Cyber Europe 2022: After Action Report
EUROPEAN UNION AGENCY FOR CYBERSECURITY Cyber Europe 2022: After Action Report ER EURO B P Y E C 2 0 22
CYBER EUROPE 2022: AFTER ACTION REPORT
Findings from a PAN-EUROPEAN cyber crisis Exercise DECEMBER 2022 CONTACT To contact the authors, please use exercises@enisa.europa.eu For media enquiries about this paper, please use press@enisa.europa.eu. AUTHORS ENISA: Nikolaos Christoforatos, Ifi genia Lella, Evangelos Rekleitis, Christian Van Heurck, Alexandros Zacharis LEGAL NOTICE This publication represents the views and interpretations of ENISA, unless stated otherwise. It does not endorse a regulatory obligation of ENISA or of ENISA bodies pursuant to Regulation (EU) No 2019/881. ENISA has the right to alter, update or remove the publication or any of its contents. It is intended for information purposes only and it must be accessible free of charge. All references to it or its use as a whole or partially must contain ENISA as its source. Third-party sources are quoted as appropriate. ENISA is not responsible or liable for the content of the external sources, including external websites referenced in this publication. Neither ENISA nor any person acting on its behalf is responsible for the use that might be made of the information contained in this publication. ENISA maintains its intellectual property rights in relation to this publication. COPYRIGHT NOTICE © European Union Agency for Cybersecurity (ENISA), 2022 This publication is licenced under CC-BY 4.0 “Unless otherwise noted, the reuse of this document is authorised under the Creative Commons Attribution 4.0 International (CC BY 4.0) licence (https://creativecommons.org/licenses/by/4.0/). This means that reuse is allowed, provided that appropriate credit is given and any changes are indicated”. Cover image © queezz, shutterstock.com For any use or reproduction of photos or other material that is not under the ENISA copyright, permission must be sought directly from the copyright holders. Print ISBN 978-92-9204-606-7 DOI: 10.2824/385167 TP-04-22-224-EN-C PDF ISBN 978-92-9204-603-3 DOI: 10.2824/397622 TP-04-22-224-EN-N
CYBER EUROPE 2022: AFTER ACTION REPORT
Findings from a PAN-EUROPEAN cyber crisis Exercise EUROPEAN UNION AGENCY FOR CYBERSECURITY 21 TABLE OF CONTENTS PART I EXERCISE OVERVIEW 5
1 INTRODUCTION 5
2 GOALS 5
The 2022 edition aimed to achieve the following Goals: 5
3 OBJECTIVES 6
4 SCENARIO 6
5 TAKEAWAYSFROMTHEEXERCISE 11
GENERALTAKEAWAYS 11
Cyber Europe 2022 Goals and Objectives 11 The future of Cyber Europe 12 Participating entities and sectors 12
I
PART I EXERCISE OVERVIEW 1 INTRODUCTION 2 GOALS
Cyber Europe is a series of EU-level cyber incident Cyber Europe 2022 was designed to fulfil a list and crisis management exercises organised by of Goals (G). These Goals were developed to provide ENISA. It is aimed at both the public and private the organisers and the participants with a clear scope sectors from the EU and EFTA Member States. and a purpose for their participation in the event.
The exercises simulate large-scale cybersecurity The 2022 edition aimed to achieve incidents that escalate into cyber crises, offering the following Goals: opportunities to analyse advanced technical cybersecurity incidents but also test participants on G1. Test EU-level technical and operational their capabilities for dealing with complex situations. cooperation during cyber-crises
The exercises aim to test the participants’ readiness and capacity to tackle challenging and G2. Provide opportunities to test local-level incident
realistic cyber crises. response and resilience plans
The exercises are organised by ENISA together with G3. Train EU- and local-level technical capabilities. planners from participating countries and institutions. These Goals were complemented by the following Cyber Europe 2022 aimed to accomplish several Goals secondary (also known as implicit) Goals: and Objectives which are detailed below.
Help to build trust
Engage the private sector
Improve situational awareness
Testthepublicaffairsresponse
Improve the exercise’s process and capabilities.
3 OBJECTIVES 4 SCENARIO
The Goals of Cyber Europe 2022 were designed to Cyber Europe 2022 revolved around the healthcare remain broad and all-encompassing. To further ecosystem and tested the resilience of several assess the relevance and the added value of the relevant stakeholders, including national Computer exercise, specific Objectives (O) were derived Security Incident Response Teams (CSIRTs), from the Goals. Each Objective was assigned cybersecurity authorities, ministries of health, specific metrics for evaluation purposes in order healthcare organisations such as hospitals and clinics, to facilitate assessment of the extent to which they eHealth service providers, and health insurance were achieved. providers. The participants had to address an
escalating cyber crisis, tackling multiple incidents
The different Objectives targeted by this exercise are simultaneously. described below, categorised per Goal. The scenario aimed at realistically mimicking
G1. TestEU-leveltechnicalandoperational technical incidents. These incidents are detailed
cooperation during cyber-crises in Figure 1 below, which highlight how they covered O01. Test the quality of information-sharing several elements, with some aimed at gaining a O02. Test incident response capability at EU level foothold and others aimed at tampering with medical O03. Evaluate situational awareness devices. The second figure describes the sectors O04. Test the articulation between the technical and targeted by the attacks and their potential impacts. operational levels O05. Test the operational coordinated handling of The objective of the scenario was to enable the public communication players to react accordingly to each incident in order to minimise the damage incurred, with G2. Provideopportunitiestotestlocal-level the general objective of testing the operational incident response and resilience plans and technical layers. The scenario, which spanned O06. Provide opportunities to participants to test two days, began on the first day by engaging their intra-organisational procedures, if they the participants around a disinformation exist (Business Continuity Plans (BCPs), Crisis campaignof manipulatedlaboratoryresults Management Plans, etc.) and a cyberattack targeting the networks
O07. Provide opportunities to participants to test of European hospitals as well as internet
cross-organisational cooperation and cloud serviceproviders.
O08. Provide opportunities to participants to
test local-level cooperation activities and/or contingency plans, if they exist
G3. TrainEU-andlocal-leveltechnical capabilities O09. Provide opportunities to train in a wide variety
of cybersecurity and crisis management skills
O10. Identify training needs for the future
The aim was to achieve the Goals and Objectives by means of the main Cyber Europe 2022 scenario presented in the following subsection.
PART I. Exercise overview Figure 1. Overviewofthetechnicalscenario
Medicaldevicetampering
GAIN DATA LOSS DATA EXFILTRATION/ HUMANLIFE FOOTHOLD GDPR VIOLATION/ ATRISK DATA LOSS
Spearphishing Tampered medical Medical data Implantable attack laboratory server attacks cardiac device instrument cyber-attack Drive-by infection
Infected document
Attacks through Ransomware Vulnerable IOTs unsecure wi-fi infection (temperature Legend: control, data leaks) Type Attack through Data loss through fileless malware unrecoverable Multiprotocol data
encryption stealer OSINT incident
Maliciousinsider
Insider threat Non Robocall Technical attacks
Figure 2. Targetedsectorsandpotentialimpactoftheattacks
Sensitive (medical) Sensitive (medical) Mainstream news outlets or confidential data for sale or confidential data loss covering major attacks/events on the darknet
Threats of exposing sensitive Compromised integrity Cyberphysical attack (medical) or confidential data of sensitive medical data (pharmacy storage) via social media
Misuse of resources (cryptominer)
TARGETS
Government Industry Networks Helthcare providers
Figure 3. CyberEurope2022planners PART I. Exercise overview Figure 4. ParticipantsperSector
Healthcare and Public Health Public/Government Facilities and Services
ICT– Information Security
ICT – Telecommunications
Defence/military
ICT – Internet and Digital Services Emergency and Security Services
Energy – Electricity
Academia and Research ICT – Hardware/ Software industry Entertainment and media
Other
0 50 100 150 200 250 300
Entities Players
In total, 918 participants (planners, players and monitors) officially registered for the exercise, representing the 27 EU Member States, 2 EFTA countries (Norway and Switzerland) and several EU institutions and agencies (including CERT-EU, EAAS, EDPS, EUSPA, EUROPOL and the European Commission). As illustrated in Figure 4, the Healthcare and Public Health sector was the most widely represented sector, but participants came from a wide range of sectors.
Figure 5. NumberofEmailsandNumberofAffiliationsperParticipatingSector
CountofAffiliation
350
300
250
200
150
Count of Email
100
50
0 0 50 100 150 200
Academia and Research Defence/military Emergency and Security Services Energy – Electricity Entertainment and media Healthcare and Public Health ICT – Hardware/Software industry ICT– Information Security ICT – Internet and Digital Services ICT – Telecommunications Other Public/Government Facilities and Services
The figure above illustrates the number of emails The programme was an opportunity for (i.e. personal emails) and affiliations (i.e. functional stakeholders to engage in fruitful discussions, mailboxes) per participating sector. exchange lessons learnt and discuss opportunities for future collaboration. An observers programme ran in parallel to the execution of the exercise, with representatives from EUIBAs (EU Institutions, Bodies and agencies) and the international cybersecurity community present in the ENISA offices in Halandri (Athens) during the two days of the exercise.
PART I. Exercise overview Figure 6. CyberEurope2022observers 5 TAKEAWAYSFROMTHEEXERCISE GENERALTAKEAWAYS
Cyber Europe 2022 Goals and Objectives
Following the completion of Cyber Europe 2022, a survey was circulated to collect feedback The Goals and Objectives set by Cyber Europe from the participants. The data collected was 2022 (CE2022) were mainly achieved. In a nutshell, complemented by findings from the planners collected CE2022 provided the testing and training during the exercise, observations from the ENISA opportunities to the participants that were stated exercise team and finally analysed by ENISA. in the main Goal.
The detailed findings were compiled in a report
shared with the planners. Themoredetailedanalysisconfirmedthatthe
exercise also achieved secondary (implicit) goals.
One key takeaway is that Cyber Europe 2022 can be Although not every participating entity was able to regarded as having been a success as all parties engage in all secondary areas, the exercise scenario
involvedidentifiedareasforimprovement. This offeredtheopportunity to all participating countries
proves that Cyber Europe is helpful in identifying and institutions to do so. what works, but also where there are shortcomings
Theuptakeofthedetailedfindingsatthe
and areas for improvement.
Objectives level, which were shared with the
planners, should result in the improvement of The lessons learned from the participants in Cyber
procedures, communication and coordination
Europe were compiled in the following word cloud.
processes that are in place at local, sectoral,
national, cross-border and EU-wide levels.
Figure 7. Wordcloud“Lessonslearnedbytheparticipants” revised guidelines plan good finetune tools communication potential standards procedures stakeholder horizontal streamline clear improved stricter revision better internal inventory improvement
The future of Cyber Europe Participating entities and sectors
An exercise like Cyber Europe as a training and CyberEurope2022confirmedtheimportance testing ground is needed, as it successfully ofallocatingsufficientbudgetandresources identifiesgapsanddevelopmentpoints to cybersecurity teams in the healthcare across the board in order to improve the sector, given the severity of the challenges linked
cybersecurity posture of all participating to cyber-attacks.
stakeholders. Cyber Europe 2022 was notably Cyber Europe 2022 provided a training ground
able to engage several stakeholders from the for Standard Operating Procedures and Business private and public sectors in collaboration and Continuity Plans. Theexerciseconfirmedthe working together towards achieving a common
need for frequent testing at local level in order
goal: improving EU-wide coordination during
to continuously improve and strengthen the
major cyber crises.
healthcare sector’s resilience with regard to The ENISA Cyber Exercise Platform (CEP) used cybersecurity threats. for the planning and execution of the exercise couldbenefitfromarefresh in order to be able
to be accommodate future expectations and improve the user experience for all involved.
CyberEurope2022confirmedtheimportance of preparing optimally for such a large-scale exercise, investing more effort in the preparation
of the results in order to produce a more useful output. The preparation helps to better identify gaps and areas for improvement, determines the impact of participating in such an exercise and facilitates recruiting players with different roles.
The planners agreed with ENISA’s observations that receiving improved support and training for their crucial role as planners would help them get even more out of future Cyber Europe exercises. It would also help level the playing field
for all players. This would ensure the exercise is adequately tailored to local-level specificities.
TP-04-22-224-EN-N Cyber Europe 2022: After Action Report ABOUTENISA The European Union Agency for Cybersecurity, ENISA, is the Union’s agency dedicated to achieving a high common level of cybersecurity across Europe. Established in 2004 and strengthened by the EU Cybersecurity Act, the European Union Agency for Cybersecurity contributes to EU cyber policy, enhances the trustworthiness of ICT products, services and processes with cybersecurity certifi cation schemes, cooperates with Member States and EU bodies, and helps Europe prepare for the cyber challenges of tomorrow. Through knowledge sharing, capacity building and awareness raising, the Agency works together with its key stakeholders to strengthen trust in the connected economy, to boost the resilience of the Union’s infrastructure, and, ultimately, to keep Europe’s society and citizens digitally secure. More information about ENISA and its work can be found here: www.enisa.europa.eu. ENISA European Union Agency for Cybersecurity AthensOffice Agamemnonos 14 Chalandri 15231, Attiki, Greece HeraklionOffice 95 Nikolaou Plastira 700 13 Vassilika Vouton, Heraklion, Greece enisa.europa.euenisa.europa.eu ISBN 978-92-9204-603-3
Fotnoter
- 1 CYBER EUROPE 2022: AFTER ACTION REPORT 3
- CYBER EUROPE 2022: AFTER ACTION REPORT 5
- CYBER EUROPE 2022: AFTER ACTION REPORT 7
- 1 These figures account only for participants who registered on the Cyber Exercise Platform. Several organisations chose to participate using a generic functional mailbox and distributed exercise information among multiple participants and teams. As a result, it is safe to assume that the actual real number of participants was significantly higher.
- CYBER EUROPE 2022: AFTER ACTION REPORT 9
- CYBER EUROPE 2022: AFTER ACTION REPORT 11