2024 Report on the State of the Cybersecurity in the Union
CONTACT
For contacting the authors please use security-index@enisa.europa.eu For media enquiries about this paper, please use press@enisa.europa.eu.
AUTHORS
ENISA
ACKNOWLEDGEMENTS
We would like to thank the NIS Cooperation Group and the European Commission for their invaluable feed-back, review and engaged cooperation.
LEGAL NOTICE
This publication represents the views and interpretations of ENISA, unless stated otherwise. It does not endorse a regulatory obligation of ENISA or of ENISA bodies pursuant to the Regulation (EU) No 2019/881. ENISA has the right to alter, update or remove the publication or any of its contents. It is intended for information purposes only and it must be accessible free of charge. All references to it or its use as a whole or partially must contain ENISA as its source. Third-party sources are quoted as appropriate. ENISA is not responsible or liable for the content of the external sources including external websites referenced in this publication. Neither ENISA nor any person acting on its behalf is responsible for the use that might be made of the information contained in this publication. ENISA maintains its intellectual property rights in relation to this publication.
COPYRIGHT NOTICE
© European Union Agency for Cybersecurity (ENISA), 2024 This publication is licenced under CC-BY 4.0 “Unless otherwise noted, the reuse of this document is authorised under the Creative Commons Attribution 4.0 International (CC BY 4.0) licence (https://creativecommons.org/licenses/by/4.0/). This means that reuse is allowed, provided that appropriate credit is given and any changes are indicated”. Images in pages 17, 28-29, 31, 33, 36-37, 47, 48, 51, 52, 56 © Shutterstock.com For any use or reproduction of photos or other material that is not under the ENISA copyright, permission must be sought directly from the copyright holders.
Catalogue number: TP-01-24-005-EN-N
ISBN: 978-92-9204-681-1
DOI: 10.2824/0401593
EUROPEAN UNION AGENCY FOR CYBERSECURITY
2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
DECEMBER 2024 TABLE OF CONTENTS
INTRODUCTION 8
1. CYBERSECURITY LANDSCAPE IN THE UNION 11
1.1 LEGISLATIVE CONTEXT 12 1.2 UNION-LEVEL RISK ASSESSMENT 14 1.3 EU CYBERTHREAT LANDSCAPE 14
2. CYBERSECURITY CAPABILITIES AT THE UNION LEVEL 20
2.1 HIGH-LEVEL FINDINGS 21 2.2 NATIONAL CAPABILITIES: ALIGNMENT OF NATIONAL CYBERSECURITY STRATEGIES 23 2.3 PRIVATE SECTOR CAPABILITIES: CYBERSECURITY CAPABILITIES OF CRITICAL SECTORS 26 2.4 SOCIETAL CAPABILITIES: CYBERSECURITY AWARENESS AND CYBER-HYGIENE OF EU CITIZENS 30
3. INCREASING THE LEVEL OF CYBERSECURITY 34
3.1 POLICY IMPLEMENTATION 35 3.1.1 Implementing a comprehensive and complementary cybersecurity policy framework 35 3.1.2 Identification and Supervision 37 3.1.3 Cybersecurity risk management measures 37 3.1.4 Information sharing and reporting obligations: institutional framework and practice 40 3.2 CYBER CRISIS MANAGEMENT 44 3.2.1 Situational awareness 44 3.2.2 National CSIRTs 47 3.2.3 National capabilities: Cyber-exercises 47 3.3 CYBERSECURITY SKILLS 49 3.4 SUPPLY CHAIN SECURITY 53 3.4.1 Vulnerability handling and disclosure 55
4. LOOKING AHEAD 57
5. ANNEX 59
EXECUTIVE SUMMARY
This document marks the first report on the state Union level of cybersecurity moving forward. Sectorial of cybersecurity in the Union, adopted by ENISA in policy initiatives (e.g. DORA, NCCS, Aviation) were adopted cooperation with the NIS Cooperation Group and the in parallel to address specific sectorial challenges. At European Commission, in accordance with Article 18 the same time the volatile geopolitical landscape has of the Directive (EU) 2022/2555 (hereinafter NIS2). The influenced the goals and tactics employed by state and report aims at providing policy makers at EU level with non-state threat actors, while an assessment of the threat an evidence-based overview of the state of play of the landscape reveals an increase in cybersecurity incidents cybersecurity landscape and capabilities at the EU, national in the EU with ransomware and DDoS attacks getting the and societal levels, as well as with policy recommendations lion’s share among the various types of attack observed. to address identified shortcomings and increase the level of cybersecurity across the Union. This report concludes that the maturity of the EU cybersecurity policy framework has reached a considerable The drafting of this report precedes the transposition level and that the following period could place emphasis date of NIS2. As a result, some of the data presented here on supporting private and public sector entities with may not fully reflect cybersecurity capabilities following the implementation of the legislation by EU MSs, with the transposition deadline of 17 October 2024. Still, this the support of the European Commission and ENISA. report includes several data points unlikely to change in The plethora of mechanisms, processes and platforms the short- and mid-term and serves as a snapshot of the for collaboration established within this framework, state of cybersecurity in the Union just before NIS2 is such as the NIS Cooperation Group, EU-CyCLONe and fully implemented by EU Member States (MSs). the CSIRTs Network to name but a few, provide a solid basis and a comprehensive toolbox to address the The recent past has been characterised by horizontal shortcomings identified in key policy areas, namely Policy
policy initiatives including but not limited to NIS2, Implementation, Cyber Crisis Management Skills and CRA, CSOA and EUDIF that improve the EU cybersecurity Supply Chains.
policy framework and establish all necessary structures and processes to allow for targeted improvements at the
DISCLAIMER
The drafting of this report took place in a special period as the collected data refer to a period when the NIS2 transposition was still ongoing, whereas the publication followed the NIS2 transposition deadline. We acknowledge that this discrepancy is likely to lead to observations and results concerning the NIS2 transposition status and the development of capabilities that may not reflect the respective status as of October 17th and thereafter. Still, it is important to capture a snapshot of the state of cybersecurity in the Union as this transposition process is still ongoing, in order to support the assessment of the impact of NIS2 in subsequent reports. The data contained in this report generally refers to the current legal framework (e.g. NIS2 and the European Digital Identity Framework) unless otherwise specified; for example, use of the terms Operators of Essential Services (OESs) and Digital Service Providers (DSPs) and related data concern NIS1.
Specifically, this report recommends:
Strengthening the technical and financial support given to EUIBAs and national competent authorities and to entities falling within the scope of the NIS2 Directive to ensure a harmonised,
comprehensive, timely and coherent implementation of the evolving EU cybersecurity policy framework using already existing structures at EU level such as the NIS Cooperation
Group, CSIRTs Network and EU Agencies.
As called upon by the Council, revising the EU Blueprint for coordinated response to
large-scale cyber incidents, while taking into account all the latest EU cybersecurity
policy developments. The revised EU Blueprint should further promote EU cybersecurity
harmonisation and optimisation, as well as strengthen both national and EU cybersecurity capabilities for levelled up cybersecurity resilience at national and European level.
Strengthening the EU cyber workforce by implementing the Cybersecurity Skills Academy
and in particular by establishing a common EU approach to cybersecurity training, identifying
future skills needs, developing a coordinated EU approach to stakeholders’ involvement to
address the skills gap and setting up a European attestation scheme for cybersecurity skills.
Addressing supply chain security in the EU by stepping up EU wide coordinated risk
assessments and the development of an EU horizontal policy framework for supply chain security aimed at addressing the cybersecurity challenges faced both by the public and the
private sectors.
Enhancing the understanding of sectorial specificities and needs, improving the level of cybersecurity maturity of sectors covered by the NIS2 Directive and using the future Cybersecurity Emergency Mechanism to be established under the CSOA for sectorial
preparedness and resilience with a focus on weak or sensitive sectors and risks identified through EU-wide risk assessments.
Promote a unified approach by building on existing policy initiatives and by harmonising national efforts to achieve a common high-level of cybersecurity awareness and cyber hygiene among
professionals and citizens, irrespective of demographic characteristics.
INTRODUCTION INTRODUCTION
INTRODUCTION
Article 18 of the Directive (EU) 2022/2555 on measures for The methodology, including the relevant variables, such as a high common level of cybersecurity across the Union quantitative and qualitative indicators from all data sources (NIS2) foresees that ENISA shall adopt, in cooperation with considered, has been developed by ENISA in cooperation the Commission and the Cooperation Group, a biennial with the Commission, the Cooperation Group and the report on the state of cybersecurity in the Union and shall CSIRTs network, ENISA’s Management Board and ENISA’s submit and present that report to the European Parliament. NLO network. This document represents the first ever version of this report on the state of cybersecurity in the Union to be These sources provide insights into different aspects presented to the stated target audience, the European of cybersecurity in the Union and the observations and Parliament. findings presented in this report are based on individual data points of interest or a correlated analysis of multiple The data used to assess the state of cybersecurity in the data points from the aforementioned data sets. The Union and to conduct the analysis in order to identify observations and findings have also been validated shortcomings and propose measures to increase the through a series of consultations with the NIS Cooperation overall level of cybersecurity in the Union comes from Group and the European Commission. several sources, including, though not limited to, the EU Cybersecurity Index, the ENISA Threat Landscapes, the The report is intended to take stock of the state of NIS Investments report, the EU Cybersecurity Technical cybersecurity in the EU from the entry into force of the Situation Report on incidents and threats (Cybersecurity NIS2 Directive on 16 January 2023 until July 2024. In Act Article 7 (6) report), the Foresight Cybersecurity Threats exceptional cases, where recent data were not available, for 2030, incidents reported in the context of existing older data sources were used. cybersecurity legislation, the evolving EU policy landscape and more . Articles 18.1 and 18.2 of NIS2 outline specific elements that shall be included in the report. These are mapped to the report structure as follows.
Chapter I ARTICLE 18 REQUIREMENTS MAPPING TO REPORT STRUCTURE
CYBERSECURITY
Art 18.1(a): a Union-level cybersecurity risk assessment, Cybersecurity risk assessment in section 1.2
taking account of the cyber threat landscape
Cyber threat landscape in section 1.3
LANDSCAPE
Art 18.1(b): an assessment of the development of Union level based on Index findings in section 2.1
IN THE
cybersecurity capabilities in the public and private sectors
National level capabilities in section 2.2
across the Union
UNION
Private sector capabilities in section 2.3
Art 18.1(c): an assessment of the general level of In section 2.4
cybersecurity awareness and cyber hygiene among citizens
and entities, including small and medium-sized enterprises
Art 18.1(d): an aggregated assessment of the outcome of the Not covered as the peer review mechanism had not been peer reviews referred to in Article 19 implemented as of the drafting of the report but will be included in future versions of the report.
Art 18.1(e): an aggregated assessment of the level of maturity Union level based on Index findings in section 2.1
of cybersecurity capabilities and resources across the
Maturity of national level capabilities in section 2.2
Union, including those at sector level and the extent to
which the Member States’ national cybersecurity strategies Maturity of private sector capabilities in section 2.3
are aligned
Societal cybersecurity awareness and cyber hygiene in
section 2.4
Alignment with NCSS in section 2.2
Art 18.2: policy recommendations, with a view to addressing Policy recommendations in chapters 2 and 3 where shortcomings and increasing the level of cybersecurity relevant across the Union and a summary of the findings for the Summary of the EU Cybersecurity Technical Situation
particular period from the EU Cybersecurity Technical
Reports in section 1.2
Situation Reports on incidents and cyber threats prepared by
ENISA
Specifically for the development of policy recommendations, the report presents an in-depth analysis of data points across several selected policy areas. The identification of these areas was based on the main shortcomings observed from the available data, as well as being based on the opinions expressed by EU MSs.
Chapter I
CYBERSECURITY LANDSCAPE
IN THE
UNION
1.1 LEGISLATIVE CONTEXT
In the recent past, several legislative developments have obligations regarding actively exploited vulnerabilities taken place. After the entry into force of the Directive (EU) and severe cybersecurity incidents are also introduced, 2016/1148 (NIS Directive ) in 2016 and the Cybersecurity applicable 21 months after the entry into force of the Act in 2019, a major policy milestone at EU level was the Act.
EU Cybersecurity Strategy (published on 16 December
since then, with important new legislation being put in enter into force in early 2025. The CSOA lays down place to complement the EU cybersecurity framework. measures to strengthen capacities in the Union to More specifically, mention shall be made of the following detect, prepare for and respond to cybersecurity legislative files. threats and incidents. It introduces three main pillars to strengthen solidarity at Union level to better detect, • Five years after the date of transposition of the NIS prepare for and respond to significant or large-scale Directive, the new NIS2 Directive entered into force cybersecurity incidents, comprising the European on 16 January 2023 setting the date for transposition Cybersecurity Alert System (pan-European Network of by the Member States on 17 October 2024. The Cyber Hubs), the Cybersecurity Emergency Mechanism NIS2 Directive provides legal measures to boost the and the European Cybersecurity Incident Review overall level of cybersecurity in the EU by imposing Mechanism. legal obligations on entities across 18 sectors of the economy, including in terms of security requirements • The amendment to the Cybersecurity Act (CSA and the notification of incidents. It also requires amendment) is expected to enter into force by the Member States to increase preparedness with, for end of 2024. The proposed targeted amendment instance, extended prerogatives and missions for aims to enable, by means of implementing acts by the Computer Security Incident Response Teams (CSIRTs) Commission, the adoption of European cybersecurity and competent authorities. The NIS2 Directive also certification schemes for ‘managed security services’, promotes cooperation among all Member States in addition to information and communications by continuing and strengthening the Cooperation technology (ICT) products, ICT services and ICT Group set up originally under the NIS Directive to processes, which are already covered under the support and facilitate strategic cooperation and the Cybersecurity Act.
exchange of information among Member States. It • The Regulation regarding measures for a high also institutionalises the EU-CyCLONe network, aimed
common level of cybersecurity at EU Institutions,
at improving preparedness for and the coordinated 9 Bodies and Agencies of the Union (EUIBAs) was management of large- scale cybersecurity incidents adopted in 2023 and entered into force on 7 January and crises at the operational level and to ensure the 2024. regular exchange of relevant information among Member States and EUIBAs. • Commission Implementing Regulation (EU) 2024/482 6 which lays down rules for the application of the • The Cyber Resilience Act (CRA) was adopted on Cybersecurity Act as regards the adoption of the 23 October 2024. The CRA introduces common
European Common Criteria-based cybersecurity
cybersecurity requirements for products with digital 10 certification scheme (EUCC) entered into force in elements, hardware and software, with the aim of February 2024 and will be applicable as of 27 February minimising product vulnerabilities and ensuring that 2025. cybersecurity is taken seriously both at the design and production phases and that vulnerability management is guaranteed across the support period for such products. Manufacturers will have to apply the rules 36 months after their entry into force. Reporting
• A number of sector-specific cybersecurity • Other recent Union legislation relevant to the
initiatives, such as: cybersecurity realm include among others the
Artificial Intelligence Act (AIA) , Regulation (EU) • Regulation (EU) 2022/2554 on digital operational 2022/1925 on contestable and fair markets in the 11 19 resilience for the financial sector (DORA) digital sector (Digital Markets Act - DMA) , Regulation entered into force on 16 January 2023; (EU) 2022/2065 on a Single Market for Digital Services (Digital Services Act - DSA) , Regulation (EU) 2023/178 • Commission Delegated Regulation (EU) 21 (Chips Act) and Regulation (EU) 2023/2854 (Data 12 22 2022/1645 and Commission Implementing Act) . Regulation (EU) 2023/203 were adopted in 2022 in the aviation sector; These policy files include legislative initiatives that explicitly focus on cybersecurity, such as NIS2 and the CRA, • The Network Code on sector-specific rules for legislative initiatives that include cybersecurity provisions cybersecurity aspects of cross-border electricity as part of a broader context, such as the AIA and the EHDS, flows (NCCS) was adopted on 11 March 2024; and legislative initiatives that, despite not including specific cybersecurity provisions, are relevant from a cybersecurity • The new European Digital Identity Framework standpoint, such as the Chips Act. amending Regulation (EU) No 910/2014 entered into force in May 2024;
• The European Health Data Space (EHDS) Regulation is in the final stages of the adoption process.
Figure 1: Overview of EU legislative landscape during the reporting period
EU legislative landscape 1.2 UNION-LEVEL RISK ASSESSMENT 1.3 EU CYBER THREAT LANDSCAPE
For the purpose of this report, the union-level risk This section provides a comprehensive overview of the assessment focuses on identifying and displaying the evolving threat landscape in the EU, based on available Union’s exposure in the cyber threat landscape. During insights and our understanding of current challenges and the reporting period, the EU experienced a surge in emerging trends. According to the ENISA Threat Landscape cyber threats, fuelled by factors such as the fast pace of 2024 report , from late 2023 to mid-2024 there was a digitisation and the ever-increasing interconnectivity of our notable escalation in cybersecurity attacks, setting new society and economy. The cybersecurity threat landscape benchmarks in both the variety and number of incidents, has become and continues to be significantly more as well as their consequences . complex and widespread . The geopolitical landscape heavily influences the goals and tactics employed by In Figure 2, it can be seen that the category of Denialstate and non-state threat actors. Malicious cyber activity of-Service attacks (DoS/DDoS/RDoS) and ransomware has become a clear component of wider hybrid threats, remained the most reported forms of attack and accounted such as disinformation and physical acts of sabotage for more than half of the events observed followed by and violence, seeking to undermine and destabilise EU threats against data, for example data breaches or data society, democracy and values. The ongoing Russian war of leaks. aggression against Ukraine initiated in February 2022 and • As geopolitical and economic tensions grow, cyber the escalated Israel-Palestine conflict since October 2023 warfare escalates with espionage, sabotage, and continued to impact the cybersecurity realm, in particular disinformation campaigns becoming key tools for in connection with rising threats of Foreign Information 24 nations to manipulate events and secure a strategic Manipulation and Interference (FIMI) and hacktivism. advantage. Similarly, major events taking place at the national or European levels provided the motivation for increased • According to ENISA’s analysis of cybersecurity 25 33 hacktivist activity (for example, the European Elections) . incidents and cyber threats , cyberespionage campaigns targeting EU MSs and EUIBAs are In addition, the fading out of the COVID-19 pandemic did continuous and remain a persistent and severe not result in a decrease in the use of digital services. On the threat, despite limited public reporting. Russia-nexus contrary, a continued demand for the use of digital devices and China-nexus threat groups remain prominent from businesses and citizens was seen in 2023 . Moreover, threats. In particular, Russia-nexus groups continue the rise of AI-powered technologies and tools continued to focusing on Ukrainian targets , while updating their have an impact on societies across the EU . infrastructure to conduct cyberespionage campaigns against EU countries and institutions and advanced EU MSs continued to be targeted by cybercriminals, cyber offensive campaigns against technology state-aligned threat groups and hacktivists who displayed providers, gaining access to high value targets. The continuous evolution and the updating of their tactics, European Parliamentary elections were seen to be techniques and procedures (TTPs) in conducting campaigns a target with information operations aligned with against governments, organisations and civil society. Russian and Chinese interests aiming at influencing Furthermore, the systems of EU MSs as well as Union 36 the civilian population , but did not include any entities continue to be exposed to the exploitation of notable or disruptive cyberattacks. known and unknown vulnerabilities. • According to a recent analysis of Foreign
Information Manipulation and Interference (FIMI)
In light of the observations and findings concerning the cases detected between December 2022 and the cyber threat landscape, the cyber threat level to the EU 28 end November 2023, it was noted that EU-based during the reporting period was assessed as substantial , organisations are a common target of such activities. meaning that it is likely entities are being directly targeted by threat actors or could be exposed to breaches using Threat actors rely on the repetitiveness of their recent discovered vulnerabilities, while serious disruptions actions, as individual incidents may seem small on of essential and important entities or EUIBAs is considered their own and may not be visible; however, these a realistic possibility. The substantial severity of the threat subtle attacks can gain power through persistence and is also based on the intent and capability of the threat repetition. Also, many hacking campaigns by stateactors. While the threat actors we tracked demonstrated nexus threat actors are using AI to create fake content the intent to generate high-scale cybersecurity incidents in or to develop new ways to spread misinformation. Europe, only some of them had previously displayed the According to the recent ENISA Threat Landscape 2024 capabilities needed to cause them. 38 report , information manipulation continues to be a key element of the Russian war of aggression against Ukraine, although an effort to further localise content and at the same time to globalise its presence is observed. According to the ENISA foresight study on
cybersecurity threats for 2030, the spotlight is on the links or social media, to trick people into revealing
growing relevance of cybersecurity in elections and their credentials, while they are also using AI to
the role of disinformation with AI content. create fake content, such as phishing e-mails and
deepfakes . A concerning trend that has gained • In the context of the cybercrime ecosystem, momentum in recent years is the rise of hacker-for-
ransomware remains among the most impactful hire services that contribute to the professionalisation
threats for EU Member States, with a shift from of the cybercrime market, but also provide services encryption to data exfiltration and with small and 42 43 to state-nexus actors. High-profile arrests and medium-sized enterprises becoming a more attractive successful take-downs show that there is an ongoing target for cybercriminals, while the double extortion concerted effort to dismantle criminal networks tactic has become the norm for well-established 40 by law enforcement agencies. In many cases, law ransomware groups . enforcement actions have forced criminal groups to
Cybercriminals continue to use social engineering reorganise themselves, signalling a downward trend
techniques, such as phishing e-mails with malicious that will likely force cybercriminals to move towards
new profitable business models.
Figure 2: Breakdown of incidents by threat type (July 2023 to June 2024)
Incidents by threat type (July 2023 to June 2024)
Figure 3: Timeline of EU incidents (number of incidents per month) (July 2023 to June 2024)
Timeline of EU incidents (July 2023 to June 2024) Hacktivist activity is increasing and becoming more unpredictable
• Meanwhile, hacktivist activity is increasing and Further, hacktivists use ransomware and wipers and becoming more unpredictable. According to the 2023 rely on data theft . A notable trend is the overlap Internet Organised Crime Threat Assessment by between state-nexus actors and supposed hacktivists. Europol, the ongoing geopolitical crisis has unleashed Pro-Russian hacktivist activity against European a wave of disruptive cyberattacks, with the EU MS targets has increased throughout the reporting period, bearing most of the effect of these malicious activities. while its operational impact remains limited and seems mainly aimed to attract attention or support
Hacktivists use common tactics, such as DDoS attacks Hacktivists use common tactics, such as DDoS attacks and
propaganda campaigns. The vast majority of hacktivist
and website defacements, but also “Fear, Uncertainty, website defacements, but also “Fear, Uncertainty, and
attacks continue to be driven by the Ukrainian conflict and Doubt” to amplify the impact of their operations. or perceived anti-Russian stances, with occasional Doubt” to amplify the impact of their operations. A huge number of Distributed Denial of Service (DDoS) instances of pro- Palestinian hacktivist groups attacks have significantly targeted the public sector A notable trend is the overlap between state-nexus potentially targeting EU Member States. Threat actors
across the EU among others. actors and supposed hacktivists.
continue to make use of their DDoS tools to further amplify their targeting. While currently the alliances among hacktivist groups appear to have minimal impact on their reach, the convergence of two or more prevailing groups could potentially generate impactful incidents.
Hacktivist activity is increasing and becoming more unpredictable Hacktivists use common tactics, such as DDoS attacks and website defacements, but also “Fear, Uncertainty, and Doubt” to amplify the impact of their operations. A notable trend is the overlap between state-nexus actors and supposed hacktivists.
Figure 4: Time series of DDoS incidents (July 2023 to June 2024)
Time series of DDos incidents (July 2023 to June 2024)
Figure 5: Targeted sectors per number of incidents (July 2023 to June 2024)
Targeted sectors per number of incidents (July 2023 to June 2024) 0.18K 1.87K
0.41K
1.11K
0.48K 11%
0.89K
0.8K
• Supply-chain threats rank highly in the EU, because • Giving an outlook into the long-term future, the
of their wide reach, their difficulty in detection increased dependencies and the development of new
and the significant potential they have in inducing technologies, such as quantum computing and AI, add
catastrophic cascading effects. On top of the ever- complexity to the threat landscape and introduce new
increasing reliance on outsourced IT services, risks for which further preparedness is needed.
creating supply chain complexities and cybersecurity
sophisticated supply chain attacks demands a multi- forecasts emerging cybersecurity threats up to
pronged approach to fortify defences. 2030, the spotlight is on the increasing power of
non-state actors. More specifically, according to the • Finally, while multiple state-nexus threat groups trends identified, while the perceived prominence of reportedly continue to exploit zero-day vulnerabilities threats such as ‘supply chain compromise of software in the context of targeted espionage, unpatched dependencies’ and ‘advanced disinformation/influvulnerabilities (N-day vulnerabilities) remain a ence operations campaigns’ is expected to decline greater risk due to their impact on a wide array of slightly until 2030, they will still pose significant risk. organisations . The ‘human error and exploited legacy systems’, the
‘exploitation of unpatched and out-of-date systems’ • The interconnected digital age leaves no sector and the ‘physical impact of natural/environmental immune to cyberattacks. According to the ENISA Threat 51 disruptions on critical digital infrastructure’ will Landscape report 2024 , a large number of events gain ground in their level of threat as perceived. have been observed (Figure 5) targeting organisations Similarly, the risk of ‘advanced hybrid threats’ linked in public administration (19%) and transport (11%) to interference, social engineering tactics and the sectors. Incidents targeting digital infrastructure and dissemination of disinformation are considered to banking constituted a substantial portion, representing be within the top-ranking ones in, for example, the 9% and 8% respectively of total events. A considerable context of elections. On the other hand, long term number of events was recorded targeting civil society perspectives of threats such as ‘skill shortages’ have though not necessarily a particular sector (these are intensified. The likelihood that ‘AI disrupting or labelled as ‘general public’) and accounted for 8% of all 52 enhancing cyberattacks’ will appear has increased, events observed . which is not surprising given the wide coverage of
emerging AI applications at scale and considerations
Figure 6: Review of the ENISA Foresight for the ethical use of newly released and emerging AI
Cybersecurity Threats for 2030. models.
Cybersecurity Threats for 2030 9 THREATS 6 2030 Chapter II
CYBERSECURITY CAPABILITIES
AT THE
UNION LEVEL
Chapter II
CYBERSECURITY CAPABILITIES
2.1 HIGH-LEVEL FINDINGS AT THE
In accordance with Art. 18.3 of the NIS2 Directive, ENISA By combining the value of quantitative and qualitative UNION LEVEL has developed a set of quantitative and qualitative indicators, the Index results in an aggregated assessment
indicators (combined in a framework hereby referred to as of the EU as a whole and on specific aspects . Based on the “EU Cybersecurity Index”) to support the aggregated the data collected in 2024, the overall value of the Index assessment of the level of maturity of cybersecurity is 62.65 (on a scale from 0 to 100 points). It is noted that capabilities and resources across the Union. The the average deviation of the scores of Member States from framework describes the cybersecurity posture of the EU the EU average is 3.76, signalling an overall convergence in selected areas, including the ability of society and the across the Union with regards to the set of indicators as private sector to recognise threats and prevent incidents, assessed, with some countries lagging slightly behind (with the state of policy development and implementation, and the minimum deviation being -13.18 points). the ability to carry out operations to ensure resilience.
Figure 7: EU Cybersecurity Index 2024 – Source: ENISA
EU Cybersecurity Index 2024 3.76 7.45 -13.18
There seems to be convergence among MSs in the domains where the EU average is the highest.
In general, the indicators with the lowest average deviation from the index among MSs (below 3 index points) largely correspond to the indicators with the highest average values (90 points or above).
MSs seem to diverge especially in domains related to policy implementation, in particular with regards to vulnerability disclosure and supervisory measures for essential and important entities, as well as R&D and education. In these domains, the average deviation of related indicators is among the
highest (25 points or more) and there is a big difference between the countries deviating the most and the least from the EU average. As regards to vulnerability disclosure and supervisory measures, this is due to the ongoing implementation of relevant legislation. As regards to R&D and education, this seems to indicate that different MSs perceive the importance of the topic differently. Sections 3.4.1 on Vulnerability Handling and Disclosure and 3.1.2 on Identification and Supervision give more detailed information on different stages of implementation in MSs. The info box on R&DI and section 2.3 on skills give more contextual information to mentioned topics.
R&D and innovation are indeed topics where EU average values hide great discrepancies among MSs.
The indicators measuring the share of EU funding for cybersecurity R&D and, as mentioned above, on the coverage and implementation of cybersecurity in national R&D policies and initiatives show high values for the maximum and minimum deviations from the EU index average.
In the field of cyber hygiene, the secure internet use of citizens showed one of the highest results. This indicator has an EU average score of 93.29 out of 100 and a low average deviation amongst
MSs. This means that, across all MSs, internet users have changed the way they use the internet due to security concerns. Section 2.4 on Cybersecurity Awareness and Cyber-Hygiene puts this finding into the context of people’s confidence into their ability to protect themselves.
The EU has a high average score in relation to enterprises that have not suffered cybersecurity incidents leading to the disclosure of confidential data or destruction and corruption of data. The
related indicators have an average EU value above 90 out of 100 and a low average deviation amongst MSs . It is important to note though that, in general, enterprises, and especially SMEs, are reluctant to admit having been a victim of an incident. Section 3.1.4 offers a more in-depth analysis on incident reporting.
There is room for improvement regarding cybersecurity investments performed by Operators of Essential Services (OESs) and Digital Services Providers (DSPs) regulated under the NIS1 Directive . The EU average for the related indicator is low (7.14) and the average deviation is low
(0,54), meaning that this issue seems to be wide-spread across the EU. A more detailed analysis on the Cybersecurity Capabilities of Critical sectors is section 2.3.
Another area needing improvement is cybersecurity governance within organisations. In particular, the EU average score for enterprises performing a cybersecurity risk assessment is 32.01 out of 100. Section 3.1.3. puts this finding in the broader context of the national Cybersecurity Risk Management measures.
The maturity of CSIRTsis also an aspect where more action would be needed. The EU average
score for the related indicator measuring the alignment of CSIRTs with internationally recognised practices , is low (10.31 out of 100) and the average deviation from this value is 10.58.This indicates that low maturity, in terms of certification, is a relatively common characteristic among MSs. On the positive side, CSIRTs seem to be well-integrated in international networks, such as Trusted Introducer and FIRST. Section 3.2.2 explains and builds on the role of CSIRTs in crisis management.
2.2 NATIONAL CAPABILITIES: ALIGNMENT OF NATIONAL CYBERSECURITY STRATEGIES
National cybersecurity strategies (NCSS) are documents Since 2017 all MSs have a national cybersecurity setting a country’s long-term policy vision for strategy which, in some cases, were also updated in later cybersecurity. NIS2 mandates that each MS adopts “a years . The MSs have different degrees of expertise in national cybersecurity strategy that provides for the drafting strategies, ranging from some being at the third (or strategic objectives, the resources required to achieve more) generation of their strategy to others being at their those objectives, and appropriate policy and regulatory first generation. measures, with a view to achieving and maintaining a high level of cybersecurity […] .
Figure 8: NCSS generation in the EU (2023) – Source: ENISA, A governance framework for National Cybersecurity Strategies
Generations of National Cybersecurity Strategies in the EU 3rd or later generation NCSS 2nd generation NCSS 1st generation NCSS Out of scope Out of the 27 Member States: • 9 Member States have a 3rd or later generation NCSS. • 14 Member States have a 2nd generation NCSS. • 4 Member States are at their first NCSS.
While it is normal that MSs can have varying priorities due Looking at a pre-identified set of strategic objectives , to their national contexts, alignment of objectives indicates national strategies are overall aligned, as most objectives that national efforts are addressed in the same direction, are shared across the great majority of MSs . thus facilitating complementarity and creating a potential for economies of scale.
The most common objectives in National Cybersecurity Strategies are:
National strategies are aligned overall, with most In order to be meaningful, the coverage of cybersecurity objectives shared across the great majority of MSs. The objectives is expected to be matched by formal action least recurrent objective concerns the cybersecurity plans that are then implemented. Generally, it is the case of the supply chain included by only half of MSs in that almost all most common objectives (10 out of 12) their strategies. Supply chain security has become an are complemented by an action plan in the majority of increasingly urgent matter in the few last years due to the MSs (80% or more) that included those objectives the discovery of impactful vulnerabilities (e.g. Log4j ) in their national strategies. However, for half of the and the geopolitical weaponisation of supply chains . most common objectives it can be observed that the The relatively low take-up of a related objective might share of MSs that have implemented their action reflect a certain difficulty in rapidly adapting strategies plans decreases (between 67 and 79%). This suggests to a changing context. This might change from sector to that there is a group of MSs that have put in place the sector; for example, in the context of the EU Toolbox on necessary policy framework but are lagging behind in the 5G Cybersecurity for the protection of 5G networks, implementation of action plans. measures have been taken at the national level to exclude high-risk vendors. The eventual implementation of the Peer Review process introduced in Art.19 of NIS2 is expected to further enhance Objectives in national strategies are generally matched cybersecurity capabilities at national level through the by formal action plans that are then implemented. sharing of good practices and the development of mutual However, there is a group of MSs that have put in place trust among MSs.
the necessary policy framework but are lagging behind in the definition of action plans.
Info box
R&D&I in national cybersecurity strategies What about the cybersecurity of institutions, bodies, offices and agencies of the European Union?
Research, development and innovation (R&D&I) are generally regarded as fundamental forward- In the digital age, information and communication looking activities to ensure a country’s technological technology is a cornerstone of an open, efficient and economic competitive edge. This holds also for and independent European administration. cybersecurity because of the fast-moving nature Evolving technology and the increased complexity of related technologies, as well as for its role in the and interconnectedness of digital systems amplify security and perceived trustworthiness of the digital cybersecurity risks, making EU institutions, bodies, environment. Cybersecurity R&D&I is generally offices and agencies (‘Union entities’) more vulnerable recognised as important and features as a dedicated to cyber threats and incidents which pose a threat objective in national strategies; the great majority of to their business continuity and capacity to make MSs (23) include a dedicated objective in their national their data secure. In December 2023, Regulation strategies. The level of implementation is mature in (EU) 2023/2841 that lays down measures for a high about two-thirds of the countries (17) that implement that objective with, for example, a dedicated body common level of cybersecurity at the institutions, overseeing cybersecurity R&D, funding programmes bodies, offices and agencies of the Union was and joint public-private investments as well as the adopted . Among others, the regulation mandates establishment of local start-up ecosystems and other that each entity establish, by 8 April 2025, a framework networking channels. Less than one-third (six MSs), for internal cybersecurity risk- management, however, has put in place mechanisms to detect the governance and control to be overseen by and under need for updates or the inclusion of new measures. the responsibility of the Union entity’s highest level While the difficulty in updating programmatic of management. Also, the regulation foresees the documents is acknowledged, R&D&I is an area in which creation of an Interinstitutional Cybersecurity Board, delayed implementation or delayed updates might lead adopting a multiannual strategy on raising the level of to significant consequences. cybersecurity in Union entities.
2.3 PRIVATE SECTOR CAPABILITIES: CYBERSECURITY CAPABILITIES OF CRITICAL SECTORS
The NIS1 and NIS2 Directives cover a wide range of and criticality of each NIS sector from a Union-wide different sectors, each with their own criticality and perspective . Through a combination of qualitative and maturity, and with their own cybersecurity needs. To allow quantitative indicators, each sector is evaluated across four for an assessment of the capabilities, and to understand critical and five maturity dimensions, scoring them from 1 the needs of each sector, ENISA developed a methodology to 10 . to assess, on an annual basis, the cybersecurity maturity
Criticality Dimensions Maturity Dimensions
1. Dependency on ICT: Higher dependency 1. Policy Framework and Guidance: Strong policies are
means increased vulnerability. foundational.
2. Time-Criticality: Quick impact requires 2. Risk Management and Good Practices: Effective risk
rapid response. management enhances resilience.
3. Economic Impact: Understanding 3. Collaboration and Information Sharing: Key to
economic consequences helps prioritise staying ahead of threats. protection. 4. Operational Preparedness: Ensures swift 4. Health and Safety Impact: Protecting human response to incidents. lives is paramount. 5. Security of ICT: Critical to protect operations from cyber threats.
• Banking and Financial Market Infrastructures
In 2023, ENISA conducted this assessment for the first 70 sectors (hereafter called Finance) time as a pilot initiative . This first assessment focused on a limited number of sectors and subsectors (or types
• Health sector
of entities within a sector) to ensure a manageable and effective evaluation process, including: • Transport sector – covering two subsectors Aviation
(Air), and Rail • Digital Infrastructure sector, covering the following
types of entities: Their overall Union-wide sectorial criticality and maturity scores are shown in Figure 9. MSs and their national
• Providers of public electronic communications authorities may need to prioritise between the various networks in the Digital Infrastructure sector sectors, deciding which sectors could receive more focus.
(hereafter called Telecoms subsector) This prioritisation will depend on many factors of course, • Internet Exchange Point providers, Content but one factor which could be considered is the relation delivery network providers, TLD name between the criticality of a (sub)sector and the maturity of registries, DNS service providers (hereafter a (sub)sector called Internet infrastructures subsector) It is important to mention that all sectors face
• Trust Service Providers (hereafter called Trust heterogeneity in terms of entity size and criticality, Services subsector)
making it challenging for national authorities to supervise • Energy – covering subsectors Electricity, Gas and Oil and enforce uniform security requirements.
Figure 9: Union-wide maturity and criticality of 10 (sub)sectors
Union-wide maturity and criticality of 10 (sub-sectors) Criticality Oil Maturity Key sectors and subsectors with High Maturity Emerging subsectors in Criticality: Internet and Criticality: Telecoms, Electricity, and Finance Infrastructure
The telecommunications, electricity and finance (sub) As our world becomes more digital, Internet Infrastructure sectors form the backbone of modern society, boasting is becoming increasingly critical. Its stability is crucial for the highest criticality scores due to their essential role in the functioning of other (sub)sectors. However, while its maintaining daily life and economic stability. Their failure criticality is nearing that of the big three, its maturity still would immediately and profoundly disrupt our daily lives needs improvement. and economic activities. Additionally, these sectors show the highest maturity levels in cybersecurity, thanks to Entities in these NIS2 sub-sectors are very aware of cyber
strong regulatory frameworks, effective supervisory risks and have developed good practices in cyber risk authorities, and advanced risk management and management. However, the level of cyber experience
operational preparedness. Consequently, their cybersecurity among entities is highly divergent, which contributes to practices serve as benchmarks for other sectors. discrepancies. Additionally, both at the national and EU levels, the understanding and follow-up of cyber risks In a majority of these ‘big three’ sectoral entities (80%), concerning these sub-sectors are limited. This limited leaders are directly involved in approving cybersecurity understanding may contribute to the sector’s reported risk management measures. There is a very strong deficiencies in incident detection, response capabilities and correlation between management involvement overall capabilities in the management of cyber risk.
in cybersecurity and an organisation’s cyber risk
management maturity and incident detection and Similarly, at the level of entities, operational
response capabilities. Organisations with leadership preparedness is quite high. Most of the entities, such
active in cybersecurity are more than twice as likely to score as the Internet exchange points (IXPs) and the Content above the basic level in both risk management and incident delivery networks (CDNs), are dealing with cyberattacks on detection and response . a daily basis. However, the lack of information sharing
and collaboration between the entities and authorities
However, there is diversity among entities within these also complicates operational collaboration in the event of sectors. For example, leadership training in cybersecurity a crisis. Enhancing these areas is essential for maintaining is highest in banking (59%) but lowest in financial market the security and stability of our digital ecosystem. infrastructures (30%). Similarly, the banking sector has the highest information security spending per annum (€2.0million), whereas the financial market infrastructures sector has one of the lowest IS (Information Security) spending per annum (€0.3m).
Moderate Criticality and Maturity: Health, Railway, and Gas
Sectors and subsectors such as health, railway and gas have moderate to high criticality scores. For instance, hospitals are primarily targeted by cyber criminals which may or may not result in patient data being leaked. However, these effects related to confidentiality are expected to be manageable. Incidents affecting the availability of health services may in fact put health or safety at risk. According to the ENISA Threat Landscape 2023 report, the health sector is one of three sectors facing the highest number of cybersecurity incidents. Moreover, according to available data on the threat landscape, even severely disruptive incidents affecting the health sector are typically isolated events with no cross-sectorial impact (in contrast to, for example, an incident affecting the Electricity sub-sector).
Similarly, an incident in the railway sub-sector would have an effect at a national level but is not likely to have a spill over impact. The health sector is becoming increasingly dependent on ICT for a range of applications, from medical instruments to patient databases, whereas the gas subsector uses ICT tools and systems to a moderate extent in its operations and is not yet heavily dependent on them.
These three (sub)sectors have moderate maturity levels, facing challenges in securing legacy systems
and operational technology (OT). Railway and Health
entities manage many legacy or obsolete systems which are difficult or even impossible to upgrade in order to implement cybersecurity measures. The respective entities are reliant on their suppliers, ICT service providers and other third parties for system updates, patch management Low Maturity: Oil sector and lifecycle management. Furthermore, the health sector’s performance in ensuring the security of the The oil sub-sector, while less critical than others due to its ICT products and processes it uses is rather inadequate lower dependency on ICT and less time-sensitive nature due to a huge variety of health entities, devices and of incidents, shows the lowest maturity in cybersecurity products. practices. The oil sub-sector is still in the very early days of its digitalisation and journey to maturity in cybersecurity. Interestingly, both Health and Rail are among the top Significant improvements are needed to elevate the investors in IT spending, with the health sector operators sector’s cybersecurity posture and ensure it does not investing annually 64 million EUR and the railway subsector become a weak link in our critical infrastructure. 101 million EUR. Addressing the above-mentioned challenges and leveraging their significant IT investments The Cyber Emergency Mechanism established with the are crucial steps toward enhancing cybersecurity in these CSOA includes preparedness actions such as coordinated vital sectors. preparedness testing of entities operating in highly critical sectors and is supported from the Digital Europe Programme and managed by the European Cybersecurity Competence Centre. The Commission, after consulting ENISA and the NIS Cooperation Group, could regularly identify relevant sectors or subsectors from the Sectors of High Criticality listed in Annex I of the NIS2 directive, from which entities may be subject to coordinated preparedness testing at EU level .
Policy Recommendation: Enhance the understanding of sectorial specificities and needs, improve the level of cybersecurity maturity of sectors covered by the NIS2 Directive, and use the future Cybersecurity Emergency Mechanism established under the CSOA for sectorial preparedness and resilience focusing on sectors found to be weak or sensitive and risks identified through EU-wide risk assessments.
To achieve this recommendation: • The EU is encouraged to capitalise on ENISA’s
technical expertise in cybersecurity to increase the • A harmonised approach for collecting sector-relevant preparedness and resilience of a sector’s cybersecurity data could be developed. MSs are encouraged to and is especially advised to seek ENISA’s technical assess and monitor the maturity and criticality of evaluation of any policy initiative that could have sectors at the national level. Additional indicators an impact on the preparedness and resilience of a may cover incidents, investments and cybersecurity sector’s cybersecurity. practices.
• A national risk assessment of selected sectors • The role of NIS2 as a horizontal framework to improve of our economy and society following an allthe level of cybersecurity maturity of sectors in scope hazards approach would provide a more granular should be preserved. assessment at national level. This would allow for • The EU MSs, with the support of the European more information to be introduced in Union-wide risk Commission and ENISA, could consider offering self- assessments of specific sectors. assessments to the entities which fall within the scope • ENISA could assist EU MSs to assess the cybersecurity of the NIS2 Directive, in addition to other measures of entities falling within the scope of the NIS2 Directive such as stress tests. in their jurisdiction, e.g. by providing information or supporting the sharing of good practices and the development of common assessment frameworks.
2.4 SOCIETAL CAPABILITIES: CYBERSECURITY AWARENESS AND CYBER-HYGIENE OF EU CITIZENS
The fast pace of digital transition and the formation of • In addition, the digital divide persists between rural new ways to exercise and enjoy fundamental rights and and urban populations. Only 46% of rural residents freedoms showcase the importance of strengthening the possess basic digital skills compared to 61% in urban cybersecurity awareness and digital skills of citizens, a areas. prerequisite for safe operations in this new environment. • While the basic digital skills gap between men and women has decreased, still the difference in Strong societal cybersecurity capabilities are crucial, as percentage terms between men and women with they directly impact how vulnerable EU citizens are to basic skills is 3.4% (2021), a drop from 5.6% (2015) . cyberattacks in their daily lives. According to the ENISA Threat Landscape 2024 report , 8% of the observed People’s confidence in their ability to protect incidents during the reporting period targeted civil society, themselves from cybercrime has decreased, suggesting i.e. the general public, with social engineering, data that cybersecurity awareness has likely increased breaches and information manipulation campaigns. among EU citizens.
• The confidence of EU citizens in their ability to Overall, a population with a high level of awareness and sufficiently protect themselves against cybercrime solid cyber hygiene practices is more resilient against has decreased to 59% (2020) from 71% (2017) . This cyber threats. This creates a safer and more secure digital could be justified given the fast-paced digitation of environment for everyone, fostering economic growth and services (public and private) and the more complex empowering individuals to fully participate in the digital and sophisticated threat landscape, but at the same age. time it could signify an increased awareness of cyber Half of EU citizens lack the digital skills needed to fully risks among the population.
participate in society, hindering their access to online
• This finding complements an observation made, based
services.
on Eurobarometer data , that a high proportion • According to Eurostat, 46% of Europeans (2021) of Internet users among the population (93%) do not possess basic digital skills and are thus not have changed the way they use the Internet due to confident when performing activities online and with concerns about security. digital devices nor can they gain the full benefits of
Low awareness about cybercrime and relevant
digital technologies. This observation is highlighted 75 reporting mechanisms among the EU population. in the Digital Decade Cardinal Points , as half of EU citizens are lacking the skills needed to access the 81 • According to Eurostat , around two-thirds of opportunities offered online to, for instance, obtain individuals in the EU manage access to their personal information from public authorities, use online data on the Internet by, for example, reading privacy banking, shop online or other activities related to policy statements before providing personal data, the Internet or software used for work, learning and restricting or refusing access to their geographical participating in society. location, limiting access to their profile or content
on social networking sites, refusing to allow the use A fair digital future requires ensuring everyone has of personal data for advertising purposes, checking the digital skills needed to embark on their journey that the website where personal data are provided is of transformation. An analysis of different socio- secure. Remarkably, though the risks posed to citizens demographic groups at the EU level shows that the following the digitisation of services has increased level of digital skills is better among young people the latest years, this share (66%) has remained stable compared to older age groups. In addition, although throughout years from 2020 to 2023.
the digital gender gap is shrinking, there is still a need
• The share of population (52%) feeling fairly or very
to promote relevant initiatives to address it.
well informed about cybercrime has not changed • The Digital Skills Dimension of the Digital Economy substantially since 2017 (46%) .
and Society Index indicated that only 35% of EU • In addition, when it comes to citizens’ awareness citizens aged 55-74 and 29% of retired and inactive of cybersecurity matters, just over one in five citizens have at least basic digital skills, compared to respondents (22%) responded to a Eurobarometer more than 70% in young adults or individuals with survey that they are aware of the existence of an higher education. official channel to report a cybercrime or other illegal online behaviour.
An analysis of different sociodemographic groups at the EU level shows that the level of digital skills is better among young people compared to older age groups. In addition, although the digital gender gap is shrinking, there is still a need to promote relevant initiatives to address it.
Cybersecurity in higher education: The availability of Cybersecurity in primary and secondary education: cybersecurity education programmes varies greatly Variations across MSs in term of cybersecurity across EU Member States. education maturity.
• When it comes to the development of cybersecurity • MSs have a series of initiatives (strategy, action knowledge in higher education, according to plan etc.) in place for cybersecurity in primary and ENISA data , more than two-thirds of MSs offer secondary education. However, national approaches bachelor and master degrees in cybersecurity as vary widely from one country to another and mostly an independent discipline in universities (24 MSs), rely on decentralised initiatives or stand at the very cybersecurity courses and/or specialised curriculum early stage of implementation . for levels 5 to 8 of the European Qualifications • While educational initiatives in cybersecurity are Framework (20 MSs) and actively promote the addition generally supported by a national regulatory of information security courses in higher education framework, they rely heavily on national cybersecurity not only for computer science students but also to 86 strategies . other professional specialties (21 MSs). • Around half of MSs affirm that their country has • According to ENISA data shared by MSs on a voluntary 84 integrated cybersecurity with national curricula for basis , some MSs have numerous higher education primary (13 MSs) and secondary education (14 MSs), institutions offering cybersecurity programmes, while while several MSs have started discussions on how others have only a few. to integrate cybersecurity with national curricula for • The implementation of funding mechanisms to primary and secondary education (6 MSs). encourage the uptake of cybersecurity degrees (e.g. scholarships, guaranteed apprenticeship/internship, etc.) seems to vary widely. Sixteen (16) MSs state that
Ongoing work
they have either not taken any action in this regard or they have only started the process of setting-up funding mechanisms. ENISA has been developing instruments related to role profiles or higher education, notably the European Cybersecurity Skills Framework (ECSF), 89 Good practices from Member States the Cybersecurity Higher Education Database (CyberHEAD), the Cyber Exercise Platform and the European Cyber Security Challenge . The Development of a public website for Cybersecurity Skills Academy is a European policy raising cybersecurity awareness on 91 initiative, part of the 2023 European Year of Skills , risks, cyber hygiene practices and that aims to close the cyber security talent gap, for providing clear instructions on strengthen the EU cyber workforce and boost EU how to report a suspicious activity 92 competitiveness, growth and resilience . or cybercrime with links to relevant public authorities.
Gamified cybersecurity awareness campaign for young students via a dedicated space with practical tools to facilitate youngsters becoming mindful and alert about relevant threats and risks.
Organisation of several awareness-raising campaigns aiming at 1) developing students’ knowledge of finance and cyber security, and 2) allowing them to quickly and easily learn how to recognise cyberattacks and how to avoid them. Also, organisation of a series of educational events, campaigns, conferences and webinars in this regard, as well as TV spots with well-known personalities, to raise awareness.
Policy Recommendation: Promote a unified approach by building on existing policy initiatives and by harmonising national efforts to achieve a common high-level of cybersecurity awareness and cyber hygiene among professionals and citizens, irrespective of demographic characteristics.
To achieve this recommendation: and promoting relevant material in national languages to facilitate the improvement of cyber hygiene • The national cybersecurity strategy of MSs should practices among the general population. include a plan to enhance the general level of cybersecurity awareness among citizens, in • EU MSs are invited to work closely with the European accordance with Art.7(1) (h) of the NIS2 Directive. Commission and ENISA towards developing a As part of their national cybersecurity strategy, MSs monitoring framework related to primary and are encouraged to adopt policies promoting and secondary educational programmes addressing the developing educational programmes and training gap in cybersecurity skills. sessions focusing on cybersecurity, cybersecurity skills, awareness raising and research and development • EU MSs are encouraged to develop retraining initiatives, as well as guidance on good cyber hygiene policies and programmes to upskill talent. In this practices and controls, aimed at citizens, stakeholders context, they are also encouraged to use the ENISA and entities in accordance with Art.7(2) (f) of the NIS2 CyberHEAD database for higher education (European Directive. Qualifications Framework, levels 6-7), as the reporting tool to collect relevant EU data, but also to promote • EU MSs are encouraged to develop programmes its usefulness to citizens looking to upskill their with tailored content to address the specific needs knowledge in the field of cybersecurity. of different demographics in order to improve • EU MSs should encourage providers of services in cybersecurity awareness in underserved populations areas such as telecoms, banking and digital services and also to use multiple communication channels to invest on cybersecurity awareness as part of their such as social media, public service announcements corporate digital responsibility with the possibility of and community events to reach a wider audience. eventually establishing a responsibility framework • Aiming for a common high level of cybersecurity for corporate cybersecurity applicable to relevant awareness among EU citizens, ENISA could support operators. MSs by organising awareness events and by preparing
Chapter III
INCREASING
THE LEVEL OF
CYBERSECURITY
Chapter III 3.1 POLICY IMPLEMENTATION
A number of particular areas of focus were identified for further analysis with the aim of increasing the level of
3.1.1 Implementing a comprehensive
cybersecurity in the EU. The selection of these areas was
and complementary cybersecurity policy
based on an analysis that took into consideration the
framework
following:
• Indicators of the EU Cybersecurity Index 2024 with the As the EU cybersecurity policy framework has evolved
INCREASING
lowest EU average values and/or highest deviation over the last few years, implementation at a national level
THE LEVEL
among EU MSs; becomes a priority and national competent authorities are already in the process of working towards this goal. OF • Individual key findings and gaps from other sources,
However, the policy implementation process is including though not limited to NIS Investments, an
demanding both in terms of time and resources. At the
assessment the criticality and maturity of NIS1 sectors CYBERSECURITY time data was being collected, the MSs were introducing
and an analysis of NCSS; the new NIS2 sectors into their national legislation. The • Main threats to the Union deriving from the Threat expansion in scope and coverage of entities between NIS1 Landscape, Risk Assessment and Foresight findings; and NIS2 directives is demanding in effort both during the transposition process and for the subsequent supervision • Specific priorities identified by EU MSs, as expressed 93 of these entities by national competent authorities. in Council Conclusions on the future of cybersecurity, a survey by the NIS Cooperation Group (NIS CG) and At the same time, important and substantial EU ENISA ’s discussions with MSs in various fora (e.g. NIS
horizontal legislation (EUCC, CRA, CSOA) has been
Cooperation Group).
adopted recently or is about to be adopted. For
instance, in view of the application of the EUCC, MSs are The selected areas were validated by the NIS CG and the now working on establishing capabilities for assessing European Commission. conformity including accreditation and notification, market surveillance and enforcement. Similar efforts will need to be undertaken at a much larger scale for the CRA. In addition, one lex specialis to NIS2 (i.e. DORA) and a few sector-specific implementing or delegated acts
complementary to the horizontal policy framework (i.e.
electricity, aviation) were adopted. The coordination effort needed by the MSs to facilitate coherent implementation on a national level is significant (e.g. on security measures, incident reporting, vulnerability notifications, etc.) and will have to be followed by efforts to ensure compliance by the concerned entities themselves. It is paramount to avoid
fragmentation, duplication or overlap of cybersecurity legislation across the Union with sector specific
initiatives or lex specialis . The Council has called on the Commission to develop a clear overview of the relevant horizontal and sectoral legislative frameworks and their interplay . Moreover, it is important to leverage any
potential synergies.
• With respect to the notification of incidents, next two years. Based on discussions with MSs, NCAs implementation of the various laws could leverage will also need to augment their cybersecurity staff in synergies in order to avoid the creation of multiple, order to address the growing volume of tasks and the independent data sets on incidents. Fragmentation expanded scope of NIS2. would limit the benefits to situational awareness of • Guidance and support for NCAs is needed to having access to the full picture of information on accompany the implementation process, given the incidents. wide coverage of the horizontal legislation and also • The impact of various legislative instruments on the the interplay with other relevant pieces of legislation. entities could also be considered. For instance, data Likewise, timely guidance and support provided to relating to NIS Investments in 2023 reveals that the entities within the scope can help them better prepare primary legal driver of cybersecurity investments in for compliance. Discussions with the MSs highlight the the Transport sector is the NIS Directive (55% of the following topics (non-exhaustive): transport OESs who were interviewed report such a driver), followed by transport industry-specific security • The understanding of the NIS2 scope and requirements (27% of the transport OESs) and legal annexes; requirements such as GDPR (12% of the transport OESs). The lone exception is the Aviation sector, where • The interpretation of the GDPR in relation to the sectorial legislative requirements actually top the NIS2; priorities list over NIS with 45%. • Interpretations of what constitutes a significant • The issue of skilled resources in order for entities to incident in various sectors; comply with the new legislative framework has been documented in the 2023 NIS Investments report with • The way that horizontal and sectorial legislation over half of the entities within the scope of the NIS relates, such as NIS2 and DORA or NCCS, or the planning to hire new cybersecurity staff (median of way horizontal legislation relates to technologytwo new staff members per organisation) over the based legislation such as AI-Act and EUDIF.
Ongoing work
The NIS CG has established several work streams (e.g. on incident reporting, security measures etc.) to support harmonised implementation of NIS2 across MSs in several dimensions. Moreover, the NIS CG has established interfaces to collaborate with national authorities responsible for the implementation of sectoral legislation to identify and address any potential overlaps and gaps. The input provided by the NIS CG is highly valued and essential for achieving a consistent and harmonised implementation across MSs. This includes the mapping of national solutions and experiences, the discussion of challenges to implementation, and the elaboration of concrete recommendations and guidelines for both the MSs and the EC.
3.1.2 Identification and Supervision 3.1.3 Cybersecurity risk management measures
When it comes to the national transposition of NIS2, the
process to establish a list of essential and important The majority of MSs have defined cybersecurity risk entities by the MSs is at an advanced stage (progress is management measures for essential and important
assessed at 62% with 22 MSs close or above this average). entities.
• The majority of the MSs are currently drawing up a list • Two-thirds of the MSs have documented cybersecurity of essential and important entities. baselines for essential and important entities, while the rest are in the process of identifying and • Around two-thirds of MSs are in the process of documenting them. In addition, 41% of the MSs creating a list of essential and important entities that have established an informal or formal process for are SMEs, while most of the rest have completed this reviewing and updating these measures. process. • The adoption of legislation setting cybersecurity • The list of essential and important entities is expected requirements for the newly added sectors of NIS2 is to be kept up to date (for the majority of the MSs). ongoing in the majority of the MSs.
The implementation of supervisory measures varies • Almost all MSs require measures on policies on risk among MSs. It appears too early in the transposition analysis and cybersecurity, incident handling and process to collect data on compliance to the measures for business continuity. More than two-thirds require the all entities under NIS2. remaining cybersecurity risk management measures defined in Article 21. • One-third of the MSs indicated that more than 80% of the NIS2 entities are subjected to supervisory It is expected that all the above indicators will change measures by the relevant national competent after the transposition of NIS2. Moreover, for the types authorities. The rest of the MSs indicate lower of entities listed in Article 21(5) a more harmonised EU percentages that vary. approach to cyber risk management is foreseen with the • Regular cybersecurity audits are performed in more adoption, in October, of the Implementing Regulation than two-thirds of the MSs, either by a dedicated 2024/2690 on cybersecurity risk management for specific supervisory authority or by independent third parties. categories of entities providing digital services. We expect Only a very limited number of MSs has no mechanism that the Implementing Regulation, pursuant to NIS2 to check compliance. The percentage of essential Articles 21(5) & 23(11), will reshape and harmonise the and important entities for which compliance data is cybersecurity risk management measures for the sectors collected varies significantly among MSs. concerned.
Good practices from Member States
Supervision can be carried out differently, depending on the country’s needs. Examples include working closely together with the entities on how to assess conformity as well as offering conformity assessment services to the entities on a voluntary basis relying on third-party support.
Cybersecurity risk management measures for essential and important Info box entities under NIS2 Cybersecurity risk management measures (article 21)
Type: appropriate and proportionate technical, • Policies on risk analysis and information system operational and organisational measures security;
Aim: (a) to manage the risks posed to the security • Incident handling; of network and information systems which • Business continuity, such as backup management those entities use for their operations or for the and disaster recovery, and crisis management; provision of their services and (b) to prevent or
• Supply chain security, including security-related minimise the impact of incidents on recipients
aspects concerning the relationships between each of their services and on other services. entity and its direct suppliers or service providers;
Risk-based approach: level of security of network • Security in network and information systems
and information systems is appropriate to the
acquisition, development and maintenance, risks posed, taking into account the state-of-the
including vulnerability handling and disclosure;
art and the cost of implementation.
• Policies and procedures to assess the effectiveness
Proportionality: taking account of the degree of of cybersecurity risk-management measures;
the entity’s exposure to risks, the entity’s size • Basic cyber hygiene practices and cybersecurity and the likelihood incidents may occur and their
training; severity, including their societal and economic
impact. • Policies and procedures regarding the use of
cryptography and, where appropriate, encryption; All-hazards approach: protect network
and information systems and the physical • Human resources security, access control policies environment of those systems from incidents. and asset management;
• The use of multi-factor authentication or
continuous authentication solutions, secured voice, video and text communications and secured emergency communication systems within the
entity, where appropriate.
When it comes to the implementation of cybersecurity risk • 45% of the OESs and DSPs declared good or management measures, we see significant deviations mature cyber risk management capabilities, while among entities, which are dependent on the size of the 23% declared having only limited or none such company and the maturity of the sector. capabilities . Likewise, 49% declared good or mature incident detection and response capabilities, and 18% • In 2023, Operators of Essential Services (OESs) limited or none such capabilities. In both of these and Digital Service Providers (DSPs) under the 95 areas, we noted wide deviations between sectors, NIS1 Directive spent 11.9% of their IT FTEs on with higher maturity being assessed in sectors such as information security, a decrease of 0.1% compared Banking, Energy, Healthcare and Transport, and lower to 2022, despite the overall increase in cybersecurity 96 maturity in sectors such as Digital infrastructures and spending . At the same time, the percentage of IT Drinking water. budgets going to cybersecurity varies significantly among sectors, ranging between 5% and 10%.
• According to Eurostat, as of 2022:
Ongoing work
• 83% of large enterprises in the EU apply at least one ICT security measure with 25 member states close to or above this figure. The percentage drops to 49% when considering SMEs in the EU. The portion of companies that apply all these ICT security measures is 17% for large enterprises and 4% for SMEs. Moreover, the measures examined by Eurostat are only a fraction of the measures under NIS2 for essential and important entities.
• 80% of large enterprises have documented measures, practices or procedures on ICT security In the past, the NIS CG and ENISA had created a and 58% have defined or reviewed an ICT security guideline on cybersecurity measures aimed at the policy within the previous 12 months (data entities to assist with conformity. The cybersecurity collected in 2022). But for SMEs, the numbers are measures were mapped to international standards much lower; 36% have documented measures, and good practices. ENISA is currently preparing a practices or procedures on ICT security and 23% similar document in collaboration with European have defined or reviewed an ICT security policy Commission and the NIS CG. On a national level, MSs within the previous 12 months. are also developing guidance for NIS entities on how the NIS2 measures for cybersecurity risk management • 72% of large enterprises perform risk assessments match national or international standards. to assess the risk of ICT security incidents, compared to 31% of SMEs.
Overall, the involvement of top management in
cybersecurity affects significantly whether security
Good practices from Member States
measures are implemented. The maturity of risk
management, incident detection and response, and the management of cyber risk by a third party are strongly Development of a correlated with the involvement of top management. ‘Managing Cyber Risks’ • Leadership approves management measures for handbook aimed at cybersecurity risk in 81% of the OESs and DSPs we senior management, surveyed in 2023 . For 50% of these organisations, providing leadership attends dedicated cybersecurity training. an overview and recommendations for • We also observed a very strong correlation between managing cyber risks. It the involvement of top management in cybersecurity formulates six basic principles and an organisation’s maturity in the management of to help management and supervisory boards analyse cyber risk and in its incident detection and response cyber risks and is complemented by a toolkit of capabilities. In both cases, organisations whose helpful questions and answers to raise awareness of leadership is active in cybersecurity are more than cyber security at senior management level. twice as likely to score above the basic level.
Good practices from Member States
Monitoring the implementation of cyber risk management measures in a particular sector (e.g. public administration) can be achieved by collecting national statistical information via a self-assessment tool or audits.
3.1.4 Information sharing and reporting One of the most prominent areas of information sharing obligations: institutional framework and concerns cybersecurity incidents. A number of EU legal acts practice contain provisions (and, in some cases, obligations) for entities falling under their respective remit to report incidents to A functioning cooperation among relevant actors is a pre- the competent authority. The implementation of reporting requisite for the effective sharing of information. The NIS2 provisions relies on the establishment of dedicated processes Directive outlines obligations for national-level cooperation, and tools, as well of a common understanding of what applying to competent authorities, single point of contacts constitutes an incident and how it shall be communicated. 100 108 (SPOCs), and CSIRTs (hereby referred to as ‘NIS2 entities’). NIS2 (formerly NIS1), European Digital Identity Framework 109 110 They are expected to cooperate among themselves and also, (EUDIF formerly eIDAS ) and EECC are the main pieces to various degrees, with the authorities responsible for specific of EU legislation mandating the reporting of incidents with domains, e.g. those competent for the financial sector under a significant impact . They apply respectively to essential DORA . Overall, the state of national cooperation is fairly and important entities, trust services providers and good; the MSs that have not yet reached full maturity telecommunication services providers .
in terms of cooperation among NIS2 entities are taking action to progress. However, cooperation between NIS2 The implementation of obligations to notify incidents authorities and competent authorities under other pieces and the application of contextual measures are
102 generally advanced, although the implementation of the
of EU legislation is lagging behind in some MSs . requirements of NIS2 is still ongoing and some MSs lack
• Based on ENISA data , all MSs have either
dedicated reporting tools. The coherent implementation
established or are defining mechanisms for
of reporting obligations across EU legislation and MSs will
cooperation among NIS2 entities. This also includes
be crucial for the effectiveness of such requirements.
the notification of incidents, threats and near misses 104 • Based on data ENISA collected from the MSs, the to CSIRTs or competent authorities . More than twothirds (21 MSs) have either implemented or are in the introduction of legal provisions for the notification of process of implementing the flow of such information incidents, to ensure that specific organisations notify the from the CSIRTs or competent authorities to the relevant authorities of incidents with a significant impact, 105 is almost complete for providers of telecommunication national single point of contact . services providers (as per Article 40 of the EECC) (24 • All MSs have either implemented or are defining MSs) and trust services providers (as per Article 19 of measures to ensure that the NIS2 competent 113 the eIDAS Regulation ) (25 MSs). The implementation authorities and the authorities competent for critical of notification requirements for essential and important entities (under the Directive 2022/2557) cooperate entities mandated by NIS2 Article 23 is still progressing and exchange information on a regular basis, e.g. on (15 MSs). It is to be noted that NIS2 Article 23.11 gives risks, threats and incidents affecting critical entities . the EC the possibility of adopting implementing acts • About two-thirds of MSs have taken action to ensure to further specify the type of information, the format that the NIS2 competent authorities exchange, on and procedure for the notification of an incident. The a regular basis, information on cyber incidents and article also requires the EC to adopt implementing acts threats with the authorities competent for electronic further specifying, for certain types of entities, the cases identification and trust services (Regulation 910/2014 in which an incident is considered to be significant. This - eIDAS) (19 MSs); for the financial sector (Regulation is currently being done for the digital infrastructure and 2022/2554 - DORA) (17 MSs); or for electronic ICT service management sectors, a practice that could communications services (Directive 2018/1972 - EECC) be extended to other sectors where streamlined and (18 MSs). harmonised guidance at the EU level would be beneficial.
• Most MSs (23 MSs) have defined and documented a national taxonomy for the classification of cyberincidents, as well as thresholds for their evaluation (24 MSs). Dedicated tools to facilitate the reporting processes have been put in place in 22 MSs.
• The review of NIS1 was driven, among other factors, by the fact that MSs interpreted incident reporting requirements differently. This issue might persist as MSs might operationalise the reporting requirements of EU 114 115 legislation (e.g. NIS2, DORA, NCCS and Aviation ) in differing ways, with national contexts and specificities sometimes making it difficult to align on notification timelines and the definition of incidents.
Main incident reporting obligations in the EU legislation Info box
NIS1 compared to NIS2
NIS 1 NIS2
Article 13 sets the obligation for Member States Article 23 sets the obligation for Member States to
to ensure that operators of essential services ensure that essential and important entities notify any
(OESs) notify the competent authority or the CSIRT incident that has a significant impact on the provision
of incidents having a significant impact on the of their services. continuity of their services.
Note: The deadline for the Member States to transpose the
Article 16 sets the obligation for Member States to Directive was 17 October 2024. ensure that providers of certain digital services (online market places, online search engine, cloud computing) (so called Digital Service Providers - ‘DSPs’) notify the competent authority or the CSIRT of any incident having a substantial impact on the provision of their services.
eIDAS Regulation compared to the European Digital Identity Framework
eIDAS Regulation European Digital Identity Framework (EUDIF)
Article 19 sets the obligation for qualified and The reporting obligations for trust service providers falling non-qualified trust service providers to notify any under the scope of NIS2 will be driven by NIS2 provisions, breach of security or loss of integrity that has a as explained in recital 50. Some reporting obligations significant impact on the trust service provided or are still set by EUDIF. In particular articles 19a and 24.2 on the personal data maintained therein. require, respectively, non-qualified and qualified trust service providers to notify any security breaches and service disruptions with a significant impact on the service or the personal data maintained therein. Note: The European Digital Identity Framework entered into force in May 2024.
EECC
Article 40 sets the obligation for Member States to ensure that providers of public electronic communications
networks or of publicly available electronic communications services notify security incidents that have a
significant impact on the operation of networks or services. It is to be noted that EECC Art. 40-41 is repealed by
NIS2 as of 18 October.
DORA
Article 19 mandates the reporting of major ICT-related incidents to the relevant competent authorities.
Aviation
Organisations shall report any event having an actual adverse effect on the security of network and information systems .
The number of incidents reported shows consistency • The ENISA NIS Investment studies indicate that,
over the years (EECC) or an increase (NIS1, eIDAS).
in 2021 and 2022 respectively, 11% and 6% of the
This can be explained by the threat landscape, but it
surveyed OESs and DSPs declared that they had
is likely also a sign of progress both in the maturity of
experienced a major security incident. However, 12%
the reporting frameworks themselves as well as in the
and 10% respectively did not want to disclose this kind
reporting capabilities of the entities concerned. Still, the
number of reported incidents seems to be low, which of information. probably means that incidents are under-reported. 119 • According to Eurostat , in 2022 there were 30,017 • In terms of actual reporting, the reporting framework large enterprises working in relevant sectors in the of the EECC seems to be the most established, with a EU . Assuming that all of them were OESs or DSPs steady annual number of reported incidents over the and that each incident was reported by a different last ten years. OES or DSP and taking into account the year when most significant incidents were reported (2023, with • The number of significant incidents affecting OESs 1,049 incidents for both OESs and DSPs), this suggests and DSPs under NIS1 increased from 880 incidents that approximately 3.5% of OESs/DSPs in the EU have reported in 2022 to 1049 in 2023 . Similarly, the experienced a significant incident. number of reported security breaches affecting trust services (eIDAS) also increased significantly in 2023 • In 2019, the total number of OESs that were reported 118 to the Commission by Member States ranged from with respect to the past . 20 to 10,897 with an average of 633 OESs per • Although the data above concerns only incidents with 121 Member State . Again, taking into account the an impact considered ‘significant’, hence a sub-set of significant incidents reported in 2023, and assuming the overall number of incidents, their number has that each incident was reported by a different OES, been assessed as probably underestimated based approximately 6% of OESs in the EU have experienced on discussions with the NIS CG and the general a significant incident. reluctance of organisations to share this kind of information (see first bullet point). Still, it is difficult to determine with precision whether all incidents with a significant impact have been reported:
Ongoing work
or crises. A key example of this work is the Quarterly EU Joint Cyber Assessment Report developed by the Agency together with CERT-EU and EC3 and with contributions from MSs that provide a regular situational picture about incidents, vulnerabilities and threats impacting the EU. This report maps the requirements outlined in CSA Art. 7(6) as well as being described in the Blueprint. The Agency is working on further integrating input from various communities including private sector and international partners .
The European Commission is developing, in In 2022 ENISA began developing capabilities to be able collaboration with ENISA and CERT-EU, a cybersecurity to monitor, collect and analyse incident vulnerabilities Situation Centre to collect and integrate information using information shared with the Agency on a voluntary from relevant sources and provide a real-time overview basis by stakeholders (including MSs and Union entities) of the threat landscape to the EU bodies. or due to legal requirements. In particular, the Agency has developed structured cooperation with CERT- EU and intensified cooperation with other relevant Union entities such as the EEAS, Europol EC3 and the Commission. This allowed the Agency to build situational pictures both on a regular basis as a preparedness tool as well as to provide input during large-scale incidents
Policy Recommendation: Strengthen the technical and financial support to EUIBAs and competent authorities and to entities falling within the scope of the NIS2 Directive to ensure a harmonised, comprehensive, timely and coherent implementation of the evolving EU cybersecurity policy framework using already existing structures at EU level such as the NIS Cooperation Group, CSIRTs Network and EU Agencies.
To achieve this recommendation the following actions are suggested.
• ENISA and/or the EC should consider mapping the • The NIS Cooperation Group, with the support of various legal requirements deriving from EU horizontal ENISA and the EC, should establish a single common and sectoral cybersecurity policies. In this context, the EU framework (including templates and data fields) NIS Cooperation Group, EU-Cyclone and the EU CSIRTs to report incidents under NIS2. Such a framework Network could be used to increase joint understanding could be the basis for exploring alignment with other of the complex elements of cybersecurity legislation reporting frameworks under other EU legislation. such as the NIS2 Directive, amongst others such as The framework could take into account the different the scope, incident reporting thresholds and security maturity levels of reporting practices and aim to measures. reduce the administrative burden on the entities and on the authorities. The framework could also allow • The EC with the technical support by ENISA, should for post-incident analysis, which can offer valuable help MSs ensure a unified approach on baseline insights to the entities concerned and act as an cybersecurity risk management measures for essential incentive for reporting. and important entities. NIS2 article 21.5 mandates the EC to adopt implementing acts laying down the • To support entities in their compliance with upcoming technical and methodological requirements for certain regulatory requirements, the MSs (e.g. via the NIS CG), entities for certain sectors within the scope of NIS2 with the support of ENISA, could establish information and provides the possibility to do so for other such sharing platforms with private sector entities to sectors. It is important that applicable measures are discuss implementation challenges and foster discussed with all the stakeholders concerned, and collaboration and alignment. in particular with the sectors involved, to ensure a • To address challenges in terms of resources, smooth implementation and take-up. external support could be made available to national • ENISA should support the MSs with non-binding competent authorities that deal with the supervision guidance on risk management aimed at entities and of the NIS2 Directive (e.g. via an EU support action). for specific sectors, taking into account standards and good practises. Such guidance could address implementation challenges faced by specific sectors in the NIS2 Directive or by SMEs and start-ups.
3.2 CYBER CRISIS MANAGEMENT This evolution of crisis management has brought into the picture new actors, roles and tasks. In this context, the Council in May 2024 called on the Commission to
Cybersecurity crisis management at EU level has matured swiftly evaluate the current Blueprint and, on this significantly in past years. At the time of the adoption of basis, propose a revised one in the form of a Council NIS1, in 2016, EU-level cooperation on crisis management recommendation. was still a relatively new area. The Commission’s recommendation on coordinated response to large-scale The Council Conclusions also emphasise the need for cybersecurity incidents (so called ‘Blueprint’) , adopted compatibility of cyber crisis management with existing and in 2017, addressed the roles of all relevant actors and emerging EU crisis management frameworks, procedures identified the need for a mechanism at operational level and structures. to connect technical and political levels. Accordingly, the EU-CyCLONe network of national cyber crisis management In parallel, the legislative framework needs to be matched authorities was set up on an informal basis in 2020. Since with joint technical capabilities and mutual assistance. For then, the situation has evolved rapidly; in 2022 NIS2 example, work is also being done to support the technical was adopted, including provisions covering cyber crisis capabilities of MSs to prevent and respond to large-scale management at the levels of the EU and MSs, and involving cyberattacks. Notably, ENISA provides both ex-post services specific organisations such as important and essential for incident management and response, as well as ex-ante entities. In particular, NIS2: services such as the assessment of capabilities .
• Formalises the establishment of a European cyber This section focuses on three important aspects of crisis liaison organisation network (EU-CyCLONe) to European crisis management: situational awareness, the support the coordinated management of large-scale capabilities of MSs and, in particular, of their CSIRTs and cybersecurity incidents and crises at operational CSIRTs Network’s members and MSs participation in cyber level , and strengthens the role of the CSIRTs exercises, intended as an indicator of preparedness. Network , composed of CSIRTs appointed by EU MSs and tasked, among other things, to promote swift and effective operational cooperation among them; • Mandates the designation of national authorities 3.2.1 Situational awareness responsible for the management of large-scale cybersecurity incidents and crises and the adoption of The foundation of crisis management is the availability of national large-scale cybersecurity incident and crisis 126 information and the capability to process it. Cyber threat response plans ; intelligence (CTI), open-source intelligence (OSINT), data • Mandates MSs to ensure that essential and important from private sources and from governmental sources, entities take appropriate and proportionate technical, reporting of incidents and near misses; these are only operational and organisational measures, including on some examples of the information sources that allow crisis management. the monitoring and analysis of cyber threats, events and incidents that ultimately will lead to the cyber situational To complement the framework of NIS2, it is important to awareness needed for crisis management. mention the CSOA, which further strengthens the context for cybersecurity crisis management; for example, it In order to support reliable and solid situational foresees a European Cybersecurity Alert System, made awareness at the EU level, several initiatives are being up of Cyber Hubs interconnected across the EU, and a carried out by European Union institutions, bodies and comprehensive Cybersecurity Emergency Mechanism. agencies, such as the European Commission, ENISA, the
EU Intelligence and Situation Centre (EU INTCEN), CERT-
Also relevant is the Cyber Crisis Management Roadmap EU and Europol’s European Cybercrime Centre (EC3). developed in the Council under the Czech Presidency in Still, a common, real-time picture encompassing all MSs 2022. and covering all aspects of situational awareness is
missing.
MSs also monitor their national cyber space and strive to risk assessment, this finding seems to indicate a need
share relevant information in a timely manner across the to provide easier access to CTI, especially for smaller
country and, when relevant, at the EU level . Overall, OESs and DSPs.
all countries monitor their cybersecurity threat level; 133 • The ENISA NIS Investments Report 2023 shows
however there are significant differences on the
that 70% of OESs and DSPs engage in collaboration
monitoring frequency and alerting modes. The latter is
or information-sharing initiatives and most of them
not necessarily an issue, while the former signals a lack
130 do so by using ISACs, either at the EU level (36% of
of capabilities in some MSs .
the total) or national level (9%). ISACs have emerged
• All countries are endowed with the means for as a successful tool to share information – especially
monitoring the cybersecurity threat level nationally, at the EU level – as sectors featuring European ISACs
which almost two-thirds of Member States (19 MSs) have the highest rates of participation in any kind of
use daily or 24/7. The remaining MSs monitor the information sharing activities. Still, such information
threat level weekly, monthly or only on specific sharing activities often limit access to SMEs, since 56%
occasions. of SMEs do not engage in similar activities.
• In case of need, all MSs are equipped to communicate It is to be noted that monitoring capabilities at the the threat level to essential and important entities, organisational level do not necessarily translate to better either in a manual/ad-hoc manner (13 MSs) or situational awareness at the national or EU level. As with minimum human intervention (14 MSs). While highlighted in section 3.1.4, despite important advances, timeliness of information sharing is obviously crucial
the significant cybersecurity incidents reported at the
in the context of a crisis, the choice of the means
EU level are probably only a sub-set of the incidents
of communication (manual vs automated) does not
that actually took place and, in general, enterprises,
necessarily reflect the level of maturity, as it can be
especially SMEs, might not report e.g. for reputational
dictated by factors such as a more limited number of
reasons, lack of awareness or obligation to report.
essential and important entities or a more tailored
Indeed, the share of SMEs that declared that they have
approach to alerting.
not experienced incidents is strikingly high, when compared to large enterprises.
Single organisations perform threat monitoring also; for
example, a company might have its own Security Operation • According to Eurostat, which regularly conducts a
Centre (SOC) to detect and respond to cyber threats and/ survey among enterprises on their ICT security , the
or it could access relevant information by purchasing number of enterprises in the EU declaring that they
Cyber Threat Intelligence from specialised companies. have experienced at least one ICT security incident in
Another way for organisations to access and also to 2021 is 22.2% , although the source of the incidents
exchange information is through participation in industry is generally non-malicious . It needs to be pointed
associations or Information Sharing and Analysis Centres out that entities are generally reluctant to report
(ISACs), i.e. organisations that provide a central resource incidents e.g. to avoid damage to their reputations.
for gathering information on cyber threats, root causes • The biggest share of the incidents declared led to the and incidents as well as sharing experience, knowledge 131 unavailability of ICT services, though the experiences and analysis . Comprehensive public data on the actual of large enterprises and SMEs differed significantly monitoring capacity of enterprises is scarce, however ENISA in this respect; 65.9% of large enterprises and 82.3%
data shows that the capabilities of OESs/DSPs to collect
of SMEs did not experience such incidents. Although and exchange information are not yet mature. A large 138 large enterprises likely experience more incidents ,
share of OESs/DSPs does not have a Security Operation
the relatively high share of SMEs that have not
Centre (SOC) and – with some exceptions – they do not
experienced security incidents is somehow striking
invest significantly in CTI. This share is much bigger for
and might indicate an even more marked reluctance in
SMEs. ISACs have emerged as a successful tool to share
‘admitting’ they had suffered from such an incident.
information at the EU level.
• Further analysis does not indicate substantial • According to the ENISA NIS Investments Report 132 differences for incidents leading to data destruction/ 2022 , 37% of the OESs and DSPs do not operate a corruption or disclosure of confidential data; on dedicated Security Operation Centre (SOC) and this average, more than 90% of both large enterprises and figure increases to 76% for SMEs. SMEs did not experience such security incidents in
• OESs and DSPs spend on median EUR 50,000 per 2021.
annum on Cyber Threat Intelligence (CTI), though data
indicates that most organisations do not earmark vast
budgets for CTI, while larger operators — especially
within the banking sector — do invest significantly
in CTI. Considering that CTI is a valuable source of
information in the context of incident prevention and
3.2.2 National CSIRTs 3.2.3 National capabilities: Cyber-exercises
CSIRTs have important operational functions in the The management of a cyber crisis starts before the crisis collaboration and co-ordination both at the national level itself begins, with specific actions to ensure preparedness. and between national and international communities and The organisation of simulation exercises to test procedures, organisations . CSIRTs act as a first line of response to cooperation and fluidity of action in the event of a cyber incidents and often act as producers of situational crisis is regarded as an important component of crisis awareness for the public, businesses and decision- management. In general, the objectives of exercises are makers. As such, CSIRTs and those that are part of the to test processes at the EU and national levels, improve CSIRTs Network in particular form a crucial part of EU network coordination and detect or resolve vulnerabilities, cyber infrastructure and can be considered the technical raise awareness of players’ capabilities and train leadership frontline for incident response. Therefore, their relationship and staff . In 2023, the exercise Blue Olex gathered with cyber crisis management authorities and EU-CyCLONe together the high level executives of competent authorities is crucial. in 27 MSs who are in charge of cyber crisis management and/or cyber policy, the EC and ENISA. It was an Members of the CSIRTs Network are well-integrated in opportunity for these actors to exercise their interactions the wider international networks dealing with security with the newly formed EU-CyCLONe network at the EU issues. Their maturity, in terms of compliance with level . Shortly afterwards, representatives from national internationally recognised practices, could improve. electoral and cybersecurity authorities came together for This aspect is more pronounced among CSIRTs that are the exercise ‘EU ELEx’ to evaluate and strengthen their not part of the Network. Scalability of CSIRTs’ tooling, working methods should potential cybersecurity incidents also in support of processes automation, could help affecting the European elections occur. Lastly, this year in both in harmonising maturity and capabilities across June, the 7th edition of the exercise ‘Cyber Europe 2024’ the EU. took place. Cyber Europe is a series of pan-European 140 exercises organised bi-annually by ENISA, together with the • The ENISA CSIRTs Inventory lists 675 CSIRTs in the MSs and other European bodies. The exercise’s scenario MSs, of which 39 are members of the CSIRTs Network. envisioned attacks on the energy sector across the EU, • Most of the CSIRTs Network members (77%) are also that would also be targeting digital infrastructure and members of FIRST, the Forum for Incident Response public administration as secondary objectives to increase and Security Teams, which is an indicator of their pressure and incite chaos . integration in wider networks to deal with security issues. About one-third of them (31%) are either Participation in EU-level exercises is high, but it is not certified or candidates for (re)certification under always matched by structured national exercises, Trusted Introducer (TI) meaning that their security which might weaken the EU’s overall capacity to incident management procedures, infrastructures deal with a cybersecurity crisis. It has been noted and response capacity are aligned with internationally that exercises are being organised under several recognised standards. frameworks, hence avoiding ‘exercise-fatigue’ will be
an ever-important factor to ensure the effectiveness of
• These percentages are significantly lower among the
this high level of participation in exercises.
CSIRTs that are not part of the network; about half (46%) are members of FIRST and only 7% are either • Based on ENISA data , most MSs (24) conduct cyber certified or candidates for (re)certification under exercises, either at the national or EU/international Trusted Introducer. level and involve both the private and the public sectors (22 MSs). Indeed, participation in cybersecurity • In the last few years, CSIRTs witnessed a sharp exercises organised at the EU-level is high. increase in the constituency they serve; for example, more sectors are considered as important or • About half of MSs (12) has a defined and established essential in NIS2 and the CSIRTs’ role in the case of programme at the national level but fewer (11) feature cybersecurity crises has been strengthened. CSIRTs a process to incorporate lessons learnt and new also have a role in vulnerability management under testing needs. Although some MSs use international CRA. In light of this, the efficacy and efficiency of exercises to also test national procedures, the lack procedures will probably need to rely on tools that of structured national exercises might weaken the support the automatization of processes and that are national foundations of EU-level crisis management. scalable and interoperable across the EU.
A common, real-time picture encompassing all Member States and covering all aspects of situational awareness is missing. In order to support EU-level situational awareness, several initiatives are being carried out by EU institutions, bodies and agencies. Policy Recommendation: As called upon by the Council, the European Commission, when proposing a revision of the EU Blueprint for coordinated responses to large-scale cyber incidents, takes into account all the latest EU cybersecurity policy developments. The revised EU Blueprint should further promote EU cybersecurity harmonisation and optimisation, as well as strengthen both national and EU cybersecurity capabilities for levelled up cybersecurity resilience at the national and European levels.
Without prejudging the role of the mandated actors, crisis be achieved by increasing synergies and coherence management could be enhanced as follows. among crisis management mechanisms, procedures, tasks and actors, as well by defining with more Share situational awareness precision the mandate and responsibilities of each actor. • MSs and national CSIRTs could seek to improve common situational awareness at the national and • EU MSs could consider measures in their national cross-border levels through their participation in cybersecurity programmes to facilitate participation the CSOA European Cybersecurity Alert System and in information sharing initiatives and access to CTI for leverage their opportunities for the development of the entities under NIS2. interoperable tools, infrastructures and services. • EU MSs could prioritise the maturity of CSIRTs (e.g. • As per the CSA, Article 7(6), ENISA, in close cooperation by supporting their certification) as well as ensuring with the MSs, prepares regular in-depth EU adequate tooling e.g. through coordination within Cybersecurity Technical Situation Reports on incidents the CSIRTs Network on the development – also at the and cyber threats (JCARs). ENISA and the MSs could EU level – of tools that support the automatization of improve collaboration on situational awareness to processes, and that are scalable and interoperable ensure coverage of the whole EU; MSs could increase across different countries. their active participation in structure and tools (e.g. • EU-CyCLONe could define a strategy to ensure that CSIRT Network) to exchange information, while participation in exercises is optimised to ensure consolidation of data and analysis could happen at coherent coverage of relevant aspects, including a the EU level by strengthening existing mechanisms stock-taking of national capabilities (e.g. by sharing concerning information flows between both the MSs information on different exercises being organised and the EU, as well as among EU bodies. to facilitate rationalisation) and taking into account the latest risk scenarios at the EU level such as those
Enable effective and timely response and clear
developed under the cyber posture process (https://
communication
digital-strategy.ec.europa.eu/en/news/risk-assessment- • EU MSs and Union entities could further streamline report-cyber-resilience-eus-telecommunications-andand consolidate crisis management processes in electricity-sectors). order to be able to constitute a stronger common front for incident management and response. This can
exercise has revealed that the skills shortage remains In an evolving cybersecurity landscape with geopolitical among the list of top 10 threats, while its long-term uncertainties, cultivating a cybersecurity culture through perspectives have intensified somewhat, climbing awareness, retaining cybersecurity talent and improving from number 8 to number 2 of the relevant future relevant skills are crucial aspects for addressing current challenges from 2023 to 2024. and upcoming challenges. Putting people at the centre of • Finally, based on a recent Eurobarometer analysis , the digital transformation of our societies and economies is 146 only 18% of companies seem to be aware of the at the core of the EU’s vision for the Digital Decade . European Cyber Security Skills Framework.
Cybersecurity skills: While the demand for people with Diversity and Inclusion: Gender imbalance in ICT and cybersecurity skills is rapidly increasing, the cybersecurity roles in the EU cybersecurity skills and talent shortage is growing too.
• When it comes to diversity and inclusion, according • Companies are facing severe difficulties in finding to a recent Eurobarometer analysis of cyber skills , appropriate candidates, when they have open 147 70% of companies surveyed agree that diversity positions . The lack of available cybersecurity and inclusion in cybersecurity are important in their professionals is a major concern, as around 70% of the organisations. companies surveyed that tried to hire staff with skills in cybersecurity (over the last 12 months) experienced • However, while two-thirds of companies agree that difficulties in recruitment. women are encouraged to take up roles and tasks
148 in cybersecurity, 56% of companies do not have any • According to the same analysis , 76% of employees women in cybersecurity roles . in cybersecurity-related roles did not receive any formal qualification or certified training. Almost 157 • The ENISA 2023 NIS Investments data disclose that one-third entered the role from a non-cyber related OESs and DSPs employ an average of 11% of women role, while more than half of employees absorbed in information security FTEs, while the median is zero cybersecurity responsibilities into an existing role. percent, meaning that most of the organisations
surveyed do not employ any women as part of their • Regarding the demand for skills, almost half of OESs information security FTEs. and DSPs (under NIS1) plan to hire information security FTEs in the next two years aiming to hire an • The ICT sector suffers from a severe gender imbalance average of 4 FTEs . Most of these hires are expected in the EU with 81% of employed ICT specialists in in the domain of cybersecurity operations (56%), 2022 being male while women account for 51% of the followed by IT security architecture and engineering 158 European population . (42%) and cybersecurity governance and risk (36%).
• 83% of OESs and DSPs claim they experience recruitment difficulties in at least one information Ongoing work
security domain, especially in the domain of IT security architecture and engineering (34%) . Embracing diversity and • The talent shortage affects all types of companies, gender balance is one including SMEs, which represent 99% of all businesses 151 of the aims of the in the EU . In fact, things may be worse for SMEs EU Cybersecurity as it was admitted that ‘there is a shortage of skills Skills Academy regarding cybersecurity’; in fact, they claim to be facing 152 (see below for difficulties in hiring for any cybersecurity domain . more information On top of that, it was admitted that SMEs usually do on the Academy). not have a Chief Information Security Officer (CISO), With a special focus but rather assign the relevant role to someone within on upskilling and the organisation, who may not have the necessary reskilling women, the cybersecurity skills and competencies. goal is to have gender convergence in cybersecurity positions by 2030. Several EU-level initiatives have been established in this regard, such as the EU
Good practices from Member States
Proactive engagement with private sector Dedicated resources to support SMEs in improving organisations through regular meetings, fostering their cybersecurity awareness and practices, such awareness and explaining the NIS2 Directive’s as a centralised hub with explanations of common requirements and their relevance to their businesses. cyber threats, step-by-step guides and downloadable resources or leveraging Public-Private Partnerships (PPPs) for SMEs so as to support enterprises with no internal capacity and expertise.
Cybersecurity training and awareness in enterprises: Enterprises’ Cyber hygiene: The state of cyber Enterprises in Europe understand the importance hygiene in the EU reveals a concerning gap between of cybersecurity but taking relevant action remains SMEs and large enterprises.
a challenge. SMEs lag in cybersecurity awareness 169 • Almost all large enterprises in the EU are using
compared to large enterprises.
at least one of the following ICT security measures, • There is a general consensus among companies with strong password authentication, a combination of one or more employees that cybersecurity is a matter at least two authentication mechanisms, encryption of high priority (71%) . techniques for data, data backup to a separate location, network access control, VPN, maintenance • Still, the numbers show that almost three-quarters of log files for analysis after security incidents and (74%) of companies have not provided any training performance of ICT security tests. or awareness raising about cybersecurity for their employees during the last twelve months (from April • Almost one-fifth of SMEs have defined or most 2023 until April 2024) . recently (within the last 12 months) reviewed their ICT security policy, a finding that has not improved • In most cases (68% of companies) there is a strong 170 since 2015 . This may indicate a lack of cybersecurity consideration and perception that no training or 165 awareness, management commitment or skilled awareness raising about cybersecurity is needed . personnel. In contrast, the respective percentage for • In the case of Small and Medium Enterprises (SMEs), large organisations is 58%, an improvement of almost about half of the companies (54%) make their 15 percentage points since 2015. employees aware of ICT-related obligations , while • While almost 80% of large enterprises have this is the case for almost all large enterprises (99%) document(s) on measures, practices or procedures This observation suggests that SMEs do not prioritise on ICT security, only one-third of SMEs maintain such cybersecurity awareness training due to immaturity, 171 documentation , which could be due to limited lack of recognition of its importance or budget resources among other reasons. constraints. • These findings are aligned with the observations made in a recent ENISA report, which states that the low level of cybersecurity awareness of personnel is considered one of the seven major challenges identified for SMEs .
Ongoing work
ENISA is mandated to support closer coordination The European Commission has recognised and and the exchange of best practices among MSs on responded to the skills shortage, by adopting and cybersecurity awareness and education, as shown launching the Cybersecurity Skills Academy , which in the Cybersecurity Education Roadmap and is aimed at fostering knowledge generation through demonstrated through initiatives such as the European education and training by working on a common Cyber Security Challenge, the European Cybersecurity framework of profiles for cybersecurity roles and Skills Framework and the Cybersecurity Higher associated skills, ensuring a better channelling and Education Database, known as CYBERHEAD. visibility over available funding opportunities for skillsrelated activities, calling on stakeholders to take action and defining indicators to monitor the evolution of the market.
Policy Recommendation: Strengthen the EU cyber workforce by implementing the Cybersecurity Skills Academy and in particular by establishing a common EU approach to cybersecurity training, identifying future skills needs, developing a coordinated EU approach to stakeholders’ involvement to address the skills gap and setting up a European attestation scheme for cybersecurity skills.
To achieve this recommendation: • Initiatives at European and national level conducted by public and private entities (PPP) to address shortages • ENISA and the European Commission are encouraged in the cybersecurity labour market should be to conduct an advanced skills gap analysis using the structured and systematic. European Cybersecurity Skills Framework to identify discrepancies between the supply of cybersecurity • ENISA and/or the EC are advised to expand training skills and industry’s needs and demand as identified. programmes, increasing accessibility across industries, MSs are invited to work closely with the EC and ENISA and fostering public-private partnerships. towards developing a monitoring framework related • When it comes to certification of cybersecurity skills in to workforce supply and demand. professionals, ENISA should initiate the development • To address the workforce shortage, EU MSs could of mutual agreements and the creation of a European ensure that a cybersecurity workforce strategy is Cybersecurity Skills Framework profile for specific reflected in their national cybersecurity strategies attestation schemes. and incorporate elements related to awareness, skills and education in accordance with Arts. 7(1) (h) and • The EC is invited to consider mobilising EU funds for 7(2) (f) of the NIS2 Directive and that, in particular, EU funded masters and PhD degrees under current or the lack of cybersecurity professionals is addressed. newly targeted issues due to the urgency of the EU’s MSs could propose in their roadmaps concrete actions security needs. Specific examples could involve the on attracting and retaining cybersecurity specialists. mobilisation of Erasmus Mundus thematic masters MSs could include measures and funding in their and Marie Sklodowska-Curie Actions. national cybersecurity strategies, targeting SMEs in • The European Parliament is encouraged to consider particular, to boost cyber hygiene and cybersecurity establishing special funding for master’s degrees investments in SMEs. Mentorship programs launched and training programmes for digital sovereignty and by MSs could be a powerful tool to address the gender cybersecurity using AI. imbalance. Efforts could also encourage the reskilling of employees, who come from other disciplines. • EU funded educational programmes are advised to consider expanding their programmes adding for • Considering the significant number of cyber incidents example new interdisciplinary topics that include targeting public administration, MSs are advised security and defence and new technologies, cyberto provide training for public sector employees on diplomacy etc, building on existing initiatives in the cybersecurity awareness and hygiene. framework of the European Education Area.
3.4 SUPPLY CHAIN SECURITY • In 2022, only 47% of the OESs and DSPs had
earmarked a dedicated budget for third-party risk management . Moreover, only 24% of the OESs and Threat groups demonstrate a continuous interest and DSPs had dedicated employees for third-party risk increased capability in supply chain attacks . In 2021, management (TRM). These percentages differ between ENISA assessed 24 examples of supply chain attacks sectors. For example, third-party risk management which took place between January 2020 and July 2021 . policy is less common in digital infrastructures (55%), The report reveals that strong security protection is no compared to the banking sector where 86% have such longer enough for organisations when attackers have 182 a policy in place .
already shifted their attention to suppliers.
• The percentage of OESs and DSPs with third-party risk management policies increases from 36% to 87% when ENISA discovered the following facts and figures. management signs-off on cyber risk management • 66% of supply chain attacks focus on the supplier’s measures. code, while advanced persistent threat actors • When assessing their third-party risks, 61% of the (APTs) are developing alarmingly sophisticated OESs and DSPs take into account whether a supplier methodologies for approaching and overwhelming 175 is certified, use security risk rating services (43%) and attack targets ; perform due diligence or risk assessments (37%). • This trend continued in 2023, as there was continued Moreover, the entities take into account the type of activity by threat actors making use of software update product or service (59%), the volume of spending with mechanisms to deliver malware to victims ; the supplier (47%) and whether or not the supplier is
subject to the NIS1 Directive (42%) . • An increased number of threat actors targeted identity providers, IT suppliers and managed service providers 177 Cybersecurity certification is a tool that allows product in 2023 ; vendors and service providers to demonstrate and • Threat actors focus on employees as an entry advertise the cybersecurity of their solutions, and for point for organisations, especially targeting those users to ensure the cybersecurity of the services and with privileged access by using social engineering products that they acquire. Internationally the number techniques ; of schemes and assessment methodologies is growing
over the years.
• Supply Chain Compromise of Software Dependencies is considered the top emerging threat among the • Regarding the Common Criteria scheme for ICT Cybersecurity threats for 2030 . products, in 2024, 44% of the total assessment bodies
were in Europe. This number can be explained by the However, supply chain security appears to be the least SOG-IS (‘Senior Officials Group Information Systems developed area in terms of cybersecurity risk management Security’) Mutual Recognition agreement existing and NIS2 entities face a challenging task in assessing in the Union and signed by 17 MSs, which makes it and mitigating supply chain risks. 74% of the MSs have possible to recognise evaluations up to the highest already defined, in their national legislation, supply assurance level of the Common Criteria, and that chain security measures for essential and important applies a lot to sensitive ICT products such as smart entities. The number is expected to increase further due cards and other hardware security modules broadly to the national transposition of NIS2 and the requirements 184 developed by EU industry . of the DORA regulation for the Finance sector, which place • In the past few years new schemes were born to particular emphasis on cybersecurity risk management answer either sectoral needs, such as payments, measures offered by managed service providers. telecommunications or transport, or technological needs with, for instance, the rise of connected When examining whether entities already apply such devices . measures in 2023, it was discovered that 77% of OESs and
DSPs had a policy related to supply chain cybersecurity
• In terms of cryptographic products in the EU, the risk management from third-parties . However, large most important agreement that has dominated
enterprises are more likely to have a policy (85%)
the EU market is the SOG-IS Agreed Cryptographic compared to SMEs (53%). Even fewer entities have 186 Mechanisms , which will be onboarded into the
dedicated resources for supply chain cybersecurity.
EUCC scheme to become the EU-wide reference for These figures are affected by the maturity of the sector, size cryptographic algorithms and conformance testing for of the entity and the commitment of top management. security mechanisms.
The CRA introduces requirements for products and On 9 March 2022, an informal meeting of the obligations for manufacturers that will result in more Telecommunications Ministers in Nevers resulted in cyber secure products to be placed on the EU market. a joint call, the so-called ‘Nevers Call’, to reinforce the EU’s cybersecurity capabilities. It recognised that critical • 59% of the OESs and DSPs agree that common infrastructure such as telecommunications networks and requirements would lead to a reduction in compliance digital services are of the utmost importance for many costs for users as regards their supply chain. critical functions in our societies and are therefore a prime • 56% of the OESs and DSPs agree that common target for cyberattacks. The call described eight items for requirements would lead to lower costs of risk action, including the need to focus supply chain security mitigation for users. on the enhancement of the resilience of communications networks, the need to strengthen the market via public- • 61% of the OESs and DSPs agree that common private collaboration, the rapid adoption of the NIS2 requirements would reduce the number of security Directive and the need to build an ecosystem of trusted incidents and, as a result, the cost of managing and 187 cybersecurity service providers. recovering from such incidents .
At EU level, the NIS2 sets out the possibility for the NIS Moreover, on 17 October 2022, the Council issued its Cooperation Group, in cooperation with the Commission conclusions on ICT supply chain security , stating that it is and ENISA, to conduct coordinated security risk of utmost importance to appropriately take the geopolitical assessments of critical ICT supply chains (Article 22 of environment into consideration not only when reacting to NIS2). These coordinated security risk assessments of malicious cyber activities but also when building critical ICT supply chains ‘should take into account both and maintaining the resilience of information and technical and, where relevant, non-technical factors’, and communication technologies (ICT). The Council invited should follow an all hazards approach. However, in 2024, the NIS Cooperation Group, in cooperation with the the objective to ‘improve the cybersecurity of the Commission and ENISA, to develop a toolbox of measures supply chain’ was the least aligned objective among the for reducing critical ICT supply chain risks (ICT Supply 188 Chain Toolbox), which is currently being developed and is national cybersecurity strategies of the MSs . expected to be ready for adoption by the end of this year.
Good practices from Member States
The EU Toolbox on 5G cybersecurity (EU 5G Toolbox) published in January 2020 aims to address risks related to the cybersecurity of 5G networks . It identifies and describes a set of strategic and technical measures, as well as corresponding supporting actions to reinforce their effectiveness, which may be put in place in order to mitigate the risks identified. MSs are currently implementing the various measures at national level on a voluntary basis.
3.4.1 Vulnerability handling and disclosure • In 2022, 48% of the OESs and DSPs had implemented a risk-based vulnerability management process, with According to ENISA threat landscape 2023 , state- 26% covering only internet-facing assets and 22% nexus groups have an appetite for exploiting both old only covering critical assets. Whereas 37% of the OESs vulnerabilities and zero-day vulnerabilities. The report and DSPs had partially implemented a risk-based highlights that there are still a lot of older vulnerabilities vulnerability management process, it may be noted that can be exploited. Threat actors do not have to invest that only 15% did not have such processes at all. in zero-days as there are many known and unpatched • The sector with the highest share of organisations vulnerabilities available for abuse. This makes the timely without a risk-based vulnerability management handling of vulnerabilities by NIS2 entities very important. process is Online Search Engines (38%), while only 4% In fact, according to ENISA’s Foresight Cybersecurity Threats 192 of the organisations in the Banking sector do not have For 2030 , the exploitation of unpatched and out-of-date such processes in place. systems is considered one of the top 10 emerging threats for 2030. This can be particularly significant for sectors • The majority of OESs and DSPs (52%) had a rigid that have a large portion of legacy systems or particularly patching policy, in which only 20% or less of their long lifecycles for their ICT products, e.g. the energy and assets are not covered. On the other hand, 13.5% of transport sectors. the surveyed OESs and DSPs had no visibility over the patching of 40% or more of their information assets.
MSs are progressing in the definition and
These can be particularly challenging for organisations
implementation of national coordinated vulnerability
with wide geographic spreads or with OT systems.
disclosure (CVD) policies. Currently, the majority of the
MSs have taken steps but they are at different levels of • 46% of OESs and DSPs patch critical vulnerabilities in implementation. less than a month. Furthermore, an equal percentage of the organisations surveyed indicated that they • 37% of MSs have defined a national coordinated patch critical vulnerabilities within six months or less. vulnerability disclosure (CVD) policy. As such, one may reasonably conclude that 92% of OESs and DSPs patch critical vulnerabilities within at • 55% of MSs were currently in the process of defining least six months after their discovery. Only 8% of the such policies at the time data was being collected. organisations surveyed indicated that they exceed this • The majority of the national vulnerability disclosure time and take longer than six months to patch critical policies which are in place cover all NIS2 sectors (both vulnerabilities in their systems. essential and important entities). However, the new • The transport sector is characterised by very long- NIS2 sectors have the lowest coverage rate. life cycles for its products. In 2023, a deep dive into Vulnerability notifications are becoming more common in this sector indicated that 51% of organisations in the recent cybersecurity policy developments. For instance, transport sector need one month to patch critical NIS2, CRA, NCCS and the Regulation for EUIBAs all include vulnerabilities in IT or OT assets, and 21% need a time mandatory or voluntary vulnerability reporting. This results between 1 month and six months. Only 28% of the in the creation of vulnerability repositories that could be organisations surveyed fix critical vulnerabilities on leveraged to improve situational awareness. critical assets in one week.
When it comes to the entities under NIS2, ‘vulnerability handling and disclosure’ is one of the mandatory cybersecurity risk management measures that they have Good practices from Member States to apply. This was not an explicit requirement in the NIS1 directive. Currently, two-thirds of MSs include this measure in their national legislation. We expect more Assistance for NIS2 entities to include it as the transposition process advances. is needed to adopt a strong vulnerability management Regardless of whether the measure is mandatory or process. For example, not, even entities that were already within the scope of the national competent NIS1 as OESs and/or DSPs face challenges in handling authority can offer vulnerabilities. Dealing with vulnerabilities for the process templates for entirety of their assets or patching in a timely manner entities to adapt and use.
are practices which, currently, are not being fully implemented and we expect this gap to grow with the addition of new sectors and entities under NIS2. Such
challenges also depend on sector characteristics.
Policy Recommendation: Supply chain security should be further addressed by stepping up EU wide coordinated risk assessment and the development of an advanced EU horizontal policy framework for supply chain security, aimed at addressing the cybersecurity challenges faced both by the public and the private sectors.
To achieve this recommendation:
• In terms of vulnerability disclosure and handling, critical vulnerabilities could be monitored both at • The NIS Cooperation Group, in cooperation with national and EU level, and across various sectors. EU ENISA and the EC, could carry out systematic risk MSs are advised to monitor the time for a patch to assessments of critical supply chains in the EU. These become available by a supplier, and the time needed assessments could assess the risk stemming from for applying the patch by NIS2 entities. The latter could dependencies on high-risk third-country suppliers, but be part of the supervision mechanisms implemented they would also require significant effort and accurate by the MSs for NIS2 that refer to entities. data from national competent authorities.
• Several MSs have established or are preparing national • The EU MSs, with the support of ENISA, are CVD policies. In this context, EU MSs could offer encouraged to work closely with entities and specific incentives and funding for security researchers to sectors falling within the scope of the NIS2 Directive to actively participate in CVD research, either through identify ways and share good practices on managing national or European bug bounty programmes, or supply chain risks, especially software dependencies. through promoting and conducting cybersecurity Particular focus could be placed by national training. competent authorities on the supervision of categories of suppliers, such as managed service providers or • The public sector in MSs is advised to adopt managed security service providers. vulnerability management and disclosure policies and
could share templates for other entities to use.
Chapter IV
LOOKING AHEAD
NIS Cooperation Group set up a dedicated workstream Implementation of the NIS2 Directive, along with other that aims to support and facilitate strategic cooperation key cybersecurity legislation such as the CRA and the CSOA, will increase cybersecurity capabilities across the and the exchange of information among MSs on the Union. At the same time, recent significant improvements subject and that should serve as a forum to coordinate the in the overarching policy framework and established actions of MSs at the EU level with a view to facilitating the structures for cybersecurity across the EU can provide transition to PQC by developing a roadmap, taking into the basis for further development of cybersecurity account Commission Recommendation (EU) 2024/1101 of capabilities and enhance cyber resilience and effective 11 April 2024. In this context, it is critical to ensure that
cooperation among EU MSs. In this context the EU and its R&D&I funding is available for critical technologies
Member States should maximise the use of these existing and applications to support global competitiveness in structures to tackle any cybersecurity fragmentation cybersecurity and to reinforce the EU’s cybersecurity and shield the EU against threats. ENISA, the EU Agency capabilities. A more intense involvement in applying for Cybersecurity, could support the EU with technical disruptive technologies in cybersecurity, and a forwardknowledge and assessments of any future possible need leaning legislative approach could bring additional benefits for targeted reviews within the existing policy framework for the EU. and, especially, could support the EU in any effort aimed at mainstreaming cybersecurity robustness across EU’s The de facto cross-border nature of cybersecurity incidents policies. and the risks that come with it could be re-assessed in light of these new technological trends and the geopolitical Still, National competent authorities and EUIBAs alike context affecting the EU. The national authorities of MSs are faced with similar challenges when it comes not only and EUIBAs need to be prepared to answer tomorrow’s to implementing their new roles but also dealing with challenges in the area of cybersecurity, not only as the ever-evolving cyber threat landscape. New tasks vehicles for cooperation and support to operators but also and responsibilities do not always go hand in hand with in terms of safeguarding their own vital operational role. additional resources, human, financial or otherwise, and In this context, particular emphasis could be placed authorities and EUIBAs are confronted with the same skill on developing common situational awareness and gaps affecting entities in sectors of high criticality. While operational cooperation. While the framework already short- and medium-term measures to support them may exists, it needs to be tested to identify any potential prove sufficient for the fulfilment of the responsibilities shortcomings if and when the need for its full deployment arising from new legislation, the same cannot be said with arrives. Developing processes for international cooperation certainty about potential challenges that come with the beyond the Union would be an additional way to build up prevalence of new technological trends and the fast-paced situational awareness, particularly in the case of crossthreat landscape. border incidents whose impact extends beyond the EU’s borders. ENISA could also play a key role in this endeavour, In terms of emerging technologies, two topics have gained arising from its technical credibility internationally. traction over the past year, namely AI and Post-Quantum The EU cybersecurity policy and legal framework is being Cryptography (PQC). In order for MSs and the EU to put in place but will require time and resources to be react promptly to the challenges arising from these new fully implemented in order to provide the tools necessary technologies, effort should be placed on technical analysis to prepare for and respond to emerging cybersecurity to identify the needs for, and the impact of, potential challenges. It will be up to the stakeholders at national and future policy interventions, as well as implications for EU level to optimise its implementation and maximise its current legislation. For example, in the field of PQC, the efficiency.
Chapter V
ANNEX
ANNEX A: ABBREVIATIONS
AI Artificial intelligence AIA Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) CDN Content delivery network CER (Directive) Directive (EU) 2022/2557 of the European Parliament and of the Council of 14 December 2022 on the resilience of critical entities and repealing Council Directive 2008/114/EC CISO Chief Information Security Officer CRA Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) No 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act) CSA Regulation (EU) 2019/881 of the European Parliament and of the Council of 17 April 2019 on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology cybersecurity certification and repealing Regulation (EU) No 526/2013 (Cybersecurity Act) CSIRT Computer security incident response team CSOA Cyber solidarity act CTI Cyber-threat intelligence CVD Coordinated vulnerability disclosure CyberHEAD Cybersecurity Higher Education Database DDoS Distributed denial of service DMA Regulation (EU) 2022/1925 of the European Parliament and of the Council of 14 September 2022 on contestable and fair markets in the digital sector (Digital Markets Act) DNS Domain name system DORA Regulation (EU) 2022/2554 on digital operational resilience for the financial sector DoS Denial of service DSA Regulation (EU) 2022/2065 of the European Parliament and of the Council of 19 October 2022 on a Single Market For Digital Services (Digital Services Act) DSP Digital service provider EC European Commission ECSF European Cybersecurity Skills Framework EEAS European External Action Service EHDS European health data space
eIDAS Regulation (EU) No 910/2014 of the European Parliament and of the Council of 23 July 2014 on electronic identification and trust services for electronic transactions in the internal market ENISA EU Agency for Cybersecurity ETL ENISA threat landscape report EU European Union EUDIF Regulation (EU) 2024/1183 of the European Parliament and of the Council of 11 April 2024 amending Regulation (EU) No 910/2014 as regards establishing the European Digital Identity Framework EUCC European common criteria-based cybersecurity certification scheme EUIBAs EU Institutions, bodies and agencies of the Union Europol EC3 Europol’s European cybercrime centre FIMI Foreign information manipulation and interference FTE Full Time Equivalent ICT Information and communications technology IS Information Security ISAC Information Sharing and Analysis Centre IT Information Technology IXP Internet exchange point JCAR Joint cyber assessment report MS Member State NCA National Competent Authority NCCS Network Code on sector-specific rules for cybersecurity aspects of cross- border electricity flows NCSS National Cyber Security Strategy NIS Network and information security NIS CG Cooperation group, Art 14 of NIS 2 Directive NIS1 (Directive) Directive (EU) 2016/1148 of the European Parliament and of the Council of 6 July 2016 concerning measures for a high common level of security of network and information systems across the Union NIS2 (Directive) Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 1 Directive) NLO National Liaison Officer OES Operator of essential services OSINT Open-source intelligence OT Operational Technology PQC Post quantum cryptography R&D Research and development R&D&I Research, development and innovation RDoS Ransom denial of service RED (Directive) Directive 2014/53/EU of the European Parliament and of the Council of 16 April 2014 on the harmonisation of the laws of the Member States relating to the making available on the market of radio equipment and repealing Directive 1999/5/EC SMEs Small and medium-sized enterprises SOC Security Operations Centre TLD Top-level domain
ANNEX B: ENISA DATA SOURCES
SOURCE DESCRIPTION
Report
Education
Database
Threats for 2030
Report
ANNEX C: GLOSSARY OF TECHNICAL TERMS
TERM DESCRIPTION
Intelligence (CTI) decision making.
ANNEX C: GLOSSARY OF TECHNICAL TERMS
TERM DESCRIPTION
FOOTNOTES
Incidents - AVG in national AVG
international AVG graduates in AVG
Incidents - AVG vulnerability AVG
Citizens: internet use funding
MS 11 0
Incidents - AVG in national AVG
Catalogue number: TP-01-24-005-EN-N
international AVG graduates in AVG ABOUT ENISA
14 8 The European Union Agency for Cybersecurity, ENISA, is the Union’s agency dedicated to
Source TI Listed /Accredited / highest number of achieving a high common level of cybersecurity across Europe. Established in 2004 and
ENISA - CSIRTs by strengthened by the EU Cybersecurity Act, the European Union Agency for Cybersecurity
country map 10 15 contributes to EU cyber policy, enhances the trustworthiness of ICT products, services
and processes with cybersecurity certification schemes, cooperates with Member States SMEs: Security What does 100 mean 94,99 Coverage of What does 100 mean 41,87 and EU bodies, and helps Europe prepare for the cyber challenges of tomorrow. Through Incidents - AVG vulnerability AVG knowledge sharing, capacity building and awareness raising, the Agency works together with
Destruction or experience incidents 1,22 disclosure States, vulnerabilty 35,13 its key stakeholders to strengthen trust in the connected economy, to boost resilience of the
MAX MAX Union’s infrastructure, and, ultimately, to keep Europe’s society and citizens digitally secure.
data 27 3,41 1 58,13 More information about ENISA and its work can be found here: www.enisa.europa.eu.
Citizens: internet use funding
in R&D investments by European Union Agency for Cybersecurity
activities. MIN Investments MIN Chalandri 15231, Attiki, Greece
MS 11 0
Heraklion Office
95 Nikolaou Plastira
700 13 Vassilika Vouton, Heraklion, Greece
Source Source Rue de la Loi 107
authorities. -39,26 -21,31 1049 Brussels, Belgium
enisa.europa.eu
Fotnoter
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- 5 7 2020) . Several regulatory measures have been taken • The Cyber Solidarity Act (CSOA) is expected to
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- solidarity Act Implementation
- Cybersecurity Act Under development
- Cyber Resilience Act
- Artificial Intelligence Act RED
- Includes cybersecurity Electricity
- Network Code
- Digital Service Act Digital euro regulation Regulation for EUIBAs
- Chips Act
- Data Act
- No specific provisions Aviation -
- EU Health Horizontal rule Data Space
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- 0 JUL 23 AUG 23 SEP 23 OCT 23 NOV 23 DEC 23 JAN 24 FEB 24 MAR 24 APR 24 MAY 24 JUN 24
- 20242024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- 100 100 JUL 23 AUG 23 SEP 23 OCT 23 NOV 23 DEC 23 JAN 24 FEB 24 MAR 24 APR 24 MAY 24 JUN 24
- 1% PUBLIC ADMIN
- ICT SERVICE MANAGMENT
- GENERAL PUBLIC
- BUSINESS SERVICES
- DIGITAL INFRASTRUCTURE 8%
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- 49 54 challenges, especially for SMEs , the alarming rise of According to an ENISA study that analyses and
- Skill Shortage Human Error and Exploited Legacy Systems Within Cyber-Physical Ecosystems Supply Chain Exploitation of Compromise of Unpatched and Software Out-of-date Systems 10 Dependencies 5
- Physical Impact of Rise of Digital Natural/Environmental Surveillance Disruptions on Critical Authoritarianism / Digital Infrastructure Loss of Privacy
- AI 8 7
- Abuse of AI Cross-border ICT Service Providers as a Single Point of Failure Rise of Advanced Advanced Disinformation Hybrid Threats / Influence Operations (IO) Campaigns
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- The EU average is 62.65out of 100
- Deviation from the EU average Average
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- Gas Aviation
- Trust services
- LOW MODERATE HIGH
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- 20242024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- 20242024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- 153 3.3 CYBERSECURITY SKILLS • The ENISA Foresight Cybersecurity Threats 2030
- 159 160 Gender Equality Strategy , Women4Cyber , Women in Digital Scoreboard and Concordia Women in Cyber .
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- EUROPEAN CYBERSECURITY SKILLS FRAMEWORK
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- EU Cybersecurity The EU Cybersecurity Index is a framework, consisting of both quantitative and qualitative Index indicators, to describe the cybersecurity posture of the Member States and the EU.
- It serves as the core evidence base for the Report’s aggregated assessment of the level of maturity of cybersecurity capabilities and resources (mandated by Article 18.1(e)). It includes an assessment of the criticality and maturity of NIS1/NIS2 sectors using both quantitative and qualitative data.
- The Report only refers to EU-level data. The data set for the EU and the MSs has limited disclosure and it is not in the public domain.
- The methodological framework can be found on ENISA’s website: https://www.enisa.europa.eu/ topics/cybersecurity-policy/nis-directive-new/eu- cybersecurity-index
- Joint Cyber According to the CSA, ENISA shall prepare a regular EU Cybersecurity Technical Situation Report Assessment (JCAR) on incidents and threats based on open-source information, its own analysis and reports shared by, among others: Member States’ CSIRTs (on a voluntary basis) or NIS Directive Single
- The report has limited disclosure and is classified TLP: AMBER + STRICT.
- ENISA Threat The ENISA Threat Landscape report is the annual report of ENISA on the state of the Landscape cybersecurity threat landscape. The latest reports can be found here: https://www.enisa. europa.eu/topics/cyber-threats/threats-and- trends/?tab=publications
- NIS Investments This report aims at providing policy-makers with evidence to assess the effectiveness of the Report existing EU cybersecurity framework specifically through data on how OESs and DSPs invest their cybersecurity budgets and how the NIS Directive has influenced this investment through a large-scale survey of over 1,000 such operators.
- Cybersecurity The Cybersecurity Higher Education Database (CyberHEAD) is the largest validated Higher cybersecurity higher education database in the EU and EFTA countries. It has been the main point of reference for all citizens looking to upskill their knowledge in the cybersecurity field.
- This list allows young talents to make informed decisions on the variety of possibilities offered
- by higher education in cybersecurity and helps universities attract high-quality students motivated in keeping Europe cybersecure.
- ENISA Market ENISA has developed a Cybersecurity Market Analysis Framework to scope, customise and perform Studies market analyses. In the last few years, ENISA has analysed the market for IoT in distribution grids and for cloud cybersecurity.
- ENISA publications Based on the CSA, ENISA’s certification activities are featured in a dedicated website, which also covers on cybersecurity relevant publications. certification For example, the report uses the ENISA Market of Cybersecurity Assessments 2018-2022:https:// certification.enisa.europa.eu/publications/market-cybersecurity- assessments-2018-2022_en
- Foresight The ENISA Foresight Cybersecurity Threats for 2030 study represents a comprehensive analysis Cybersecurity and assessment of emerging cybersecurity threats projected for the year 2030. The study is grounded on a rigorous methodology and collaboration between experts and offers a forward-
- looking perspective on the evolving cybersecurity landscape.
- https://www.enisa.europa.eu/publications/foresight-cybersecurity-threats-for-2030- update- 2024-extended-report
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- Advanced This term is commonly used to refer to cyber threats, in particular that of Internet-enabled persistent threat espionage using a variety of intelligence gathering techniques to access sensitive information, but actors (APT) applies equally to other threats such as that of traditional espionage or attack.
- Cybercrime / The objective of cybercrime actors is financial gain or profits in general. Their attacks are Cybercriminals opportunistic and indiscriminate and they target the data or infrastructure that has the highest impact on the operations of victims. They can either steal directly from victims, can extort the victim or can monetise the information stolen from victims.
- Cyber Threat Data and information collected and analysed to understand the threat landscape and inform
- Data Breach An intentional cyber-attack brought by a cybercriminal with the goal of gaining to unauthorised access and release sensitive, confidential or protected data.
- Data Leak An event (such as misconfigurations, vulnerabilities or human errors) that can cause the unintentional loss or exposure of sensitive, confidential or protected data.
- DDoS DDoS targets system and data availability and, though it is not a new threat, it plays a significant role in the cybersecurity threat landscape.
- Deepfakes Deepfake software can create a synthetic video or image that realistically represents anyone in the world even if they were never actually performed that action or uttered that phrase.
- Hacker-for-hire Hacker-for-hire actors contribute to the professionalisation of the cybercrime market, but also provide services to State-nexus actors. The hacker-for-hire actors can lower the barrier to get access to the criminal market, such as for example with ransomware-as-a-service or RaaS.
- Hacktivists Hacktivists are not as well-resourced as other threat actors but are often fuelled by strong motivations. Their objectives often involve disruption and they use hacking to affect some form of political or social change. The hacktivists groups are very diverse and vary heavily in skillsets and capabilities.
- Incident An event compromising the availability, authenticity, integrity or confidentiality of stored, transmitted or processed data or of the services offered by, or accessible via, network and information systems.
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- Information Foreign Information Manipulation and Interference (FIMI) describes a mostly non-illegal pattern Manipulation of behaviour that threatens or has the potential to negatively impact values, procedures and political processes.
- Malware Malicious code and malicious logic, is an overarching term used to describe any software or firmware intended to perform an unauthorised process that will have an adverse impact on the confidentiality, integrity or availability of a system.
- Phishing A form of social engineering where attackers deceive people into revealing sensitive information.
- Ransomware A type of attack where threat actors take control of a target’s assets and demand a ransom in exchange for the return of the asset’s availability or in exchange for publicly exposing the target’s data.
- Social engineering Activities that attempt to exploit human error or human behaviour with the objective of gaining access to information or services.
- State-nexus actors State-nexus actors, are in general well-funded, resourced and advanced. Their objective is primarily espionage and disruption, sometimes directed by the military, intelligence or state control apparatus of their country.
- Vulnerability A weakness, susceptibility or flaw of ICT products or ICT services that can be exploited by a cyber threat.
- Wipers Disruptive malware designed to permanently delete or corrupt data.
- Zero-day A vulnerability that is unknown to the organisation developing/maintaining an asset and for vulnerability which no patch is available.
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- 1 https://eur-lex.europa.eu/eli/dir/2022/2555 26. See https://www.eurofound.europa.eu/en/covid-19-anddigitalisation and the special Eurobarometer 532 ‘The 2. See Annex B of this report. Digital Decade’, March 2023, available at https://europa.eu/ 3. http://data.europa.eu/eli/dir/2016/1148/oj. eurobarometer/surveys/detail/2959.
- 4 http://data.europa.eu/eli/reg/2019/881/oj. 27. Report on the state of the Digital Decade 2023. https://digitalstrategy.ec.europa.eu/en/library/2023-report-state-digital- 5. https://digital-strategy.ec.europa.eu/en/policies/cybersecurity- decade. strategy. 28. ENISA, CERT-EU, Europol (EC3), CSA Art. 7(6) Joint Cyber
- 6 https://eur-lex.europa.eu/legal-content/en/ Assessment Report Q1,Q2,Q3 2024. TXT/?uri=CELEX%3A32024R2847 29. ENISA Threat Landscape 2024 report, https://www.enisa.
- 7 https://digital-strategy.ec.europa.eu/en/library/proposed- europa.eu/publications/enisa-threat-landscape-2024. regulation-cyber-solidarity-act. 30. ENISA Threat Landscape 2024 report, https://www.enisa.
- 8 https://digital-strategy.ec.europa.eu/en/library/proposed- europa.eu/publications/enisa-threat-landscape-2024. regulation-managed-security-services-amendment. 31. ENISA Threat Landscape 2024 report, https://www.enisa.
- 9 http://data.europa.eu/eli/reg/2023/2841/oj. europa.eu/publications/enisa-threat-landscape-2024.
- 10 http://data.europa.eu/eli/reg_impl/2024/482/oj. 32. ENISA Threat Landscape 2024 report, https://www.enisa. europa.eu/publications/enisa-threat-landscape-2024.
- 11 https://www.eiopa.europa.eu/digital-operational-resilienceact-dora_en. 33. ENISA, CERT-EU, Europol (EC3), CSA Art. 7(6) Joint Cyber Assessment Report Q1,Q2,Q3 2024.
- 12 http://data.europa.eu/eli/reg_del/2022/1645/oj. 34. ENISA, CERT-EU, JP-23-01 - Sustained activity by specific
- 13 http://data.europa.eu/eli/reg_impl/2023/203/oj. threat actors, https://cert.europa.eu/static/files/TLP-CLEAR-
- 14 http://data.europa.eu/eli/reg_del/2024/1366/oj. JointPublication-23-01.pdf
- 15 http://data.europa.eu/eli/reg/2024/1183/oj. 35. One Year After: The Cyber Implications of the Russo-Ukrainian War - Sekoia.io Blog.
- 16 http://data.europa.eu/eli/reg/2014/910/oj. 36. European Parliament, https://www.europarl.europa.eu/
- 17 https://health.ec.europa.eu/publications/proposal-regulationdoceo/document/TA-9-2024-0380_EN.html. european-health-data-space_en. 37. European Union External Action, 2nd EEAS Report on
- 18 http://data.europa.eu/eli/reg/2024/1689/oj. Foreign Information Manipulation and Interference Threats,
- 19 http://data.europa.eu/eli/reg/2022/1925/oj. January 2024, https://www.eeas.europa.eu/sites/default/ files/documents/2024/EEAS-2nd-Report%20on%20FIMI%20
- 20 http://data.europa.eu/eli/reg/2022/2065/oj. Threats-January-2024_0.pdf.
- 21 http://data.europa.eu/eli/reg/2023/1781/oj. 38. ENISA Threat Landscape 2024 report, https://www.enisa. europa.eu/publications/enisa-threat-landscape-2024.
- 22 https://eur-lex.europa.eu/eli/reg/2023/2854. 39. ENISA, Foresight Cybersecurity Threats For 2030 - Update
- 23 ENISA Threat Landscape 2024 report, https://www.enisa. europa.eu/publications/enisa-threat-landscape-2024. 2024, https://www.enisa.europa.eu/publications/foresightcybersecurity-threats-for-2030-update-204-extended-report.
- 24 European Union External Action, 2nd EEAS Report on Foreign Information Manipulation and Interference Threats, 40. ENISA, CERT-EU, Europol (EC3), CSA Art. 7(6) Joint Cyber Assessment Report Q1,Q2,Q3 2024. January 2024, https://www.eeas.europa.eu/sites/default/ files/documents/2024/EEAS-2nd-Report%20on%20FIMI%20 41. ENISA Threat Landscape 2024 report, https://www.enisa. Threats-January-2024_0.pdf. europa.eu/publications/enisa-threat-landscape-2024.
- 25 ENISA Threat Landscape 2024 report, https://www.enisa. 42. Bitdefender - French Authorities Arrest Russian National europa.eu/publications/enisa-threat-landscape-2024. - https://www.bitdefender.com/blog/hotforsecurity/french-
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- authorities-arrest-russian-national-allegedly-connected-to- the cybersecurity of the supply chain; 11. Protect critical hive-ransomware/. information infrastructure, OESs and DSPs; 12. Address cybercrime; 13. Establish incident reporting mechanisms; 14. 43. Europol - Ragnar Locker ransomware operation taken - Reinforce privacy and data protection; 15. Establish a publichttps://www.europol.europa.eu/media-press/newsroom/ private partnership; 16. Institutionalise cooperation between news/ragnar-locker-ransomware-gang-taken-downpublic agencies; 17. Engage in international cooperation. international-police-swoop. For more on the assessment framework: https://www. 44. ENISA Threat Landscape 2024 report, https://www.enisa. enisa.europa.eu/topics/national-cyber-security-strategies/ europa.eu/publications/enisa-threat-landscape-2024. national-cyber-security-strategies-guidelines-tools/nationalcybersecurity-assessment-framework-ncaf-tool#/. For more 45. Europol, Internet Organised Crime Threat Assessment on the assessment framework: https://www.enisa.europa. (IOCTA) 2023, https://www.europol.europa.eu/publication- eu/topics/national-cyber-security-strategies/national-cyberevents/main-reports/internet-organised-crime-assessment- security-strategies-guidelines-tools/national-cybersecurityiocta-2023. assessment-framework-ncaf-tool#/.
- 46 Blackberry - BiBi Wiper Used in the Israel-Hamas War Now 63. 12 out of 17 objectives are covered in the strategies of 20+ Runs on Windows - https://blogs.blackberry.com/en/2023/11/ Member States. bibi-wiper-used-in-the-israel-hamas-war-now-runs-onwindows. 64. Joint Statement on Log4Shell — ENISA (europa.eu).
- 47 JPost - Hackers steal IDF patient records from cyberattack on 65. ENISA Threat Landscape 2024 report, https://www.enisa. Israeli hospital - https://www.jpost.com/israel-news/defense- europa.eu/publications/enisa-threat-landscape-2024 . news/article-775843. 66. EU Toolbox on 5G Cybersecurity, NIS Cooperation Group, 29 48. ENISA Threat Landscape 2024 report, https://www.enisa. January 2020. The EU Toolbox was adopted by the Member europa.eu/publications/enisa-threat-landscape-2024. States’ national cybersecurity authorities and endorsed by the European Council and the Commission. 49. ENISA, Foresight Cybersecurity Threats For 2030 - Update 2024, https://www.enisa.europa.eu/publications/foresight- 67. https://eur-lex.europa.eu/legal-content/EN/TXT/ cybersecurity-threats-for-2030-update-204-extended-report. HTML/?uri=OJ:L_202302841&qid=1724748319670.
- 50 ENISA, CERT-EU, Europol (EC3), CSA Art. 7(6) Joint Cyber 68. ENISA consolidated Annual Activity Report 2023, https://www. Assessment Report Q1,Q2 2023. enisa.europa.eu/publications/corporate-documents/enisaconsolidated-annual-activity-report-2023. 51. ENISA Threat Landscape 2024 report, https://www.enisa. europa.eu/publications/enisa-threat-landscape-2024. 69. The methodological framework can be found on ENISA’s website: https://www.enisa.europa.eu/topics/cybersecurity- 52. During the analysis, incidents were identified that relate to policy/nis-directive-new/eu-cybersecurity-index. services of sectors that are not currently within the scope of the NIS directive. These include consulting services, legal 70. ENISA consolidated Annual Activity Report 2023; https://www. services, hospitality services etc., and are grouped under the enisa.europa.eu/publications/corporate-documents/enisacategory ‘Business Services’ and represent 8% of the total consolidated-annual-activity-report-2023. events. 71. Including but not limited to the types of entities listed in 53. ENISA Threat Landscape 2024 report, https://www.enisa. Annex II of the NIS1 Directive. europa.eu/publications/enisa-threat-landscape-2024. 72. NIS2 introduces obligations that strengthen leadership 54. ENISA, Foresight Cybersecurity Threats For 2030 - Update involvement in cybersecurity (Art.20). 2024, https://www.enisa.europa.eu/publications/foresight-cy- 73. https://eur-lex.europa.eu/legal-content/EN/TXT/ bersecurity-threats-for-2030-update-2024-extended-report. HTML/?uri=CELEX:52023PC0209. 55. The EU Cybersecurity Index data set has limited disclosure 74. Eurostat, European Union survey on ICT usage in households and it is not public. More information is available in the and by individuals, 2020, https://ec.europa.eu/eurostat/ Annex of this report which provides an overview of data databrowser/view/isoc_cisci_prv20/default/table?lang=en. sources. 75. European Commission, Digital Decade Cardinal Points, 2023, 56. The indicators refer to the share of enterprises that have https://digital-strategy.ec.europa.eu/en/library/cardinaldeclared not to have suffer from such incidents. points-digital-decade-report-2023. 57. The related indicator uses the terminology of NIS1. 76. The Digital Economy and Society Index (DESI), 2022, https:// 58. On the basis of Trusted Introducer. digital-strategy.ec.europa.eu/en/policies/desi.
- 59 NIS2 - Article 7. 77. The Digital Economy and Society Index (DESI), 2022, https:// digital-strategy.ec.europa.eu/en/policies/desi. 60. https://www.enisa.europa.eu/topics/national-cyber-securitystrategies. 78. The Digital Economy and Society Index (DESI), 2022, https:// digital-strategy.ec.europa.eu/en/policies/desi. 61. https://www.enisa.europa.eu/publications/a-governanceframework-for-national-cybersecurity-strategies. The report 79. Eurobarometer, Special Eurobarometer 499: Europeans’ presents the situation as it was at the end of 2022. attitudes towards cyber security (cybercrime), 2020, https://data.europa.eu/data/datasets/s2249_92_2_499_ 62. These are the 17 objectives identified in ENISA’s National eng?locale=en. Capabilities Assessment Framework, namely: 1. Develop a national cyber contingency plan; 2. Establish baseline 80. Eurobarometer, Special Eurobarometer 499 : Europeans’ security measures; 3. Secure digital identity and build attitudes towards cyber security (cybercrime), 2020, trust in digital public services; 4. Organise cyber security https://data.europa.eu/data/datasets/s2249_92_2_499_ exercises; 5. Establish an incident response capability; 6. eng?locale=en. Raise user awareness; 7. Strengthen training and educational 81. Eurostat, European Union survey on ICT usage in households programmes; 8. Foster R&D; 9. Provide incentives for the and by individuals, https://ec.europa.eu/eurostat/ private sector to invest in security measures; 10. Improve
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- databrowser/view/isoc_cisci_prv20/default/table?lang=en. 99. ENISA NIS Investment study 2023, https://www.enisa.europa. eu/publications/nis-investments-2023. 82. Eurobarometer, Special Eurobarometer 499 : Europeans’ attitudes towards cyber security (cybercrime), 2020, 100. NIS2 Article 13. https://data.europa.eu/data/datasets/s2249_92_2_499_ 101. Regulation (EU) 2022/2554 on digital operational resileng?locale=en. ience for the financial sector: https://eur-lex.europa.eu/eli/ 83. ENISA, Data based on EU-Cybersecurity Index 2024 [ind. reg/2022/2554/oj. 4b, 6], https://www.enisa.europa.eu/topics/cybersecurity- 102. This finding and supporting data points below refer to the policy/nis-directive-new/eu-cybersecurity-index/eu_csi_ implementation of article 13.1, 13.2 and 13.3 (first data point), methodological_note_v1-0.pdf. article 13.5 (second and third data points). 84. ENISA, CyberHead - Cybersecurity Higher Education Database, 103. ENISA Data based on the EU-Cybersecurity Index, https:// CYBERHEAD - Cybersecurity Higher Education Database — www.enisa.europa.eu/topics/cybersecurity-policy/nis-direc- ENISA (europa.eu). The institutions participate in VyberHead tive-new/eu-cybersecurity-index/eu_csi_methodological_note_ upon interest, data is shared as obligation to be part of the v1-0.pdf. tool. 104. Articles 13.1 and 13.2. 85. ENISA, Cybersecurity Education Maturity Assessment, May 2024, Cybersecurity_Education_Maturity_report_en.pdf. 105. Article 13.3.
- 86 ENISA, Cybersecurity Education Maturity Assessment, May 106. Directive (EU) 2022/2557 on the resilience of critical entities: 2024, Cybersecurity_Education_Maturity_report_en.pdf. https://eur-lex.europa.eu/eli/dir/2022/2557/oj.
- 87 ENISA, Data based on EU-Cybersecurity Index 2024, https:// 107. NIS2 Article 13.5. www.enisa.europa.eu/topics/cybersecurity-policy/nisdirective-new/eu-cybersecurity-index/eu_csi_methodological_ 108. NIS2 Article 23. note_v1-0.pdf. 109. eIDAS Article 19. 88. ENISA, European Cybersecurity Skills Framework, https:// 110. EECC Article 40. www.enisa.europa.eu/news/developing-a-strongcybersecurity-workforce-introducing-the-european- 111. It is to be noted that NIS2 Article 30 foresees the voluntary cybersecurity-skills-framework. notification of (non-significant) incidents, cyber-threats and missing for important and essential entities, as well as the vol- 89. ENISA, CyberHEAD - Cybersecurity Higher Education untary notification of significant incidents, cyber-threats and Database, CYBERHEAD - Cybersecurity Higher Education near misses for entities other than essential and important Database — ENISA (europa.eu) entities. 90. ENISA, European Cyber Security Challenge, https://ecsc.eu/ 112. It is to be noted that NIS1, the obligation to report incidents, about. applies to Operators of Essential Services and Digital Service 91. https://year-of-skills.europa.eu/index_en. Providers (respectively under articles 14 and 16). Also, the obligation under eIDAS for trust services providers has been 92. European Commission, Cybersecurity Skills Academy, https:// integrated in NIS2; Regulation (EU) 2024/1183, amending eIdigital-skills-jobs.europa.eu/en/cybersecurity-skills-academy. DAS and establishing the European Identity Framework, refers to NIS2 for incident reporting. 93. https://www.consilium.europa.eu/en/press/press-releases/2024/05/21/cybersecurity-council-approves-conclu- 113. As explained in the info box, the reporting obligations for sions-for-a-more-cyber-secure-and-resilient-union/. trust service providers falling under the scope of NIS2 will be driven by NIS2 provisions. 94. Council Conclusions on the Future of Cybersecurity: implement and protect together cybersecurity, Brussels, 21 May 114. Network Code on Cybersecurity. 2024, https://data.consilium.europa.eu/doc/document/ST- 10133-2024-INIT/en/pdf. 115. Commission Implementing Regulation (EU) 2023/203 on Requirements for the management of information security risks 95. The data sources used for the analysis in some cases concern with a potential impact on aviation safety for organisations data on NIS1 entities and in others NIS2 entities. In the case and competent authorities: https://eur-lex.europa.eu/eli/ of the former, these entities will be referred to as OES/DSP reg_impl/2023/203/oj. whereas in the latter case as essential and important entities. 116. IS.D.OR.230 Information security external reporting scheme, 96. ENISA NIS Investment study 2023. https://www.enisa.europa. included in the Commission Delegated Regulation (EU) eu/publications/nis-investments-2023. 2022/1645 laying down rules for the application of Regulation (EU) 2018/1139 as regards requirements for the management 97. ENISA NIS Investment study 2023. https://www.enisa.europa. of information security risks with a potential impact on eu/publications/nis-investments-2023. aviation safety for organisations. 98. Source: Eurostat – European Union survey on ICT usage in en- 117. https://ciras.enisa.europa.eu/ciras-visual. terprises. Share of enterprises using at least one of the following ICT security measures: Strong password authentication, 118. Regulation 910/2014 (so called ‘eIDAS’) mandates in Article Combination of at least two authentication mechanisms (e.g. 19.2 ‘Where appropriate, in particular if a breach of security user-defined password, one-time password (OTP), code gen- or loss of integrity concerns two or more Member States, the erated via a security token or received via a smartphone, bio- notified supervisory body shall inform the supervisory bodies metric methods), Encryption techniques for data, documents in other Member States concerned and ENISA’. or e-mails, Data backup to a separate location (including backup to the cloud), Network access control (management of 119. https://ec.europa.eu/eurostat/statistics-explained/index. access by devices and users to the enterprise’s network), VPN php?title=Structural_business_statistics_overview#Size_ (Virtual Private Network extends a private network across a class_analysis, see database: https://ec.europa.eu/eurostat/ public network to enable secure exchange of data over public statistics-explained/images/d/d3/Structural_business_ network), Maintenance of log files for analysis after security statistics_overview09-11-2023v2.xlsx. incidents, Performance of ICT security tests. 120. Eurostat uses NACE’s classification. For the purposes
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- of this report, we have selected the following sectors: the surveyed OESs and DSPs declared that they had not expe- Manufacturing, electricity, gas, steam and air conditioning rienced a significant incident in 2022 and 10% did not share supply; Water supply; Sewerage, waste management information about significant incidents. and remediation activities; Transportation and storage; 138. https://www.enisa.europa.eu/publications/enisa-report-cyber- Information and communication; Financial and insurance security-for-smes. activities; Human health and social work activities. The selection is based on a rough mapping between the NIS1 139. https://www.enisa.europa.eu/publications/enisa-csirt-maturisectors and NACE: as such we are aware that it can only be ty-framework. an imprecise estimate, which is therefore used only to give an order of magnitude. Only large enterprises were considered 140. https://www.enisa.europa.eu/topics/incident-response/ as, based on the ENISA NIS Investments Report 2022, large csirt-inventory/certs-by-country-interactive-map. CSIRTs of enterprises represent the largest share of the surveyed OESs EUIBAs have not been included. Data cut-off date 09/04/2024.
- and DSPs (74%). 141. EC Exercise Guidelines.
- 121 Report from the Commission to the European Parliament 142. https://www.enisa.europa.eu/news/blue-olex-2023-gettingand The Council assessing the consistency of the approaches ready-for-the-next-cybersecurity-crisis-in-the-eu. taken by Member States in the identification of operators of essential services in accordance with Article 23(1) of Directive 143. https://www.enisa.europa.eu/news/eu-cybersecurity-exer- 2016/1148/EU on security of network and information cise-foster-cooperation-secure-free-and-fair-eu-elections. systems: https://eur-lex.europa.eu/legal-content/EN/ 144. https://www.enisa.europa.eu/topics/training-and-exercis- TXT/?uri=CELEX%3A52019DC0546. es/cyber-exercises/cyber-europe-programme/cyber-eu- 122. Commission Recommendation of 13.9.2017 on Coordinated rope-2024. Response to Large Scale Cybersecurity Incidents and Crises, 145. ENISA Data based on the EU-Cybersecurity Index, https:// C(2017) 6100 final. www.enisa.europa.eu/topics/cybersecurity-policy/nis-direc- 123. Commission Staff Working Document – Impact Assessment tive-new/eu-cybersecurity-index/eu_csi_methodological_note_ Report accompanying the proposal for NIS2: https:// v1-0.pdf. digital-strategy.ec.europa.eu/en/library/impact-assessment- 146. European Commission, 2030 Report on the state of the Digital proposal-directive-measures-high-common-level- Decade, https://commission.europa.eu/europes-digitalcybersecurity-across-union. decade-digital-targets-2030-documents_en. 124. Article 16. To know more, see: https://www.enisa.europa.eu/ 147. Eurobarometer analysis on Cyberskills, May 2024, https:// topics/incident-response/cyclone. europa.eu/eurobarometer/surveys/detail/3176. 125. https://csirtsnetwork.eu/. 148. Eurobarometer analysis on Cyberskills, May 2024, https:// 126. Article 9. europa.eu/eurobarometer/surveys/detail/3176,
- 127 These services take place in the framework of the ENISA 149. ENISA NIS Investment study 2023, https://www.enisa.europa. support action, https://www.enisa.europa.eu/publications/ eu/publications/nis-investments-2023, cybersecurity-support-action. 150. ENISA NIS Investment study 2023, https://www.enisa.europa. 128. In 2023 ENISA signed working arrangements with US CISA eu/publications/nis-investments-2023, and UA SSSCIP and UA NCSCC. 151. SME definition, https://single-market-economy.ec.europa.eu/ 129. Even though significant advances have been made, as smes/sme-fundamentals/sme-definition_en, highlighted in section 3.1.3 Information sharing in practice: 152. ENISA NIS Investment study 2023, https://www.enisa.europa. information provision, collection and exchange, the signifieu/publications/nis-investments-2023, cant cybersecurity incidents reported at the EU level under specific legislation is probably only a sub-set of the incidents 153. ENISA Foresight Cybersecurity Threats For 2030 - Update that actually took place. 2024: Extended report. https://www.enisa.europa.eu/
- publications/foresight-cybersecurity-threats-for-2030-update- 130. ENISA Data based on the EU-Cybersecurity Index: 2024-extended-report. 131. https://www.enisa.europa.eu/topics/cybersecurity-policy/ 154. Eurobarometer, Cyber skills - May 2024, https://europa.eu/ nis-directive-new/eu-cybersecurity-index/eu_csi_methodologeurobarometer/surveys/detail/3176. ical_note_v1-0.pdf. 155. Eurobarometer analysis on Cyberskills, May 2024, https:// 132. https://www.enisa.europa.eu/topics/national-cyber-securieuropa.eu/eurobarometer/surveys/detail/3176. ty-strategies/information-sharing.
- 156 Eurobarometer analysis on Cyberskills, May 2024, https:// 133. ENISA NIS Investments Report 2023 - https://www.enisa. europa.eu/eurobarometer/surveys/detail/3176. europa.eu/publications/nis-investments-2023.
- 157 ENISA NIS Investment study 2023, https://www.enisa.europa. 134. https://ec.europa.eu/eurostat/statistics-explained/index. eu/publications/nis-investments-2023. php?title=ICT_security_in_enterprises#:~:text=)%20and%20 (isoc_cisce_ic)-,ICT%20security%20measures,access%20con- 158. Eurostat study on ICT specialists in employment, May 2024, trol%20(65%20%25. https://ec.europa.eu/eurostat/statistics-explained/index. php?title=ICT_specialists_in_employment. 135. Eurostat variable: E-SEC2IANY - Enterprises that experienced any ICT security related incidents leading to unavailability of 159. European Commission, Gender Equality Strategy, https:// ICT services, destruction or corruption of data, disclosure of commission.europa.eu/strategy-and-policy/policies/justiceconfidential data (for any reason), https://ec.europa.eu/eu- and-fundamental-rights/gender-equality/gender-equalityrostat/databrowser/view/isoc_cisce_ic/default/table?lang=en. strategy_en.
- 136 https://ec.europa.eu/eurostat/web/products-eu- 160. European Commission, Women4Cyber, https://women4cyber. rostat-news/w/EDN-20230214-1. eu/.
- 137 The ENISA NIS Investment study 2023 indicates that 84% of 161. European Commission, Women in Digital Scorecard, https://
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- digital-strategy.ec.europa.eu/en/news/women-digital- 184. Market of Cybersecurity Assessments, ENISA, 2024, scoreboard-2021. https://certification.enisa.europa.eu/publications/marketcybersecurity-assessments-2018-2022_en. 162. CONCORDIA Women in Cyber, https://www.concordia-h2020. eu/delivers/womenincyber/. 185. Market of Cybersecurity Assessments, ENISA, 2024, https://certification.enisa.europa.eu/publications/market- 163. Eurobarometer analysis on Cyberskills, May 2024, https:// cybersecurity-assessments-2018-2022_en. europa.eu/eurobarometer/surveys/detail/3176. 186. https://www.sogis.eu/documents/cc/crypto/SOGIS-Agreed- 164. Eurobarometer analysis on Cyberskills, May 2024, https:// Cryptographic-Mechanisms-1.3.pdf. europa.eu/eurobarometer/surveys/detail/3176. 187. NIS Investments 2022, https://www.enisa.europa.eu/ 165. Eurobarometer analysis on Cyberskills, May 2024, https:// publications/nis-investments-2022. europa.eu/eurobarometer/surveys/detail/3176. 188. https://www.enisa.europa.eu/topics/national-cyber-security- 166. Eurostat, https://ec.europa.eu/eurostat/statisticsstrategies/ncss-map/national-cyber-security-strategiesexplained/index.php?title=ICT_security_in_ interactive-map. enterprises&oldid=583136#Enterprises_make_persons_ employed_aware_of_their_obligations_in_ICT_security. 189. NIS Cooperation Group, Cybersecurity of 5G networks - EU Toolbox of risk mitigating measures, 29 January 2020, https:// 167. ENISA, Cybersecurity for SMEs - Challenges and digital-strategy.ec.europa.eu/en/library/cybersecurity-5g- Recommendations, June 2021, https://www.enisa.europa.eu/ networks-eu-toolbox-risk-mitigating-measures. publications/enisa-report-cybersecurity-for-smes. 190. https://data.consilium.europa.eu/doc/document/ST-13664- 168. Cyber hygiene practices are addressed to two different 2022-INIT/en/pdf. target groups under the Directive 2022/2555: the entities (essential and important) and the citizens. See preamble 49, 191. ENISA Threat Landscape 2023, https://www.enisa.europa.eu/ 89, article 7(2) points f and i, article 21(2) point g of Directive publications/enisa-threat-landscape-2023. (EU) 2022/2555. The current section focuses on cyber hygiene 192. ENISA Foresight Cybersecurity Threats For 2030 - Update practices addressed to entities. 2024: Extended report, https://www.enisa.europa.eu/ 169. Eurostat, European Union survey on ICT usage in enterprises, publications/foresight-cybersecurity-threats-for-2030-updatehttps://ec.europa.eu/eurostat/databrowser/view/ISOC_CISCE_ 2024-extended-report. RA/default/table.
- 170 Eurostat, European Union survey on ICT usage in enterprises, https://ec.europa.eu/eurostat/databrowser/view/ISOC_CISCE_ RA/default/table.
- 171 Eurostat, European Union survey on ICT usage in enterprises, https://ec.europa.eu/eurostat/databrowser/view/ISOC_CISCE_ RA/default/table.
- 172 https://digital-skills-jobs.europa.eu/en/cybersecurity-skillsacademy.
- 173 ENISA Threat Landscape 2023, https://www.enisa.europa.eu/ publications/enisa-threat-landscape-2023.
- 174 ENISA Threat Landscape for Supply Chain Attacks, July 2021, https://www.enisa.europa.eu/publications/threat-landscapefor-supply-chain-attacks.
- 175 ENISA Threat Landscape for Supply Chain Attacks, July 2021, https://www.enisa.europa.eu/publications/threat-landscapefor-supply-chain-attacks.
- 176 ENISA Threat Landscape 2023, https://www.enisa.europa.eu/ publications/enisa-threat-landscape-2023.
- 177 ENISA Threat Landscape 2023, https://www.enisa.europa.eu/ publications/enisa-threat-landscape-2023.
- 178 ENISA Threat Landscape 2023, https://www.enisa.europa.eu/ publications/enisa-threat-landscape-2023.
- 179 ENISA Foresight Cybersecurity Threats For 2030 - Update 2024: Extended report, https://www.enisa.europa.eu/ publications/foresight-cybersecurity-threats-for-2030-update- 2024-extended-report,
- 180 NIS Investments Report 2023, https://www.enisa.europa.eu/ publications/nis-investments-2023,
- 181 NIS Investments Report 2022, https://www.enisa.europa.eu/ publications/nis-investments-2022,
- 182 NIS Investments Report 2023, https://www.enisa.europa.eu/ publications/nis-investments-2023,
- 183 NIS Investments 2022, https://www.enisa.europa.eu/ publications/nis-investments-2022.
- 2024 REPORT ON THE STATE OF CYBERSECURITY IN THE UNION
- SMEs: Security What does 100 mean 98,02 Cybersecurity What does 100 mean 58,52
- All SMEs did not All EU Member States Disclosure of experience incidents 0,79 education have integrated 25,35
- confidential leading to disclosure 0 curricula cybersecurity curricula 14
- MAX MAX
- of confidential data. for primary and
- data 1,28 41,48
- 27 seconday education 3
- Source Source MIN and updates them MIN
- Eurostat 0 MS 10
- -2,42 regularly. -58,52
- CSIRTs What does 100 mean 97,62 Cybersecurity What does 100 mean 45,65
- In all EU Member The EU average reflects presence States, CSIRTs are 2,87 higher how EU compares to 25,7
- FIRST members and 14 education the country with the 8
- MAX MAX
- Source TI Listed /Accredited / highest number of
- 3 2,38 Source 3 54,35
- Certified. cybersecurity graduates
- ENISA - CSIRTs by
- MIN ENISA - per population in the MIN
- country map 10 15
- -7,62 CyberHead EU. -39,48
- SMEs: Security What does 100 mean 94,99 Coverage of What does 100 mean 41,87
- All SMEs did not In all EU Member Destruction or experience incidents 1,22 disclosure States, vulnerabilty 35,13
- corruption of leading to destruction 0 policies disclosure policies 11
- MAX MAX
- or corruption of data. cover all NIS2 sectors
- data 27 3,41 1 58,13
- Source of high criticality, as Source well the NIS2 "other
- MIN MIN Eurostat 0 MS 15
- -3,79 critical sectors". -41,87
- Large enterprises: What does 100 mean 93,83 What does 100 mean 35,16
- Security Incidents SMEs:
- All large enterprises AVG In all EU MS, SMEs have AVG
- - Disclosure of EU R&D
- did not experience 2,81 recieved all the 20,43 confidential data incidents leading to 0 funding country's EU R&D 10
- MAX MAX
- disclosure of funding for
- 5,17 Source 64,84
- confidential data. 26 cybersecurity topics 8
- Source EC - Horizon
- MIN within the Horizon MIN
- Eurostat 1 Dashboard 9
- -10,93 Europe security cluster. -35,16
- What does 100 mean 93,29 What does 100 mean 24,93
- secure All internet users have AVG EU R&D In all EU MS, AVG
- changed the way they 2,69 Cybersecurity topics 13,19
- use the internet due to 0 have recieved all the 8 MAX country's EU R&D MAX security concerns.
- 5,69 Source 30,9
- 27 funding for the 12
- Source EC - Horizon
- MIN Horizon Europe MIN
- Eurobarometer 0 Dashboard security cluster. 7 -7,36 -24,93
- Large enterprises: What does 100 mean 92 What does 100 mean 10,31
- Security Incidents - CSIRT(s)
- All large enterprises AVG In all EU Member AVG Destruction or did not experience 2,81 certification 10,58 States, CSIRTs are corruption of data incidents leading to 0 TI certified. 5
- MAX MAX
- destruction or Source
- Source corruption of data.
- ENISA - CSIRTs MIN by country map MIN Eurostat 0 11
- Cybersecurity What does 100 mean 64,1 Cybersecurity What does 100 mean 7,14
- in R&D investments by
- All EU Member States AVG The whole IT budget of AVG
- essential /
- priorities and have implemented 28,11 surveyed essential/ 0,54
- 12 important entities 0
- initiatives relevant measures to important entities is
- MAX Source MAX
- support and promote devoted to information
- 4 35,9 ENISA-NIS 27 1,46
- cybersecurity R&D security. Source
- activities. MIN Investments MIN
- -64,1 Report -1,24
- Implementation What does 100 mean 59,26 Enterprises: What does 100 mean 32,01
- of supervisory risk
- In all EU Member AVG All enterprises AVG measures for States, all operators in 31,71 assessment perform a 9,76
- essential and scope of NIS2 are 11 cybersecurity risk 6
- MAX MAX
- important entities subjected to assessment.
- supervisory measures Source Source by national competent MIN MIN
- MS 16 Eurostat 5
- authorities. -39,26 -21,31
- SMEs: Security What does 100 mean 98,02 Cybersecurity What does 100 mean 58,52
- All SMEs did not All EU Member States Disclosure of experience incidents 0,79 education have integrated 25,35
- confidential leading to disclosure 0 curricula cybersecurity curricula 14
- MAX MAX
- of confidential data. for primary and
- data 1,28 41,48
- 27 seconday education 3
- Source Source MIN and updates them MIN
- Eurostat 0 MS 10
- -2,42 regularly. -58,52
- CSIRTs What does 100 mean 97,62 Cybersecurity What does 100 mean 45,65
- In all EU Member The EU average reflects presence States, CSIRTs are 2,87 higher how EU compares to 25,7
- FIRST members and education the country with the
- MAX MAX
- 3 2,38 Source 3 54,35
- Certified. cybersecurity graduates
- MIN ENISA - per population in the MIN
- -7,62 CyberHead EU. -39,48
- All SMEs did not In all EU Member
- corruption of leading to destruction 0 policies disclosure policies 11
- or corruption of data. cover all NIS2 sectors
- Source of high criticality, as Source well the NIS2 "other
- MIN MIN Eurostat 0 MS 15
- -3,79 critical sectors". -41,87
- Large enterprises: What does 100 mean 93,83 What does 100 mean 35,16
- Security Incidents SMEs:
- All large enterprises AVG In all EU MS, SMEs have AVG
- - Disclosure of EU R&D
- did not experience 2,81 recieved all the 20,43 confidential data incidents leading to 0 funding country's EU R&D 10
- MAX MAX
- disclosure of funding for
- 5,17 Source 64,84
- confidential data. 26 cybersecurity topics 8
- Source EC - Horizon
- MIN within the Horizon MIN
- Eurostat 1 Dashboard 9
- -10,93 Europe security cluster. -35,16
- What does 100 mean 93,29 What does 100 mean 24,93
- secure All internet users have AVG EU R&D In all EU MS, AVG
- changed the way they 2,69 Cybersecurity topics 13,19
- use the internet due to 0 have recieved all the 8 MAX country's EU R&D MAX security concerns.
- 5,69 Source 30,9
- 27 funding for the 12
- Source EC - Horizon
- MIN Horizon Europe MIN
- Eurobarometer 0 Dashboard security cluster. 7 -7,36 -24,93
- Large enterprises: What does 100 mean 92 What does 100 mean 10,31
- Security Incidents - CSIRT(s)
- All large enterprises AVG In all EU Member AVG Destruction or did not experience 2,81 certification 10,58 States, CSIRTs are corruption of data incidents leading to 0 TI certified. 5
- MAX MAX
- destruction or Source
- Source corruption of data.
- ENISA - CSIRTs MIN by country map MIN Eurostat 0 11
- Cybersecurity What does 100 mean 64,1 Cybersecurity What does 100 mean 7,14 ENISA
- All EU Member States AVG The whole IT budget of AVG
- essential /
- priorities and have implemented 28,11 surveyed essential/ 0,54
- 12 important entities 0
- initiatives relevant measures to important entities is Athens Office
- MAX Source MAX
- support and promote devoted to information
- 4 35,9 ENISA-NIS 27 1,46 Agamemnonos 14
- cybersecurity R&D security. Source
- -64,1 Report -1,24
- Implementation What does 100 mean 59,26 Enterprises: What does 100 mean 32,01
- of supervisory risk
- In all EU Member AVG All enterprises AVG
- measures for States, all operators in 31,71 assessment perform a 9,76
- essential and scope of NIS2 are 11 cybersecurity risk 6
- MAX MAX
- important entities subjected to assessment. Brussels Office
- supervisory measures
- by national competent MIN MIN
- MS 16 Eurostat 5