By now it is becoming clear that the threats cyber attacks pose are real. Luckily, while cyber threats may be inevitable, their paralysing impact is not.

But fighting them is new for us.

Some governments have closed their eyes, hoping that the menace will go away. It will not. It will only become stronger.

No borders

Other governments are more diligent, creating their own ways and institutions for response. Unfortunately the spectre does not recognise borders, which is why the NotPetya, that seemed first to be targeting primarily Ukraine, spread fast and closed businesses in Estonia while the systems that caused this were located in France.

We can win this war only if we stand united. NATO has by now officially recognised cyberspace as a domain of operations, confirming that a cyberattack on any of its allies will be considered an act of war. But cyber threats are significantly larger than military, often fought by non-military means.

The former Estonian president Toomas Hendrik Ilves, whose country in 2007 witnessed one of the first massive cyber attacks in the world, recently made a proposal to create a worldwide alliance to fight cyber threats.

A timely proposal, but realising it can take more time than we actually have.

We must act immediately, using existing structures and, where necessary, taking a step further. Europe has become a major player in fighting cyber threats.

The EU solidarity clause is valid in the case of a cyber attack, too, not only in the case of conventional threats. Luckily, today in EU we do no longer lack the tools, we just have to be able to use them.

EU response

In September, the Commission published the renewed EU cyber security strategy.

The Estonian presidency in the council acted quickly upon the commission's proposals and adopted council conclusions in November, followed by adoption of the concrete action plan to implement the EU cybersecurity strategy in December.

For us to be able to convincingly deter cyber threats, the EU agreed last year on its framework that will allow to use all EU common foreign policy tools as a response to cyber attacks – from diplomatic demarches to economic sanctions.

Now the politicians of Europe must be ready to use it. But experience and understanding of cyber threats among various member states are too different.

What for some is everyday reality seems to others like a fantasy from another world. We do not have time to wait for everybody to get on board, we must act now.

In the EU, this action can be taken, if needed, in the form of enhanced cooperation.

It is a procedure where a minimum of nine member states are allowed to establish advanced integration or cooperation inside the EU.

One may argue that the EU´s recently established Permanent Structured Defence Cooperation (Pesco) should provide a suitable platform for stepping up cyber defence cooperation as well.

But although there are two cyber-related projects among the initial list of projects under Pesco, the whole area of cyber security is so much broader and brings together so many civilian elements that cooperation under Pesco will never be enough.

For core challenges, enhanced cooperation would allow the participating countries to put in place rules for decreasing possibilities of cyber attacks, such as exchanging information more actively, widening the NIS directive list of essential services to areas protecting our way of life, such as democratic elections and government systems.

This would allow the member states to coordinate common responses to possible attacks and, importantly, attribute the attacks to perpetrators.

Cyber 'hygiene'

Member states could launch an investment program to R&D centres, which provide for solutions in cyber security and massive cyber education programs not only for experts but also for the general public, raising awareness in cyber hygiene.

By following simple rules, we can significantly decrease the risks of becoming a target of future attacks.

The Wannacry attack could easily have been avoided by basic security practices, such as replacing outdated software and installing critical updates.

Estonia managed to keep the impact of WannaCry to almost zero by a large-scale targeted campaign in cooperation with private sector, asking people to stop using the obsolete system containing a critical vulnerability.

From enhanced cooperation, we could take the next move: forming a cyber defence alliance, including members from other parts of the world, as cyber threats recognise no borders.

With such steps, Europe can lead the fight for the future. In the past, Europe has always been successful when it succeeded in seeing current problems as opportunities for the future.

A similar opportunity is now open for us.

Mart Laar is a former Estonian prime minister (1992-1994 and 1999-2002)

Disclaimer

The views expressed in this opinion piece are the author's, not those of EUobserver.

EU to beef up cybersecurity agency

The Commission's president proposed to set up a European Cybersecurity Agency. The EU already has an agency for Network and Information Security.

Cybersecurity and defence for the future of Europe

Cybersecurity is a core element of Europe's strategy to become a global leader in digital technologies and a secure place for its citizens, write EU commissioner Jyrki Katainen and expert Jarno Limnell.

It's time we lost our 'cyber-naivety'

You wouldn't leave a box of your most prized possessions and private information in an unlocked box in the middle of the street, so why are so many people casual about their online information?

Latest News

  1. Europe must Trump-proof its Ukraine arms supplies
  2. Antifascism and fascism are opposites, whatever elites say
  3. MEPs back Germany's Buch to lead ECB supervisory arm
  4. Russia to blame for Azerbaijan attack, EU says
  5. Fresh dispute may delay EU-wide migration reforms
  6. MEPs call for extra €10bn to boost EU's long-term budget
  7. No changes to Turkey deal on Nato, Sweden says
  8. Socialist MEP defends own side jobs after voting to ban others

Stakeholders' Highlights

  1. International Medical Devices Regulators Forum (IMDRF)Join regulators, industry & healthcare experts at the 24th IMDRF session, September 25-26, Berlin. Register by 20 Sept to join in person or online.
  2. UNOPSUNOPS begins works under EU-funded project to repair schools in Ukraine
  3. Georgia Ministry of Foreign AffairsGeorgia effectively prevents sanctions evasion against Russia – confirm EU, UK, USA
  4. International Medical Devices Regulators Forum (IMDRF)Join regulators & industry experts at the 24th IMDRF session- Berlin September 25-26. Register early for discounted hotel rates
  5. Nordic Council of MinistersGlobal interest in the new Nordic Nutrition Recommendations – here are the speakers for the launch
  6. Nordic Council of Ministers20 June: Launch of the new Nordic Nutrition Recommendations

Stakeholders' Highlights

  1. International Sustainable Finance CentreJoin CEE Sustainable Finance Summit, 15 – 19 May 2023, high-level event for finance & business
  2. ICLEISeven actionable measures to make food procurement in Europe more sustainable
  3. World BankWorld Bank Report Highlights Role of Human Development for a Successful Green Transition in Europe
  4. Nordic Council of MinistersNordic summit to step up the fight against food loss and waste
  5. Nordic Council of MinistersThink-tank: Strengthen co-operation around tech giants’ influence in the Nordics
  6. EFBWWEFBWW calls for the EC to stop exploitation in subcontracting chains

Join EUobserver

Support quality EU news

Join us