Cybersecurity Education Initiatives in the EU Member States
DECEMBER 2022
ABOUT ENISA
The European Union Agency for Cybersecurity (ENISA) has been working to make Europe cyber secure since 2004. ENISA works with the EU, its member states, the private sector and Europe’s citizens to develop advice and recommendations on good practice in information security. It assists EU member states in implementing relevant EU legislation and works to improve the resilience of Europe’s critical information infrastructure and networks. ENISA seeks to enhance existing expertise in EU member states by supporting the development of crossborder communities committed to improving network and information security throughout the EU. Since 2019, it has been drawing up cybersecurity certification schemes. More information about ENISA and its work can be found at www.enisa.europa.eu. CONTACT For contacting the authors, please use christina.skouloudi@enisa.europa.eu. For media enquiries about this paper, please use press@enisa.europa.eu. ACKNOWLEDGEMENTS We would like to acknowledge the following experts who have contributed to the study (in no particular order): Christina Skouloudi (ENISA), Chloe Blondeau (ENISA), Solène Vossot (wavestone), Corentin Decock (wavestone), Francois Prost (wavestone). LEGAL NOTICE Notice must be taken that this publication represents the views and interpretations of ENISA, unless stated otherwise. This publication should not be construed to be a legal action of ENISA or the ENISA bodies unless adopted pursuant to the Regulation (EU) No 2019/881. This publication does not necessarily represent state-of the-art and ENISA may update it from time to time. Third-party sources are quoted as appropriate. ENISA is not responsible for the content of the external sources including external websites referenced in this publication. This publication is intended for information purposes only. It must be accessible free of charge. Neither ENISA nor any person acting on its behalf is responsible for the use that might be made of the information contained in this publication. COPYRIGHT NOTICE © European Union Agency for Cybersecurity (ENISA), 2020 Reproduction is authorised provided the source is acknowledged. Cover image ©Shutterstock For any use or reproduction of photos or other material that is not under the ENISA copyright, permission must be sought directly from the copyright holders. ISBN 978-92-9204-611-8 doi:10.2824/486119 TP-08-22-341-EN-N 0 CYBERSECURITY EDUCATION INITIATIVES IN THE EU MEMBER STATES
DECEMBER 2022
TABLE OF CONTENTS
EXECUTIVE SUMMARY 2 1. INTRODUCTION 4 1.1 STUDY OBJECTIVES AND SCOPE 4 1.2 METHODOLOGY 5 1.3 DOCUMENT STRUCTURE 5 2. CONTEXT AND BACKGROUND 6 2.1 THE CYBERSECURITY EDUCATIONAL ROADMAP 6 2.2 LEGAL FRAMEWORK 6 3. CYBERSECURITY EDUCATION INITIATIVES IN EU MEMBER STATES 7 4. BEST PRACTICES AND MAIN CHALLENGES 20 4.1 GOVERNANCE AND PRIORITISATION PROCESS 20 4.2 MEASUREMENT MECHANISM 21 4.3 KEY PRINCIPLES 23 4.4 COLLABORATION WITH OTHER ORGANISATIONS, INCLUDING ENISA 23 5. CONCLUSIONS 25 5.1 CHALLENGES ENCOUNTERED 25 5.2 KEY PRIORITIES FOR THE ENISA ROADMAP 26 1 CYBERSECURITY EDUCATION INITIATIVES IN THE EU MEMBER STATES
DECEMBER 2022
EXECUTIVE SUMMARY
Today, the internet is a tool used in many educational activities, which increases the amount of time children are exposed to cyberspace and its risks. Informing young users about the importance of maintaining personal privacy is not enough to keep them vigilant when using the internet. More proactive training is required to teach children to be safe online. Member States, which are advised to increase their cybersecurity capacity, have made efforts to raise cybersecurity awareness among their population through initiatives targeting different age groups of users. With regard to children in particular, the Safer Internet Centers , co-funded by the European Commission, have proven to be the main drivers of the majority of initiatives at the national level and have served as a forum for cooperation and exchange of resources. In line with the European Cybersecurity Act, Article 10 , ENISA has the mission to focus its efforts in supporting cybersecurity in all levels of education in the Member States. In this context, ENISA has a mandate to support closer coordination and exchange of best practices among Member States on cybersecurity awareness and education. Additionally, the EU Digital Education Action Plan identifies two priority areas to prepare the next generations for the challenges posed by the digital: i) Fostering the development of a highperforming digital education ecosystem and ii) Enhancing digital skills and competences for the digital transformation. To address these challenges, ENISA recognises the importance of addressing and reshaping the existing cybersecurity education programmes and the continuous changes in the landscape to align the required cybersecurity knowledge and skills. Through this project, ENISA wants to develop a comprehensive roadmap, towards the implementation of a collaborative campaign at EU level, for enhancing cybersecurity in education - targeting primary and secondary schools - across the EU and create a common platform to foster good practices and knowledge sharing, in order to collaborate with the European Commission (EC) and Member States in the creation and implementation of the required actions. This study brings out interesting conclusions regarding the best practices around cybersecurity in education across EU Member States, and with-it priorities for ENISA. Initiatives are often designed by National Cybersecurity Agencies, which then refer to a ministry responsible for the initiatives, but these initiatives may also be designed by that ministry. This usually has an impact on the funding of the initiatives (provided by the state or by private sponsors). The most recurrent and common key principles to be followed when developing educational cybersecurity initiatives were the following: undertake a collaborative approach to involve various stakeholders, undertake a pedagogic approach to ensure the participation of students, rely on the pareto principle to maximize efforts, construct yearly plans to ensure continuous improvement, educate the parents instead of creating a chain reaction… Most of the time, KPIs are deployed to measure the achievement of predefined objectives and targets (such as completion of a task, gathering information through a satisfaction survey, web 2 CYBERSECURITY EDUCATION INITIATIVES IN THE EU MEMBER STATES
DECEMBER 2022
analytics to see how many people have participated in a training course, etc.). However, only a few Member States collect KPIs that measure the actual performance of users in the activities. Measuring the impact of cybersecurity education initiatives on the target audience, and whether and how their educational skills have evolved, is a challenge that Member States are trying to study and improve in this area. The main challenges faced by Member States are the rigid culture of the ministries responsible for educational cybersecurity initiatives, the decentralized approach of some states, the lack of time and resources (low availability of teachers, staff turnover) and the lack of recognition for stakeholders. Many respondents shared advice on how to approach the ministries responsible for the initiatives, and advice on how to develop initiatives at national level. They would also like to have visibility on what other Member States are doing in terms of cybersecurity in education, and finally they showed interest in working with ENISA and the other Member States. The goal of this report is to present an overview of the Member States’ best practices when implementing cybersecurity education initiatives - targeting primary and secondary schools - as well as the challenges faced by the interviewed stakeholders when carrying out the activities. The aim is to identify the needs and gaps regarding cybersecurity education and determine how ENISA can provide additional support to the Member States. 3 CYBERSECURITY EDUCATION INITIATIVES IN THE EU MEMBER STATES
DECEMBER 2022
1. INTRODUCTION
There is a common feature in modern cyberattacks: in most cases, basic computer hygiene such as keeping software updated, using strong passwords, encrypting sensitive data, and keeping copies in the cloud are sufficient to protect computers from such incidents. For example, one often-overlooked aspect of the 2017 WannaCry attack is that, even though more than 400,000 computers in over 150 countries were hit, millions were not affected because they had updated their software. For this reason, WannaCry was defined as a “tribute to negligence” . As mentioned in the 2017 High Level Group of Scientific Advisors on Cybersecurity to the European Commission , many Europeans still fail to take basic cybersecurity measures: many say they care a lot about their personal data, but then give them away for free on social networks. Data are striking: 90% of the data breaches reported by the 2017 Verizon Data Breach Investigation were the result of phishing. And for those who are successfully phished it is not over, because they can expect it to happen again at least once during the same year. Cybersecurity should therefore become a collective responsibility and cyber awareness and computer hygiene should become an integral part of digital literacy programs. Without awareness-raising campaigns and smart policies, cybersecurity will always be dogged by collective action. 1.1 STUDY OBJECTIVES AND SCOPE In line with the European Cybersecurity Act, Article 10 , ENISA has the mission to focus its efforts in supporting cybersecurity in all levels of education in the Member States. In this context, ENISA has a mandate to support closer coordination and exchange of best practices among Member States on cybersecurity awareness and education. The current initiative is consistent with the existing EU Digital Education Action Plan which sets two priority areas to prepare the next generations to face the challenges raised by the digital: i) Fostering the development of a high-performing digital education ecosystem and ii) Enhancing digital skills and competences for the digital transformation. There is a need for reshaping the content of the existing cybersecurity education programmes in light of the constant evolution of the landscape in order to align the required knowledge and skills. Through this project, ENISA wants to develop a comprehensive roadmap for enhancing cybersecurity in education across the EU and create a common platform to foster good practices and knowledge sharing, in order to collaborate with the European Commission (EC) and Member States in the creation and implementation of the required actions. Through desk research and interviews with key stakeholders, and thus the use of primary and secondary data, this report summarises insights around cybersecurity in education collected from Member States. 4 CYBERSECURITY EDUCATION INITIATIVES IN THE EU MEMBER STATES
DECEMBER 2022
1.2 METHODOLOGY The study is based on two initial steps: a desk study on the existing initiatives around cybersecurity in education in all Member States, and then a series of interviews with a sample of 14 countries. The results obtained were consolidated in this report. Below is a list of the interviews that were conducted as part of this study. Table 1: List of interviews
Item Interviewee Member State
1 ACN Italy 2 Hellenic Safe Internet Center Greece & National Cyber Security Authority (NCSA) 3 NUKIB Czech Republic 4 INCIBE Spain 5 University College Dublin (UCD) Ireland 6 NCSC Netherlands 7 Service National de la Jeunesse Luxembourg 8 eSkills Malta Foundation Malta MITA Directorate for Learning & Assessment Programmes at the Ministry of Education FSWS – Appogg MCAST University of Malta 9 Talinn University of Technology Estonia 10 ANSSI France 11 Government Information Security Office Slovenia 12 National Cyber Security Centre (NCSC) Portugal 13 Cyber Security Austria Austria 14 The Swedish Federation of Young Scientists Sweden
1.3 DOCUMENT STRUCTURE In this document, the identified initiatives of Member States in the field of cybersecurity education are presented. Good practices are highlighted from the stakeholder interviews, as well as blocking points and challenges. 5 CYBERSECURITY EDUCATION INITIATIVES IN THE EU MEMBER STATES
DECEMBER 2022
2. CONTEXT AND BACKGROUND
This chapter provides background information on the context of educating children on cybersecurity issues. 2.1 THE CYBERSECURITY EDUCATIONAL ROADMAP Along with the increased use of technology in recent decades, the field of cybersecurity has received more attention due to the greater exposure of citizens to ways in which they can be subjected to data theft and damage. The role of cybersecurity experts in protecting critical information and infrastructure, whilst relevant, remains insufficient to cover all internet users due to the shortage of professionals in the market. The solution, which is to address the cybersecurity knowledge level of citizens, requires reaching out to internet users of all age groups, including the new generation. Schoolchildren are often considered as early introduced to digital technologies and are a critical group to be addressed to ensure that the next generation is well equipped with the skills to use the online space more safely. According to the Cybersecurity Act , respectively article 10, ENISA is mandated to “raise public awareness of cybersecurity risks and provide guidance on good practices for individual users aimed at citizens, organisations and businesses, including cyber-hygiene and cyber-literacy”, demonstrated through initiatives such as European Cybersecurity Month, European Cyber Security Challenge, European Cybersecurity Skills Framework, CYBERHEAD – Cybersecurity Higher Education Database. At Member State level, the introduction of the cybersecurity topic in school curriculums and activities alone can help ensure that young users are more exposed to and aware of the cybersecurity field and requirements, potentially leading them to choose this domain professionally and helping address the shortage in the labour market. 2.2 LEGAL FRAMEWORK The Cybersecurity Act, which conferred ENISA a permanent mandate as an agency of the European Union for cybersecurity, describes the goal of focusing efforts in supporting the Member States in “their efforts to raise cybersecurity awareness and promote cybersecurity awareness” (cf. Article 10 Awareness-raising and education). According to the 2022-2024 Programming Document , ENISA’s support should be ensured through complementary actions such as capacity building by increasing the supply of qualified professionals to meet market demand and promoting cybersecurity education. Activity 9, in particular, outlines the intention to organise regular awareness campaigns, provide guidance on best practices and support coordination between Member States on awareness and education. The goal is to promote the cybersecurity topics, education and good practices on the basis of the ENISA stakeholders’ strategy. 6 CYBERSECURITY EDUCATION INITIATIVES IN THE EU MEMBER STATES
DECEMBER 2022
3. CYBERSECURITY EDUCATION INITIATIVES IN EU MEMBER STATES
The mission of introducing young citizens to cybersecurity fundamentals has been expressed in the national strategies of the Member States, which presented their plans of action focused on improving the security and resilience of governments, companies and citizens through improved national infrastructures and increased awareness. With various activities being carried out to ensure that all target groups of society are involved, the introduction of the best practices to children helps ensure that future generations are more apt to face an increasingly digital society. The table below illustrates the initiatives in cybersecurity education being carried out in the Member States, where it is observed that governments intend on introducing cybersecurity topics through the educational curriculum or training plans carried out in the school setting. From the initiatives corroborated through the desk research and interviews, majority of the initiatives are carried out at national level and pre-teens and teenagers are the target group regularly pursued due to the increased independent use of digital technologies as well as the optimal time to present a new career path before pursuing higher education. Member States like Italy presented specific regional initiatives that will be carried out in additional regions in the future. Some Member States (40% ) showed that on-governmental organization (NGOs) and institutions already involved in carrying out activities with children and adolescents have developed additional initiatives that present and teach the principles of cybersecurity through more practical or engaging approaches such as events, competitions, online platforms, and games. The promotion of the initiatives is usually carried out online or through traditional media. The teaching materials, developed for parents and/or teachers or directly aimed at the target audience, are often available in the institutional or dedicated and available for free. The list below solely displays the initiatives found through desk research and conducted interviews, not representing an exhaustive scope of all projects currently being carried out in the Member States. Table 2: Member States’ initiatives in cybersecurity education
Initiative (type, objective, scope, target Status and next Country /Entity audience, activities…) steps The Austria Cyber Security Challenge
Ongoing, with new • Type: Talent search initiative initiatives to be carried • Objective: Identify young talent and present out in 2023, following students with a new career path Austria - Cyber the organisation of the • Scope: Austria Security Austria 2022 European • Target audience: 14- to 25-year-old students Cybersecurity • Activities: Participate in ethical hacking Challenge in Vienna (to challenge be specified)
7 CYBERSECURITY EDUCATION INITIATIVES IN THE EU MEMBER STATES
DECEMBER 2022
Initiative (type, objective, scope, target Status and next Country /Entity audience, activities…) steps Cybersecurity training
• Type: Training plans • Objective: Teach children and adolescents how to be safe online through games • Scope: Austria • Target audience: Students in primary and secondary school • Activities: Provide trainings about various cybersecurity topics in schools or online • Organised in collaboration with the Vienna Cybersecurity and Privacy Research Cluster, the Learners programme, the Austrian Computer Society, SaferInternet.at and Teach for Austria.
Educational Exchange Platform and the Android and iOS mobile application
• Type: Platforms and applications • Objective: Teach children how to be safe online through games • Scope: Austria • Target audience: Children and adolescents • Activities: Online games and challenges
Support material: Digital Course Platform from the Ministry of Education, Science and Research.
Belgian Better Internet Consortium (B-Bico)
• Type: Awareness raising campaigns • Objective: Engage the main Belgian awareness-raising initiatives on cybersecurity, online safety and media education and promote their mutual coordination and Belgium - Centre for outreach, through more dialogue and Cyber Security cooperation N/A Belgium • Scope: Belgium • Target audience: Children and adolescents • Activities: Trainings and campaigns
Support material: Teaching material and campaigns (and the year each project was carried out).
Cybersecurity for children and parents
• Type: Online seminar • Objective: Discuss the recent statistics on access of children to the internet and how to educate young users about online safety. • Scope: Bulgaria • Target audience: Parents and teachers Bulgaria - Ministry of • Activities: N/A N/A
eGovernment
Support material: Recording of the online webinar "Cyber safety for children and parents", organised on 28 October 2021 and with guest speakers from the Parents Association, Applied Research and Communications Fund, Bulgarian Safe Internet Centre and specialists from the Bulgarian Cyber Security Academy.
8 CYBERSECURITY EDUCATION INITIATIVES IN THE EU MEMBER STATES
DECEMBER 2022
Initiative (type, objective, scope, target Status and next Country /Entity audience, activities…) steps Bulgarian Safer Internet Centre
• Type: Trainings • Objective: Protect and empower children and teenagers by increasing digital literacy and promoting positive, safe and responsible use of the internet. • Scope: Bulgaria • Target audience: Primary and secondary school students, teachers and parents. • Activities: Trainings and campaigns
Support material: List of trainings provided to students, teachers and parents. National Cybersecurity Strategy: 6.4 - Education, research, development and raising security awareness in cyberspace (I) • Type: Inclusion of cybersecurity within the formal school curricula • Objective: Ensure that students acquire knowledge, skills and competences to successfully ensure their own safe use of Croatia - Ministry of information and communication technologies N/A Interior at all levels of formal education, and awareness of the need to protect personal data. • Scope: Croatia • Target audience: Primary and secondary school students, and various population segments • Activities: N/A
European CyberSafety Projects
• Type: Training and education resources platform • Objective: Bring together the main national stakeholders with the aim of creating a safe internet culture, empowering creative, Republic of Cyprus - innovative, and critical thinking citizens in the N/A CYberSafety digital society. • Scope: Cyprus • Target audience: Children • Activities: Awareness and promotional material, helpline.
Support material: Promotional material
National Educational Plan for Cybersecurity Education and Educational programme framework
• Type: National programmes • Objective: Increase competencies of children and young people
Czech Republic -
• Scope: Czech Republic N/A
NUKIB
• Target audience: Primary and secondary school students • Activities: N/A
Educational e-learning portal:
• Type: Platform
9 CYBERSECURITY EDUCATION INITIATIVES IN THE EU MEMBER STATES
DECEMBER 2022
Initiative (type, objective, scope, target Status and next Country /Entity audience, activities…) steps
• Objective: Develop and maintain an educational e-learning platform to provide the public with cybersecurity awareness on-line courses, campaigns and webinars • Scope: Czech republic • Target audience: Public administration officers, teaching staff, IT administrators, cybersecurity managers, • and other professionals performing ACSaffected roles, as well as vulnerable population groups such as children, young people, and seniors • Activities: Courses, campaigns, webinars
Festival of Safe Internet (FBI):
• Type: Series of educational events, campaigns, conferences and webinars • Objective: Provide visitors with information and advice in the field of cyber security that can be applied to the personal and professional lives of attendees • Scope: Czech Republic • Target audience: Health workers, officials,
teachers of primary and secondary
schools, teenagers, librarians, senior citizens • Activities: Comic book campaigns for teenagers
Support material: - Information leaflets - Social media (Facebook and Instagram chat boxes) - Screens in schools, with the cooperation of Amos Vision
The Danish National Strategy for Cyber and Information Security
• Type: Curricula and training plans • Objective: Increase competencies of children
Denmark - Agency
and young people for Digital N/A • Scope: Denmark
Government
• Target audience: Primary and secondary school students • Activities: Training courses
Development of curriculum for 1st to 12th grade and extra curriculum activities
• Type: Curricula and training plans • Objective: Support other actors in the country to become better in cyber security. • Scope: Estonia Estonia - Tallinn Ongoing, with the aim to • Target audience: Teachers and students University of cover a wider range of • Activities: Competitions and trainings. Technology schools.
Support material: - Exercise portal - Competition All materials are made in Estonian, and some are provided in Russian.
10 CYBERSECURITY EDUCATION INITIATIVES IN THE EU MEMBER STATES
DECEMBER 2022
Initiative (type, objective, scope, target Status and next Country /Entity audience, activities…) steps
Development of a web platform to share material to primary and secondary schools’ pupils and teachers: • Type: Website • Objective: Deploy learning material for kids, on many topics, including cybersecurity. • Scope: EU European Union – • Target audience: Teachers and students Deployed Learning Corner • Activities: Games, learning material, and teaching material.
Support material: - Games - Competitions - Activity books - Teaching material
Development of an educational package on
cybersecurity (open website) • Type: Website • Objective: Teach cybersecurity skills to citizens Ongoing, and the aim is Finland - Aalto • Scope: EU (Finland has been awarded EUR 5 to launch the initiative University million from the EU recovery instrument. The before 2025. aim will be to share it with all EU countries) • Target audience: All citizens • Activities: Online training courses
Support material: Exercise portal.
CyberEnJeux:
• Type: Training plan • Objective: Teach the basics of cybersecurity through the creation of a game • Scope: France • Target audience: Secondary school students and higher education (BTS/IUT). • Activities: Provision of a kit with practical information and thematic sheets to guide teachers when creating the cyber game with students Ongoing. All these Joint ANSSI – Ministry of Education roadmap activities are incubated on cybersecurity training for students: by ANSSI’s innovation • Type: Training plan Lab in partnership with
France - ANSSI
• Objective: identifying curricula where a ANSSI’s Cybersecurity cybersecurity dimension could be Training Center and the implemented; training teachers (since then, a Ministry of Education mapping has been established of courses and and 110bis, its related skills evaluation schemes allowing to innovation Lab. integrate cybersecurity); developing cybersecurity educational material (since then: 14 introduction factsheets have been designed); developing innovative training material (since then: CyberEnJeux has been tested in 10 schools with more than 300 students and a release candidate is being now developed). • Scope: France • Target audience: Secondary school students.
11 CYBERSECURITY EDUCATION INITIATIVES IN THE EU MEMBER STATES
DECEMBER 2022
Initiative (type, objective, scope, target Status and next Country /Entity audience, activities…) steps
• Activities: Introduce the field of cybersecurity through cyber trainings.
Support material
- Kit to develop the game - Pedagogic sheets - Public website PIX
SecNumAcadémie - ANSSI:
• Type: MOOC • Objective: Teach the basics of cybersecurity • Scope: France • Target audience: Teenagers and adults • Activities: Cybersecurity MOOC
Association de protection de l'enfance sur internet | e-Enfance:
• Type: Interventions in schools • Objective: Protect children and teens from the dangers of the Internet, fight against cyberbullying. • Scope: France • Target audience: Primary school students to young adults • Activities: Interventions in schools and training on the responsible use of the Internet and possible risks such as cyber-bullying, cybersexism and other forms of cyber-violence.
Guidelines for the federal states
• Type: Policy • Objective: To present guidelines and Germany - Federal directions to the federal states, responsible for Office for designing and implementing their own N/A Information Security initiatives (BSI) Scope: Germany • • Target audience: Defined by the federal states • Activities: N/A
Promotion of cybersecurity as a profession and gender diversity
• Type: Training plan • Objective: Promote cybersecurity profession to address the shortage of qualified people in the area and the gender gap. The initiative of promoting cybersecurity is owned by the NCSA and carried out with the support of the Ongoing, aiming at Greece - National Hellenic Safe Internet Center and certain intensifying existing Cyber Security Universities. partnerships and Authority (NCSA) Scope: Greece executing relevant • actions plans. • Target audience: Mostly secondary school students and teachers, with some initiatives targeting university students • Activities: Presential and online courses.
Support material
- Talks and webinars - Courses and videos, posters, sharing platform
Hungary – National Hungarian National Cybersecurity Strategy Cyber Security
• Type: Curricula and training N/A
Center
12 CYBERSECURITY EDUCATION INITIATIVES IN THE EU MEMBER STATES
DECEMBER 2022
Initiative (type, objective, scope, target Status and next Country /Entity audience, activities…) steps
• Objective: Increase competencies of children and young people • Scope: Hungary • Target audience: Primary, secondary, and higher education students • Activities: Training courses
Safer Internet Hungary:
• Type: Awareness raising through educational events, campaigns, conferences and webinars • Objective: Provide children, parents and teachers with information and advice on safe use of the internet • Scope: Hungary • Target audience: teachers, parents and children • Activities: Videos and books
Support material
- Lectures and videos - Games - Events and conferences - Hotline and helpline
Cyberwise
• Type: Curricula • Objective: Provide an introductory course on cybersecurity through the Junior Cycle Short Course • Scope: Ireland Ongoing, with the aim to Ireland - University • Target audience: Primary and secondary expand the initiatives to College Dublin school students. more schools and get • Activities: Courses and competitions more funding.
Support material
- Web platform, with short courses - Industry based initiatives (e.g., bootcamps, capture the flags and cybersecurity schools’ challenges) Education programmes aimed at primary and secondary schools, universities, and post-graduate training. Specifically:
WeGil ACL Lazio Cybersecurity Academy
• Type: Curricula • Objective: Provide trainings through open to collaboration with universities, high schools, and large Italian information technology companies Cybersecurity Academy Italy - National • Scope: Lazio is ongoing in the Lazio Cybersecurity • Target audience: Upper secondary schools region, with the aim of Agency (ACN) and professionals seeking specialisation extending the initiatives to other regions. • Activities: Courses
Support material:
- Website - Trainings
Italy’s National Cybersecurity Strategy 2022-2026 • Type: Curricula and training • Objective: Provide cybersecurity education at all levels of education
13 CYBERSECURITY EDUCATION INITIATIVES IN THE EU MEMBER STATES
DECEMBER 2022
Initiative (type, objective, scope, target Status and next Country /Entity audience, activities…) steps
• Scope: Italy • Target audience: Students on all levels of education and teachers • Activities: Training and courses
National coordination network of Higher Technological Institutes (ITS Academy) for the digital transition • Type: Training • Objective: Promote the development of a national ecosystem for training of new digital skills, support the enhancement of the best experiences, also in the Cloud Computing and Cyber Security fields of the Higher Technological Institutes (ITS Academy), support the training of highly skilled technologists, with outlets at all levels, either in the Public Administration and in the private sector • Scope: Italy • Target audience: Students of Higher Technological Institutes • Activities: Training and courses
CyberChallenge.it • Type: Talent search initiative • Objective: Identify young talents in schools and academia • Scope: Italy • Target audience: High school and university students • Activities: Participation in Catch The Flag events and training, and participation in the European Cybersecurity Challenge
Latvian Cybersecurity Strategy 2014-2018 and 2019-2022 Strategy
• Type: Curricula and training Latvia – CERT.LV • Objective: Ensure that society acquires IT (Ministry of Defence) skills and master basic online security in order and Ministry of to learn more complex cybersecurity concepts N/A Education and Scope: Latvia •
Science
• Target audience: All levels of education • Activities: Training, courses, games and competitions
National Cyber Security Strategy of Lithuania
• Type: Curricula and training • Objective: Provide children and pupils fundamental knowledge of cybersecurity
Lithuania – Ministry
N/A of National Defence • Scope: Lithuania • Target audience: Students on all levels of education and teachers • Activities: Training and courses
14 CYBERSECURITY EDUCATION INITIATIVES IN THE EU MEMBER STATES
DECEMBER 2022
Initiative (type, objective, scope, target Status and next Country /Entity audience, activities…) steps BEE SECURE
• Type: Curricula and trainings, campaigns • Objective: Promote a safer, responsible and positive use of information technologies Scope: Luxembourg Maintain all ongoing • Luxembourg - Target audience: Children, adolescents, activities and • Service National de continuously assess and parents, teachers and the senior population la Jeunesse address future needs • Activities: Presential trainings, publication of and demands. material and events
Support material
- Publications - Interactive tools (Super User, SpamBee)
Digital Skills Bootcamp
• Type: Training sessions • Objective: Introduce children to coding and develop the digital skills of individuals. The eSkills Malta Foundation bootcamp is carried out annually and usually will carry out a includes cybersecurity courses Cybersecurity • Scope: Malta Roadshow in • Target audience: Children and adults collaboration with a • Activities: Training courses private security
Malta - eSkills Malta
Presential events (e.g., Safer Internet Day) company.
Foundation,
• Type: Education and awareness events
BeSmartOnline! and
• Objective: Promote the safe and responsible MITA intends on
Malta Information
use of digital technologies launching a new
Technology Agency
• Scope: Malta initiative as part of the
(MITA)
• Target audience: Students and parents national cyber security • Activities: School interventions, seminars, awareness and theatre plays education campaign, which will include Support material foundational and -Social media advances courses for -Online campaigns SOC analysts. -Media outlets -Webinars -Videos
National Cybersecurity Agenda
• Type: Curricula and training • Objective: Revise the existing curricula for primary and secondary education to cover developments in the area of cybersecurity • Scope: Lithuania • Target audience: Primary and secondary school students, teachers, and parents. Ongoing. The developer • Activities: Training and courses of Hackchallenges.NL aims to develop serious Hackchallenges.NL games to teach
Netherlands - NCSC
• Type: Platform cybersecurity and • Objective: Introduce the fundamentals of improve the integration cybersecurity through cybersecurity games with the Dutch Platform and challenges. HackShield. • Scope: Netherlands • Target audience: Primary and secondary school students • Activities: Fox book, a website that teaches kids the importance of creating safe passwords, and Catch The Flag, which introduces teenagers to topics such as
15 CYBERSECURITY EDUCATION INITIATIVES IN THE EU MEMBER STATES
DECEMBER 2022
Initiative (type, objective, scope, target Status and next Country /Entity audience, activities…) steps
hacking, forensics, coding and crypto through challenges.
Support material
-Website
E-learning portal
• Type: Platform • Objective: Introduce the topic of cybersecurity, as well as other topics such as artificial intelligence, algorithms and programming, databases, biology, chemistry, physics and – multimedia. Poland National Scope: Poland N/A Educational Network • • Target audience: Primary and secondary school students and teachers. • Activities: Training courses and competitions.
Support material
-Videos -Publications
National Strategy for Cyberspace Security
• Type: Curricula and training The action plan of the • Objective: Prevention, education and National Strategy for awareness-raising in the cyber field. Cyberspace Security is • Scope: Portugal reviewed annually by the • Target audience: Primary, secondary, and National Cybersecurity higher education students Center, where new • Activities: Actions by the various ministries, activities are registered with activities dedicated to raising awareness every year (biannual among students, for example. frequency). The action plan is then sent to the C-LAB High Council for • Type: Training platform Cyberspace Security • Objective: Support citizens, schools and (depending on the Prime entities by providing a singular platform with Minister) where it is trainings based on emerging technologies approved and ratified. • Scope: Portugal Execution reports are • Target audience: Students between the ages sent to parliament for of 6 and 18 Portugal - National ratification and political Cyber Security • Activities: Training scenarios action.
Centre (NCSC) Support material
-Website Some initiatives are Online courses (MOOCs) being launched in • Type: Trainings cooperation with the • Objective: Provide cyber-hygiene skills to Portuguese Order of citizens by presenting topics such as threats in Psychologists. the cyberspace, how to safely use Other activities in technologies, misinformation and online preparation include: shopping national campaigns for • Scope: Portugal the cybersecurity month, • Target audience: All citizens above the age of Safer Internet Day in 14. February 2023, gender • Activities: Four different MOOCs (1 - parity campaigns and Cybersafe Citizen; 2- Cyber-informed Citizen; rolling out of activities 3- Cybersafe Consumer; 4 - Cybersocial with the National Citizen) Association of Teachers of Informatics (ANPRI).
CybersecurityChallenge.pt
• Type: Talent search initiative
16 CYBERSECURITY EDUCATION INITIATIVES IN THE EU MEMBER STATES
DECEMBER 2022
Initiative (type, objective, scope, target Status and next Country /Entity audience, activities…) steps
• Objective: Identify young talents in schools and academia • Scope: Portugal • Target audience: High school and university students • Activities: Participation in Capture The Flag events and training, and participation in the European Cybersecurity Challenge.
Support material
-Website -Promotional campaigns -Online trainings
Centro Internet Segura & presential events
• Type: Awareness events and sessions, resources, and social media campaigns • Objective: Promote a safer, responsible, and positive use of digital technologies • Scope: Portugal • Target audience: Children, adolescents, parents, teachers, and the senior population • Activities: Presential/ online sessions, seminars, events, and publications.
Support material
-Social media -Website -Online campaigns -Publications / resources
Cyber Security Strategy of Romania
• Type: Curricula and training – • Objective: Promote and consolidate the
Romania
security culture in the cyber field.
Romanian National
N/A Cyber Security • Scope: Romania Directorate (DNSC) • Target audience: Primary, secondary, and higher education students • Activities: Educational programs
National Cybersecurity Strategy 2021-2025 of the Slovak Republic
• Type: Curricula and training • Objective: Provide basic security education at Slovakia – National all levels of education • Scope: Slovakia N/A
Security Authority
• Target audience: Primary school • Activities: Vocational higher and secondary education systems and activities supporting security awareness
Kibertalent.si (Cybertalent) The URSIV plans to • Type: Talent search initiative collaborate with selected • Objective: Spot and attract potential talents for secondary schools and future cybersecurity careers faculties to provide
Slovenia - Slovenian
cybersecurity workshops Government • Scope: Slovenia locally, and connect Information Security • Target audience: Students between the ages academia, industry and Office (URSIV) of 16 and 25. R&D institutions to • Activities: Bootcamp and mentoring by attract more young cybersecurity experts, and participation in the people to cybersecurity European Cybersecurity Challenge careers.
17 CYBERSECURITY EDUCATION INITIATIVES IN THE EU MEMBER STATES
DECEMBER 2022
Initiative (type, objective, scope, target Status and next Country /Entity audience, activities…) steps Educational programmes
• Type: Curricula and training • Objective: Stimulate the demand for advanced cybersecurity education and increase the supply of cybersecurity educational programmes • Scope: Slovenia • Target audience: Undergraduate and postgraduate students. Later on, to be introduced into the curricula in primary and secondary education • Activities: Educational programs
Support material
-Website -Social media
Internet Segura for Kids (IS4K)
• Type: Awareness raising and training • Objective: Provide a helpline service and foster the safe and responsible use of the internet and new technologies. • Scope: Spain • Target audience: Children and teenagers, as well as families, educators and professionals who work with minors • Activities: School interventions and sessions, INCIBE is working on events, Cyberolympics. developing additional online courses, mainly
Talent identification
for families and in • Type: Talent search initiative Spain - Spanish collaboration with the • Objective: Attract more professionals to the National internet provider cybersecurity ecosystem in Spain Cybersecurity Orange. • Scope: Spain Institute (INCIBE) A course developed in • Target audience: Students over fourteen years collaboration with the old Ministry of Education for • Activities: Practical labs showcasing how educators will be penetration testing and forensic analysis is launched in late 2022. done, and competitions
Support material
-Website -Social media -MOOCs and training courses -Publications (guides) -Videos -Online workshops -Didactic units Are you sure? #290CyberSecurity The initiative is ongoing, • Type: Awareness raising but the Swedish • Objective: Show students how to create safe Federation of Young habits online Scientists is planning to • Scope: Sweden operate the initiative in
Sweden - Swedish
the long term. Federation of Young • Target audience: Primary and secondary Scientists and school students It is also planned to Swedish Internet • Activities: Lectures from IT experts develop teaching
Foundation
Support material materials and lectures -Teaching materials for grades 1-3 to cover - Webpage for the Cybersecurity Academy all grades (1-12) and to - Social media posts (Facebook, Instagram, develop teacher training LinkedIn, etc.) via online courses in
18 CYBERSECURITY EDUCATION INITIATIVES IN THE EU MEMBER STATES
DECEMBER 2022
Initiative (type, objective, scope, target Status and next Country /Entity audience, activities…) steps
- Mailing lists and newsletters 2022 and 2023, as well as face-to-face training.
In the long term, the Cybersecurity Academy would like to see the teaching material become standard in all schools, so that every Swedish pupil can learn about cybersecurity systematically.
19 CYBERSECURITY EDUCATION INITIATIVES IN THE EU MEMBER STATES
DECEMBER 2022
4. BEST PRACTICES AND MAIN CHALLENGES
This chapter presents the identified best practices in Europe in terms of cybersecurity in education for primary and secondary levels in Europe, based on the interviews. 4.1 GOVERNANCE AND PRIORITISATION PROCESS This section presents the governance in place in some Member States in terms of cybersecurity in education, as well as the prioritisation process of the educational activities in place. Governance has been defined to refer to structures and processes (e.g., organisations involved, reporting process) that are designed to build the initiatives. We found various different practices regarding the governance in place in each country. Reporting is defined as the process of regular provision of information to decision-makers – often ministries – within a country to support them in their work. Prioritisation is defined as the specific process of deciding which initiative should be developed and when. Regarding the responsibility for initiatives, two main practices were observed in the Member State consulted. On one hand (60% ), the National Cybersecurity Agencies manage all initiatives (a ministry is always accountable, but the initiatives are designed by the Agency). On the other hand, a ministry itself is responsible for designing the initiatives. The main difference lies in the funding of the initiatives. In the case of the first practice, the Agency has to convince the ministry it refers to “release” the necessary budget and implement the initiatives. In the case of the second, there is no need to find sponsorship. We also saw many different stakeholders involved in the initiatives (i.e., universities, IT companies, other experts…). These practices are presented in more detail in the following tables: Table 3: Best practices of Member States regarding governance and prioritisation process
Good practice Example from a Member State Organisation, reporting and prioritisation process
ANSSI (France) and the Ministry of Education work together towards developing cybersecurity training and education, but there are no strong sponsorships for the activities. The topic of cybersecurity training and education for the youth is identified as a political priority but remains an emerging challenge to be tackled in years to come in The National France. Cybersecurity Agency is responsible for the NUKIB (Czech Republic) ´s director reports directly to the prime 1 initiatives around minister. NUKIB cooperates its activities with the Ministry of Education, cybersecurity in education Youth and Sports as an equal partner. The ministry is responsible for and reports to a ministry in overall education strategy and NÚKIB is the coordinator of charge. cybersecurity educational activities (it makes sure that cybersecurity education aspects are considered and included).
INCIBE (Spain) reports to the Ministry of Economic Affairs and Digital Transformation.
20 CYBERSECURITY EDUCATION INITIATIVES IN THE EU MEMBER STATES
DECEMBER 2022
Good practice Example from a Member State
A Ministry (or multiple In Luxembourg, the Service national de la jeunesse (SNJ) is the ministries) is responsible coordinator of the governmental initiative BEE SECURE, and the SNJ for the initiatives and plays is attached to the Ministry of National Education, Children and Youth; 2 a role of sponsor. Three ministries support the initiative (the Ministry of National Education, Children and Youth, the Ministry of economy, the Ministry It gives the go-ahead to of Family Affairs, Integration and the Greater Region). the National Agency. In Italy, ACN has set up a working group of stakeholders from universities, high schools, and IT companies.
In Malta, MCAST Hackspace, sponsored by eSkills Malta Foundation and supported by MITA, Cybersecurity Malta and Industry. Hackspace is a virtual and physical space where students take part in security dialogues between themselves and with Industry partners and also A community of experts is include cybersecurity sessions for further learning.
3
involved in the initiatives. In Estonia, a board of experts lead the initiatives with the help of a community of teachers.
In Ireland, UCD works with other schools, and a lot of non-for-profit organisations. This is facilitated by a working group of cybersecurity education stakeholders, organised by the Ministry for Communications, which oversees the National Cyber Security Centre.
We also identified two different practices regarding funding. Funding is the means by which the money required to undertake an initiative is secured and then made available as required. Both practices depend very much on the reporting presented above. In the first practice, which usually occurs when initiatives are launched by a ministry, funding is provided entirely by the ministry. The second occurs when the ministry responsible does not fund the initiatives. Table 4: Best practices of Member States regarding funding
Good practice Example from a Member State Funding
Funding is In Ireland, UCD receives fundings form the Public Service Innovation Fund in 4 provided by the the Department of the Environment Climate and Communication. state. Funding is provided by private sponsors In Austria, the Ministry of Education is not implicated in the initiatives and is not (industry) or 5 willing to fund those. The CSA thus works with a lot of organisations that do not other means of charge for their training and courses. implementing the initiatives are found.
4.2 MEASUREMENT MECHANISM This section presents the mechanisms that have been implemented in some Member States to measure and monitor the effectiveness of the initiatives, as well as their completion. The effectiveness of a project could be defined as the degree to which the objectives are met, within the deadlines, respecting the agreed budget. The effectiveness of a project or initiative can be measured by creating indicators (KPIs) to measure the level of performance. There are different types of indicators, and it is possible to collect indicators them by different means of data collection, (surveys, metrics (in a website), interviews, etc). After the collection of data, you need to analyse and interpret the data to be able to make decisions based on the results obtained. 21 CYBERSECURITY EDUCATION INITIATIVES IN THE EU MEMBER STATES
DECEMBER 2022
Regarding the initiatives, the effectiveness can be considered as the degree to which the students are being educated in cybersecurity. The KPIs are usually deployed to measure the completion of the objectives: follow up on the daily activities (task completion); collecting feedback form participants and all stakeholders; collection of analytics from websites and apps. Only some Member State actually collect KPIs which measure the performance of the users in the activities. Measuring the impact of initiatives on the target audience is complex. Table 5: Best practices of Member State regarding measurement mechanism
Measurement mechanism Example from a Member State
Collection of task completion NUKIB (Czech Republic) and ACN (Italy) both 1 indicators that reflect on the level of implemented a KPI for task completion of its national plan. completion of a specific initiative Feedback collection from participants of an initiative (teachers and other UCD (Ireland) collects feedback from the participants after
2
stakeholders, students) to measure each initiative the implication of stakeholders Collection of indicators of number of INCIBE (Spain) collects indicators on the number of people people using a service to measure 3 who have used their services: gender, age, geographical visibility and attractiveness of those location… services Observation of the performance of NCSC (Netherlands) observes if users are able to conclude
4
the users in the activities the objectives or not, and if additional tips should be added Collection of analytics from websites SNJ (Luxembourg) uses analytics from their website, their 5 and apps to measure the social media accounts, and the campaigns they conduct effectiveness
22 CYBERSECURITY EDUCATION INITIATIVES IN THE EU MEMBER STATES
DECEMBER 2022
4.3 KEY PRINCIPLES This section presents the key principles that have been followed in developing the initiatives of the interviewed Member States. Various key principles were highlighted by the Member States. These principles guided the approach taken by organisations in designing and deploying the initiatives. We found that the key principles were often shared by many Member States. The table below summarises the key principles that are followed by Member States in implementing and designing their initiatives: Table 6: Key principles followed by the Member States
Key principle Example from a Member State
On top of the initiatives presented above with regard to the Collaborative approach: basing the experts’ communities: in Slovenia, The URSIV plans to initiatives on close collaboration with collaborate with selected secondary schools and faculties 1 stakeholders (ministries, schools and to provide cybersecurity workshops locally, and connect teachers, industries, and other academia, industry and R&D institutions to attract more experts…) young people to cybersecurity careers. Pedagogic approach: actively involve In France, ANSSI has created a kit designed for kids to
2
students in the activities allow them to develop a cyber game Pareto principle: looking for multipliers In Greece, the NCSA is forming strategic partnerships with to try to get maximum results by 3 esteemed stakeholders, in order to reach wider audiences exploiting the least amount of and benefit from their proven know-how. resources In Malta, MITA focuses on preparing and executing yearly Preparing yearly plans to have a step plans that address the challenges and trends in the field of
4
ahead of the next initiatives cybersecurity, whilst still maintaining a plan flexible enough to tackle new problems The eSkills Malta Foundation leads initiatives for parents Educating children through the on how to make wise use of social media and the parents: creating a chain reaction consequences of misuse (e.g., go to the parent’s place of
5
which starts with the parents and work and provide sessions about online safety), in order reaches all levels of education for the parents to have the best behaviour and therefore become good examples for their children.
4.4 COLLABORATION WITH OTHER ORGANISATIONS, INCLUDING ENISA This section presents the existing collaborations between organisations, countries, or ENISA, in the field of cybersecurity education initiatives, in order to streamline activities or learn from each other, share good practices. The collaboration can have different purposes, such as obtaining more budget, or gaining expertise. In conducting the interviews, we often noted that the interviewees stressed that they would really like (if not already do) to work with ENISA and other Member States. For most Member States this is not yet the case. We have noted only a few of these, which are listed in the table below. 23 CYBERSECURITY EDUCATION INITIATIVES IN THE EU MEMBER STATES
DECEMBER 2022
Table 7: Best practices of Member States regarding collaboration
Collaboration practice Example from a Member State
Estonia works on a regular basis with Norway: they 1 Collaboration between countries organise a cybersecurity education summer camp and a cybersecurity competition together. In Italy, ACN uses the European Cybersecurity Skills Collaboration with ENISA (use of Framework -developed by ENISA - for the identification of
2
ENISA material) professional profiles to be trained at the Lazio Cybersecurity Academy.
24 CYBERSECURITY EDUCATION INITIATIVES IN THE EU MEMBER STATES
DECEMBER 2022
5. CONCLUSIONS
This chapter presents the main findings of the study, in particular it highlights the main challenges and obstacles faced by EU Member States in implementing cybersecurity initiatives in education within their countries and summarises the key priorities that ENISA should focus on for the EU cybersecurity education roadmap. 5.1 CHALLENGES ENCOUNTERED This section presents any challenges or barriers encountered by the Member States in implementing the Cybersecurity Education initiatives within their countries. A challenge can be defined as a fact or process which has made (or still makes) the initiatives difficult to deploy, or even prevented the initiative from reaching the expected level. Below is a list of challenges faced by the Member States encountered in the deployment of the initiatives: • Rigidity of anchored culture of the ministries responsible for the cybersecurity initiatives in education: The culture, which leads to cybersecurity being treated as a secondary topic (as mentioned in the previous section), leads to a slow pace of change management within these public bodies, which prevents national cybersecurity agencies - or any other organisation designing the initiatives - from deploying them at national level. • Decentralized approach: In Germany and Austria, the country is divided into a number of federal states, which have a certain amount of autonomy at many levels, including in terms of educational strategy. This makes it impossible for them to implement national initiatives, and very difficult to monitor local initiatives. • Lack of time and resources: o Teachers’ low availability: In some Member States, initiatives are launched locally with teachers in their free time, which is very limited. It is then very difficult to have them participate due to their low availability. o Staff turnover: In some Member States, there is a high turnover in the teams working on the initiatives. It is thus difficult to maintain the activities of the initiatives on a long term. • Lack of stakeholder recognition: Stakeholders who participate in initiatives, sometimes in their spare time (e.g., teachers in many Member States), might not receive enough recognition, which could further motivate them to participate in initiatives. For example, it was mentioned that teachers could get a certification or a badge, when they implement an initiative at school and the sense of ownership or confidence, they are given could motivate them further. • Need to take into account the different languages spoken in a country: In Luxembourg, Belgium or Austria, for example, initiatives and especially support materials need to be developed in the different languages of the country in order to reach all the students. 25 CYBERSECURITY EDUCATION INITIATIVES IN THE EU MEMBER STATES
DECEMBER 2022
5.2 KEY PRIORITIES FOR THE ENISA ROADMAP This section presents the key priorities that ENISA should focus on for the EU cybersecurity educational roadmap. • Advice on how to approach ministries: For many Member States, the anchored culture of the ministries responsible for the initiatives relegates cybersecurity, and in particular the cybersecurity education field to the background. This makes it difficult to push initiatives at national level and to get funding. Those Member States believe that ENISA is in a strong position to convince the national authorities of the importance of cybersecurity education, and to give them the keys on how to address the challenges. • Advice on how to develop initiatives at national level: In some Member States, such as Germany and Austria, the autonomy of the federal states within the country makes it difficult to deploy initiatives at national level, and hampers progress on this area. Those Member States hope that ENISA has the capacity to be the backend/coordinator of the topic and identify and encourage local authorities to develop educational initiatives. • Visibility on what the other Member States are doing: Many Member States expressed their willingness to compare and discuss existing initiatives deployed in other Member States. By doing so, the Member States would be able to learn from each other and make the most out of each State’s best practices, challenges encountered, and key lessons regarding those initiatives. • Encourage Member States to engage in partnerships with the private sector (e.g., industry): While some Member States already engage in this kind of partnerships (e.g., Italy, Slovenia…), most Member States miss on this opportunity to access more technical / operational point of views, and also to build a multi-disciplinary team. Indeed, this partnership with the private sector would allow to a collaborative approach around decision making process and implementation of cybersecurity innovation initiatives. 26 -N -EN -341 -22 8 -0 TP ABOUT ENISA The European Union Agency for Cybersecurity, ENISA, is the Union’s agency dedicated to achieving a high common level of cybersecurity across Europe. Established in 2004 and strengthened by the EU Cybersecurity Act, the European Union Agency for Cybersecurity contributes to EU cyber policy, enhances the trustworthiness of ICT products, services and processes with cybersecurity certification schemes, cooperates with Member States and EU bodies, and helps Europe prepare for the cyber challenges of tomorrow. Through knowledge sharing, capacity building and awareness raising, the Agency works together with its key stakeholders to strengthen trust in the connected economy, to boost resilience of the Union’s infrastructure, and, ultimately, to keep Europe’s society and citizens digitally secure. More information about ENISA and its work can be found here: www.enisa.europa.eu. ISBN 978-92-9204-611-8 doi: 10.2824/486119
Fotnoter
- 1 Safer Internet Centers: https://digital-strategy.ec.europa.eu/en/policies/safer-internet-centres 2 Cybersecurity Act, Article 10: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:52017PC0477&rid=3 3 Digital Education Action Plan (2021-2027) of the European Commission
- 4 James Lewis (2017), Darwin and Ransomware, CSIS 5 “The two most important ways to defend against security threats”, CSO (2019) More information is available at: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:52017PC0477&rid=3
- 7 Regulation (EU) 2019/881 of the European Parliament and of the Council of 17 April 2019 on ENISA and on information and communications technology cybersecurity certification and repealing Regulation (EU) No 526/2013 ENISA Programming Document 2022–2024 available here: https://www.enisa.europa.eu/publications/corporatedocuments/enisa-single-programming-document-2022-2024
- Based on the interviews and the desk research conducted, 11 out of 27 Member States have developed initiatives which have more practical and engaging approaches.
- Based on the interviews conducted with 16 Member States, 9 out of 16 Member States indicated that the National Cybersecurity Agency designs and takes the lead for all initiatives.