ENISA Single Programming Document 2023-2025 Condensed
EUROPEAN UNION AGENCY FOR CYBERSECURITY
ENISA SINGLE PROGRAMMING DOCUMENT 2023–2025
Condensed work programme 2023 JANUARY 2023 CONTACT For contacting ENISA please use the following details: info@enisa.europa.eu website: www.enisa.europa.eu LEGAL NOTICE This publication presents the European Union Agency for Cybersecurity (ENISA) Single Programming Document 2022–2024 as approved by the Management Board in Decision No MB/2010/17. The Management Board may amend the Work Programme 2022–2024 at any time. ENISA has the right to alter, update or remove the publication or any of its contents. It is intended for information purposes only and it must be accessible free of charge. All references to it or its use as a whole or partially must contain ENISA as its source. Third-party sources are quoted as appropriate. ENISA is not responsible or liable for the content of the external sources including external websites referenced in this publication. Neither ENISA nor any person acting on its behalf is responsible for the use that might be made of the information contained in this publication. ENISA maintains its intellectual property rights in relation to this publication. COPYRIGHT NOTICE © European Union Agency for Cybersecurity (ENISA), 2022 This publication is licenced under CC-BY 4.0 “Unless otherwise noted, the reuse of this document is authorised under the Creative Commons Attribution 4.0 International (CC BY 4.0) licence (https://creativecommons.org/licenses/by/4.0/). This means that reuse is allowed, provided that appropriate credit is given and any changes are indicated”. Copyright for the image on the cover and internal pages: © Shutterstock For any use or reproduction of photos or other material that is not under the ENISA copyright, permission must be sought directly from the copyright holders. Luxembourg: Publications Offi ce of the European Union, 2022 Print ISBN 978-92-9204-631-6 ISSN 2467-4397 doi: 10.2824/892841 TP-AH-23-002-EN-C PDF ISBN 978-92-9204-630-9 ISSN 2467-4176 doi: 10.2824/107843 TP-AH-23-002-EN-N
ENISA SINGLE PROGRAMMING DOCUMENT 2023–2025
Condensed work programme 2023 EUROPEAN UNION AGENCY FOR CYBERSECURITY
TABLE OF CONTENTS
ACTIVITY 1: PROVIDING ASSISTANCE IN POLICY DEVELOPMENT 8
ACTIVITY 2: SUPPORTING IMPLEMENTATION OF UNION POLICY AND LAW 11
ACTIVITY 3: BUILDING CAPACITY 14
ACTIVITY 4: ENABLING OPERATIONAL COOPERATION 18
ACTIVITY 5: CONTRIBUTE TO COOPERATIVE RESPONSE AT UNION AND MEMBER STATES LEVEL 21
ACTIVITY 6: DEVELOPMENT AND MAINTENANCE OF EU CYBERSECURITY CERTIFICATION FRAMEWORK 25
ACTIVITY 7: SUPPORTING EUROPEAN CYBERSECURITY MARKET AND INDUSTRY 28
ACTIVITY 8: KNOWLEDGE OF EMERGING CYBERSECURITY CHALLENGES AND OPPORTUNITIES 31
ACTIVITY 9: OUTREACH AND EDUCATION 34
ACTIVITY 10: ADVISE ON RESEARCH AND INNOVATION NEEDS AND PRIORITIES 38
ACTIVITY 11: PERFORMANCE AND RISK MANAGEMENT 41
ACTIVITY 12: STAFF DEVELOPMENT AND WORKING ENVIRONMENT 45
FOREWORD
The strong cyber dimension of the Russian war of aggression against Ukraine and its reflections in the cybersecurity threat landscape have once again emphasised the role of cybersecurity as a cornerstone of a digital and connected Europe. Despite the spill-overs and direct attacks, by-and-large the EU has been able to deal with the cyber threats posed by the Russian aggression through the resilience of its Member States and across Europe, as well as forging support and cooperation with Ukraine and other allies and partners.
Within this context, ENISA’s challenge is both to keep pace and set the pace in supporting the Union in achieving a high common level of cybersecurity across Europe. This Single Programming Document (SPD) for the years 2023-2025 represents another step in bringing this about.
Firstly, it puts emphasis on strengthening the resilience of Member States and EU institutions, bodies and agencies. In 2023, approximately half of ENISA’s operational resources, both budget and human resources, will be dedicated to enhancing operational cooperation and building capacity. Together with the one-off support of up to 15 million EUR, which the European Commission allocated to ENISA in Autumn 2022, the Agency will be able to massively scale up and expand its ex-ante and ex-post services to Member States in 2023.
Secondly, building on the outcomes of strategic discussions within its Management Board throughout 2022, the Agency has developed service packages in key areas of its mandate. They integrate ENISA’s various outputs across different activities, help the agency to prioritise its actions, build and make use of internal synergies, and ensure that adequate resources are reserved across the Agency in a transparent manner.
Thirdly, through this work-programme ENISA will endeavour to help Member States to prepare for the transposition of the reviewed NIS Directive, as well as to prepare the ground for the roll-out and implementation of the EU cybersecurity certification schemes.
Finally, recognising the growing need to bring together the EU's activities and resources across the cybersecurity communities, this SPD establishes a new activity in the area of research and innovation to structure the Agency’s cooperation and collaboration with the European Cybersecurity Competence Centre (ECCC) and its emerging networks.
All those areas also accentuate the resource constraints under which the Agency now operates. The foreseen budget increase for the 2023 work programme has been fully absorbed by the increase in staff expenditure and inflation. Due to a shortfall of over 3 million EUR, the Agency has had to reduce the scope of some of its operational activities, limiting the number of exercises and training it rolls-out or postponing its actions in countering ransomware.
Such reductions mean drawbacks in certain areas and might become a real obstacle if new tasks should be added to the Agency without a parallel increase in its resources. Thus, though ENISA welcomes the pioneering set of cybersecurity initiatives being put forward in 2022 and relishes the different and varied roles they imply for the Agency, it needs to have the right level of human and financial resourcing to match those aims and ambitions.
The EU has been mastering cybersecurity initiatives and structures not least through a unique general consensus across parties and across Member States as its prime driving force. This consensus should now also include the resourcing of the Agency. This would give the Union the ability it needs to steer cybersecurity developments in the years to come.
Juhan Lepassaar
Executive Director
WORKPROGRAMME2023
This is the main body of the Work Programme describing, in terms of its operational and corporate activities, what the Agency aims to deliver in the year 2023 towards achieving its strategy and the expected results. Ten operational activities and two corporate activities in total have been identified to support the implementation of ENISA’s mandate in 2023.
The activities of the work programme seek to mirror and align with the tasks set out in chapter two of the CSA, demonstrating concretely not only the specific objectives, results and outputs expected for each task but also the resources assigned.
ACTIVITY 1: Providing assistance in policy development Overview of activity
This activity delivers assistance and advice to the EU and Member States in developing cybersecurity policy and sector-specific policy and legislative initiatives on matters related to cybersecurity and on the basis of the 2020 EU Cybersecurity Strategy. Aspects such as privacy and personal data protection are taken into consideration (including encryption). The activity seeks to bolster policy initiatives on novel or emerging technology areas by providing technical, factdriven and tailor-made cybersecurity advice and recommendations. ENISA will support the EC and MSs on new policy initiatives through evidence-based inputs into the process of policy development. ENISA, in coordination with the EC and Member States will also conduct policy scouting to support them in identifying potential areas for policy development based on technological, societal and economic trends as well as in developing monitoring capabilities and tools to regularly and consistently be able to provide advice on the effectiveness of existing Union policy and law in accordance with the EU’s institutional competencies in the area. This activity also contributes to the service package INDEX by providing data used in the cybersecurity index (Activity 8), by providing input that can be used for future certification schemes (CERTI service package ) and by providing findings and recommendations for the service packages offered to critical NIS sectors (Activity 2). The added value of this activity is to support decision-makers in a timely manner on developments at the technological, societal and economic market levels which might affect the cybersecurity policy framework (see also Activity 8). Given the cross-cutting nature of cybersecurity across the policy landscape, the activity will provide an up-to-date risk-based analysis of cybersecurity not only in the areas of critical infrastructure and sectors, but also by providing advice across the field in an integrated and holistic manner. The legal basis for this activity is Article 5 of the CSA.
Objectives
• Foster cybersecurity as an integral part of EU policy (existing and new) • Ensure that EU policy makers are regularly informed about the effectiveness of the existing frameworks, and EU policy makers and stakeholders are provided with timely and tailor-made policy recommendations on future cybersecurity challenges and opportunities
Work Programme 2023 Results Link to strategic objective (ENISA strategy)
Cybersecurity aspects are considered and embedded across EU and national policies Cybersecurity as an integral part of EU policies Empowered and engaged communities across the cybersecurity ecosystem
Outputs Validation
1.1. Assist and advise the EC and Member States • NIS Cooperation Group (NIS CG) and other in reviewing the effectiveness of current formally established Groups (outputs 1.1, 1.2 cybersecurity policy frameworks and 1.3) 1.2 Assist and advise the EC and MS on new • ENISA ad hoc working groups (outputs 1.1, 1.2, policy developments, as well as carrying out and 1.3) preparatory work • National Liaison Officers Network, ENISA Advisory 1.3 Support policy monitoring of existing Group and other formally established expert and emerging policy areas and maintain groups (when necessary) a catalogue of all relevant cybersecurity legislations and policies at the EU level
Stakeholders and levels of engagement
Partners Involve / Engage
DG Connect, NIS Cooperation Group, National ENISA National Liaison Officers, operators of Competent Authorities, other formally established essential services, digital service providers and groups, European Commission Directorate industry associations or representatives. General’s Office and Agencies – depending on policy area (e.g. DG GROW, European Insurance and Occupational Pensions Authority)
Key performance indicators
ENISA’s addedvaluetoEU Unit of Frequency Data Results Target institutions, bodies and Member measurement source 2021 2023 States in providing support for policymaking (ex ante)
1.1. Number of relevant Number Annual Manual 193 215 contributions to EU and national collection from policies and legislative initiatives staff members
1.2. Number of references to ENISA Number Biennial Survey N/A Baseline to reports, analyses and/or studies be established in EU policy documents in 2023
1.3. Satisfaction with added value Biennial Survey N/A Baseline to of ENISA’s contributions be established in 2023
1.4. Number of EU policy files Number Annual Report N/A Baseline to under development and supported be established by ENISA in 2023
Resource forecast
Outputs Service A B C Total package (reserved for (reserved for other (reserved for ad related to tasks to maintain regular statutory hoc statutory category A statutory service) tasks) tasks)
FTE EUR FTE EUR FTE EUR FTE EUR
1.1 INDEX, SITAW, 1.45 246,712 0.00 11,387 0.10 0 1.55 258,099 NIS, CERTI
1.2 NIS, CERTI 1.30 28,086 0.60 27,150 0.10 0 2.00 55,237
1.3 NIS, CERTI 0.95 9,404 0.25 7,523 0.00 0 1.20 16,926
Activity total FTE 4.75 Budget 330,262
Work Programme 2023 ACTIVITY 2: Supporting implementation of Union policy and law Overview of activity
This activity provides support to Member States and EU Institutions in the implementation of European cybersecurity policy and the legal framework and technical advice on specific cybersecurity aspects of the implementation of the NIS2 and other legislations. The activity seeks to avoid fragmentation and supports a coherent implementation of the Digital Single Market across Member States, following a consistent approach between cybersecurity, privacy and data protection. Under this activity ENISA provides support to the NIS Cooperation Group, its work streams, and the implementation of its biannual Work Programme including, for example, the implementation of the 5G toolbox, but also new tasks under the NIS2 such as the EU register for operators of digital infrastructure. It further includes horizontal outputs, which address sector-agnostic cross-cutting issues , and sectorial outputs, which are sector-specific and are addressed via targeted service packages for the critical (NIS) sectors. In addition, this work contributes, with relevant sectorial intelligence, to other SPD activities such as exercises and training (Activity 3), situational awareness (Activity 5), knowledge and information (Activity 8), and awareness raising (Activity 9). Furthermore, Activity 2 provides support to MSs on cybersecurity aspects of policy implementation in the areas of digital identity and wallets (eID), once-only technical solutions (OOTS), technical aspects of privacy and data protection and to the Union’s policy initiatives on the security and resilience of the public core of the open internet (e.g. DNS4EU). Overall support is provided for the implementation of the 2020 EU Cybersecurity strategy. The legal basis for this activity is Article 5 and Article 6 (1)(b) of the CSA.
Objectives
• Consistent development of sectorial Union policies with horizontal Union policy to avoid implementation inconsistencies • Contribute to the efficient and effective monitoring of the implementation of EU cybersecurity policy in Member States • Effective implementation of cybersecurity policy across the Union and consistency between sectorial and horizontal cybersecurity policies • Improved cybersecurity practices taking on board lessons learned from incident reports
Results Link to strategic objective (ENISA strategy)
• Consistent implementation of Union policy and law in the area of cybersecurity • Cybersecurity as an integral part of EU policies • EU cybersecurity policy implementation reflects • Empowered and engaged communities across sectorial specificities and needs the cybersecurity ecosystem • Wider adoption and implementation of good practices
Outputs Validation
2.1. Support the activities of the NIS Cooperation • NIS Cooperation Group and/or established Group including its work programme work streams (Outputs 2.1, 2.2, 2.3) 2.2. Support Member States and the EC in the • Telecoms working group (ECASEC) and trust implementation of horizontal aspects of the services working group (Outputs 2.3, 2.4) NIS directive • eID Cooperation network, ENISA Ad Hoc 2.3. Support Member States and the EC with the Working Group on data protection engineering security and resilience of the NIS sectors via (Output 2.4) targeted service package identified in the • ENISA National Liaison Officers’ Network ENISA NIS strategy (as necessary) 2.4. Provide advice, issue technical guidelines and facilitate the exchange of good practices to support Member States and the EC on the implementation of cybersecurity aspects of transversal EU policies
Stakeholders and levels of engagement
Partners Involve / Engage
National cybersecurity agencies and national ENISA National Liaison Officers, operators of authorities for cybersecurity in the EU Member essential services, digital service providers, trust States (NIS CG plenary and work streams), service providers, data protection authorities, National Regulatory Authorities (ECASEC), Information Sharing and Analysis Centres National Supervisory bodies (ECATS), Conformity (ISACs), research and academia, and industry Assessment Bodies (CABs), and informal groups of associations or representatives. authorities (e.g. FESA, informal working group of financial authorities), EC, EU Institutions or bodies (e.g. Body of European Regulators for Electronic Communications (BEREC), European Data Protection Supervisor (EDPS), European Data Protection Board (EDPB), European Railway Agency (ERA), European Maritime Safety Agency (EMSA), other sectorial EU Agencies (e.g. ACER, EASA, ESA, ECB, EBA) and institutional industry bodies (e.g. ICANN, RIPE-NCC, ENTSO-E, ENTSO-G, EU.DSO entity)
Work Programme 2023 Key performance indicators
Contribution to policy Unit of Frequency Data Results Target implementation and measurement source 2021 2023 implementation monitoring at EU and national levels (ex post)
2.1. Number of EU policies and Number Annual Manual 5 5 regulations implemented at collection national level supported by from staff ENISA members
2.2. Number of ENISA reports, Number Biennial Survey N/A Baseline to be analyses and/or studies established referenced at EU and NIS CG in 2023 documents (survey)
2.3. Satisfaction with added-value of Biennial Survey N/A Baseline to be ENISA of support (survey) established in 2023
2.4. Number of critical sectors with Number Annual Internal N/A Baseline to be high level of cybersecurity analysis (NIS established maturity (NIS sector 360) sector 360) in 2023
Resource forecast
Service A B C Total Outputs package (reserved for (reserved for other (reserved for ad related to tasks to maintain regular statutory hoc statutory category A statutory service) tasks) tasks)
FTE EUR FTE EUR FTE EUR FTE EUR
2.1 SITAW, NIS, 6.2 336,846 0 - 0.25 - 6.45 336,846 TREX
2.2 SITAW, NIS, 4.45 422,402 0 0.3 - 4.75 422,402 CERTI, TREX
2.3 SITAW, NIS, - - 3 214,155 0.3 3.3 214,155 CERTI
Activity total FTE: 14.5 Budget: 973,404
ACTIVITY 3: Building capacity Overview of activity
This activity seeks to improve and develop the capabilities of Member States, Union institutions, bodies and agencies as well as various sectors to respond to cyber threats and incidents, raise resilience and increase preparedness across the Union. This is achieved through the development of frameworks (Risk management, strategies, etc.) that are based on lessons learnt from MSs through the implementation and development of their National Cybersecurity Strategies. Actions to support this activity include the organisation of large-scale exercises, sectorial exercises, training and others. In addition, the activity seeks to develop and raise CSIRT capabilities, support information sharing within the cybersecurity ecosystem including cross-border, and assist in reviewing and developing national and Union level cybersecurity strategies. This activity leads the service package TREX and contributes to NIS and INDEX service packages. The legal basis for this activity is Articles 6 and 7(5) of the CSA.
Objectives
• Increase the level of preparedness, capabilities and cooperation within and between Member States and sectors and EU institutions, bodies and agencies • Prepare and test capabilities to respond to cybersecurity incidents • Foster interoperable, consistent European risk management, methodologies and risk assessment practices • Increase skill sets and align cybersecurity competencies
Results Link to strategic objective (ENISA strategy)
• Enhanced capabilities across the community • Cutting-edge competences and capabilities in • Increased cooperation between communities cybersecurity across the Union • Empowered and engaged communities across the cybersecurity ecosystem
Work Programme 2023 Outputs Validation
2.1. Assist MSs to develop, implement and assess • NLO Network (as necessary) National Cybersecurity Strategies • CSIRTs Network (output 3.3) 3.2. Organise large-scale biennial exercises and 8 • CyCLONe members (as necessary) sectorial exercises • NIS Cooperation Group (output 3.2 and 3.3) 3.3. Organise training and other activities to support and develop maturity and skills of • EU ISACs (output 3.3) CSIRTs (including NIS sectorial CSIRT), NIS • Ad-hoc WG on SOCs (output 3.5) cooperation group (NIS CG) and work streams, information sharing and analysis centres (ISACs) and other communities 3.4. Develop coordinated and interoperable risk Stakeholders and levels 9 management frameworks of engagement
3.5. Support the reinforcement of Security
Involve / Engage
Operational Centres (SOCs) as well as their Cybersecurity professionals, private industry collaboration, assisting initiatives of the sectors (operators of essential services such Commission and Member States in this as health, transport etc.), EU Institutions and area in line with the objectives of the EU bodies, CSIRTs Network and related operational Cybersecurity Strategy in the building and 10 communities, European ISACs, CyCLONe improving of SOCs members, NISD Cooperation Group, ISACs 3.6. Organise and support cybersecurity Blueprint stakeholders challenges including the European Cyber Security Challenge (ECSC)
Key performance indicators
Increased resilience against Unit of Frequency Data Results Target cybersecurity risks and preparedness measurement source 2021 2023 to respond to cyber incidents
3.1.Increase/decreaseinindicatorsofmaturity
Maturity of national cybersecurity strategies
Number of Member States that rate the overall maturity of their cybersecurity strategy
High maturity Number Annual Survey 3 5
Medium maturity Number Annual Survey 4 5
Low maturity Number Annual Survey 3 2
Increased resilience against Unit of Frequency Data Results Target cybersecurity risks and preparedness measurement source 2021 2023 to respond to cyber incidents
Number of Member States planning to use ENISA's framework to measure the maturity of their national cybersecurity capabilities Already using Number Annual Survey 3 5 Not set but planning to use Number Annual Survey 4 5 Don’t know or have not set KPIs currently Number Annual Survey 3 3 and will not set KPIs The frequency with which Member States update their strategies to adapt to technological advancements and new threats Every 2–3 years Number Annual Survey 2 3 Every 4–5 years Number Annual Survey 6 8 More than 6 years or don’t know Number Annual Survey 2 2 Total maturity of ISACs (self-assessment) % Annual Report 63% 65%
3.2.Outreach,uptakeandapplicationoflessonslearnedfromcapability-buildingactivities
CySOPEx 2021 (number of improvements Number Per exercise Report 5 3 proposed by participants) 3.4Thenumberofexercisesexecuted Number Annual Report 5 5
annually
3.5Stakeholderassessmentoftheusefulness,addedvalueandrelevanceofENISAcapacity-building activities (survey)
Usefulness low % Biennial of Survey 9% Maximum capacity 5% building activities Usefulness medium % Average of Survey 71% 25% to 50% capacity building activities Usefulness high % Average of Survey 20% Minimum capacity 45% building activities
Work Programme 2023
Increased resilience against Unit of Frequency Data Results Target cybersecurity risks and preparedness measurement source 2021 2023 to respond to cyber incidents
Relevance low % Average of Survey 4% Maximum capacity 5% building activities Relevance medium % Average of Survey 53% 25% to 50% capacity building activities Relevance high % Average of Survey 43% Minimum capacity 45% building activities
3.5ISACsmaturity
Number of Exercises organised by EU % Biennial Report N/A Minimum ISACs 30% Number of Training sessions organised % Biennial Report N/A Minimum by EU ISACs 30%
Resource forecast
Outputs Service A B C Total package (reserved for (reserved for other (reserved for ad related to tasks to maintain regular statutory hoc statutory category A statutory service) tasks) tasks)
FTE EUR FTE EUR FTE EUR FTE EUR 3.1 TREX, INDEX 2.00 108,919 0.00 0 0.00 0 2.00 108,919 3.2 TREX, NIS 4.25 584,153 0.00 0 0.00 0 4.25 584,153 3.3 TREX 4.00 635,580 0.00 0 0.00 0 4.00 635,580 3.4 – 3.5 TREX 0.50 28,544 0.00 0 0.00 0 0.50 28,544 3.6 TREX 3.00 352,043 0.00 0 0.00 0 3.00 352,043
Activity total FTE: 13.75 Budget: 1,709,239
ACTIVITY 4: Enabling operational cooperation Overview of activity
The activity supports operational cooperation among Member States, Union institutions, bodies, offices and agencies and between operational activities in particular through its local office in Brussels, Belgium. Actions include establishing synergies with and between the various national cybersecurity communities (including the civilian, law enforcement, cyber diplomacy and cyber defence) and EU actors notably CERT-EU with a view to exchanging know-how, best practices, providing advice and issuing guidance. In addition, inline with NIS2 requirements ENISA will continue to support Member States in the CSIRTs Network in respect of operational cooperation. Moreover with the formal establishement of the EU CyCLONe (Cyber Crisis Liason Organization Network) in NISD2, ENISA will support tthe coordination of cyber crises by advising and assisting both networks. Under this activity ENISA is supporting operational communities through helping to develop and maintain secure and highly available networks and IT platforms and communication channels to ensure, in particular, the maintenance, deployment and uptake of the MeliCERTes platform . Furthemore, in view of the implementation of the NIS2 Directive, this activity supports coordinated vulnerability disclosure by designated CSIRTs in the CSIRTs Network and the implementation of a European vulnerability database. In view of the EC Recommendation 4520 (2021) and Council Conclusions of the 20 October 2021 (ST 13048 2021) on ‘exploring the potential of the Joint Cyber Unit initiative – complementing the EU Coordinated Response to Large-Scale Cybersecurity Incidents and Crises’, ENISA will engage in exploring the potential of the JCU, along the lines and the roles defined according to ongoing discussions amongst MSs and relevant EU institutions, bodies and agencies. In addition, this activity implements the ENISA Cybersecurity Support Action . This activity underpins the Situational Awareness service package and contributes to INDEX and NIS service packages. The legal basis for this activity is Article 7 of the CSA.
Objectives
• Enhance and improve incident response capabilities across the Union • Enable effective European cybersecurity crisis management by continuously improving the cyber crisis management framework • Ensure coordination in cybersecurity crisis management among relevant EU institutions, bodies and agencies (e.g. CERT-EU, European External Action Service (EEAS), European Union Agency for Law Enforcement Cooperation (EUROPOL) • Improve maturity and capacities of operational communities (CSIRTs Network, EU CyCLONe) • Contribute to preparedness, shared situational awareness and coordinated response and recovery to large-scale cyber incidents and crises across different communities (e.g. by providing Ex-ante services)
Work Programme 2023 Results Link to strategic objective (ENISA strategy)
• All communities (EU institutions and MSs) use a streamlined and coherent set of SOPs for • Effective cooperation amongst operational management of cyber crises actors within the Union in case of massive cyber incidents • Efficient tools (secure and with high availability) and methodologies for effective management of • Empowered and engaged communities across cyber crises the cybersecurity ecosystem
Outputs Validation
4.1. Support the functioning and operations of 4.1. NLO Network (as necessary) the operational networks and communities 4.2. CSIRTs Network and EU CyCLONe and cooperation with relevant stakeholders including blueprint actors . 4.3. Blueprint actors 4.2. Support coordinated vulnerability disclosure efforts by designing and deploying the EU Vulnerability Database. 4.3. Deploy, maintain and promote platforms for operational cooperation and tools including preparations for a secure virtual platform for CyCLONe
Stakeholders and levels of engagement
Partners Involve / Engage
Blueprint actors, EU decision-makers, institutions, NISD Cooperation Group, OESs and DSPs, ISACs agencies and bodies, CSIRTs Network Members, EU CyCLONe Members, SOCs.
Key performance indicators
EffectiveuseofENISA’s toolsand Unit of Frequency Data Results Target platformsandtake-upofSOPsin measurement source 2021 2023 operational cooperation
4.1 Number of users, both new and recurring, and usage per platform/tool/SOP provided by ENISA CSIRT Network Active users – increase from 2020 % Annual Platform 115% 110% Number of exchanges/interactions – % Annual Platform 291% 100% increase from 2020 EU CyCLONe Active users – increase from 2020 % Annual Platform 143% 100% Number of exchanges/interactions – % Annual Platform 1,011% 150%* increase from 2020 4.2 Uptake of platforms/tools/SOPs Ad hoc N/A during massive cyber incidents 4.3 Stakeholder satisfaction with the N/A Biennial Survey N/A Baseline to be relevance and added value of platforms/ established tools/SOPs including EU vulnerability in 2023 database
Resource forecast
Outputs Service A B C Total package (reserved for (reserved for other (reserved for ad related to tasks to maintain regular statutory hoc statutory category A statutory service) tasks) tasks)
FTE EUR FTE EUR FTE EUR FTE EUR 4.1 NIS, SITAW 4.30 44,567 3.70 412,895 0.35 0 8.35 457,462 4.2 NIS, SITAW 1.00 72,978 1.00 69,743 0.20 0 2.20 142,720 4.3 SITAW, NIS 3.00 636,908 3.00 885,440 0.00 0 6.00 1,522,348
Activity total FTE: 16.55 Budget: 2,122,530
Work Programme 2023 ACTIVITY 5: Contribute to cooperative response at Union and Member States level Overview of activity
This activity contributes to the development of cooperative preparedness and responses at the level of the Union and Member States to large-scale cross-border incidents or crises related to cybersecurity. ENISA is delivering this activity by aggregating and analysing reports to establish a common situational awareness, ensuring information flow between the CSIRTs network, CyCLONe, the Cyber Crisis Task Force and other technical, operational and political decision-makers at Union level and including cooperation with other services of EUIBAs such as CERT-EU and EC3 and the use of an information exchange with security vendors and non-EU cybersecurity entities. The activity includes the development of regular in-depth EU Cybersecurity Technical Situation Reports in accordance with CSA art 7(6). In addition, the activity foresees, at the request of Member states, the facilitation of the handling of incidents or crises (including analyses and the exchange of technical information). The activity supports Union institutions, bodies, offices and agencies in the public communication of incidents and crises. The activity specfic cyber threats, assisting in the assessment of incidents, facilitating the technical handling of incidents, supporting crossborder information sharing and analysing vulnerabilities, including through the EU Vulnerability Database (under development in Output 4.2). This activity supports operational cooperation, including mutual assistance and situational awareness in the framework of the proposed potential JCU. In addition, this activity implements the ENISA Cybersecurity Support Action . Moreover the activity persues the further fostering and optimising of structured cooperation with CERT-EU (please see Annex XIII Annual Cooperation Plan 2023). This activity leads the service package on situational awareness (SITAW) and contributes to the INDEX and NIS service packages. The legal basis for this activity is Article 7 of the CSA.
Objectives
• Enhanced preparedness and effective incident response and cooperation amongst Member States and EU institutions, including cooperation of technical, operational and political actors during incidents or crises • Common situational awareness before and during cyber incidents and crises across the Union • Information exchange and cooperation, cross-layer and cross-border between Member States and as well as with EU institutions
Results Link to strategic objective (ENISA strategy)
• Member States and institutions cooperating effectively during large-scale cross-border • Effective operational cooperation within incidents or crises the Union in case of massive (large-scale, cross-border) cyber incidents • Stakeholders and public aware of current developments in cybersecurity • Empowered and engaged communities across the cybersecurity ecosystem
Outputs Validation
5.1. Generate and consolidate information (including • Blueprint actors for the general public) on common cyber situational awareness, technical situational reports, incident reports, threats and support consolidation and exchange of information at strategic, operational and technical levels 5.2. Support technical (including through MeliCERTes) and operational cooperation, incident response coordination and EU wide crisis communication during large-scale crossborder incidents or crises 5.3. Maintain, develop and promote the trusted network of vendors or suppliers for information exchange and situational awareness
Stakeholders and levels of engagement
Partners Involve / Engage
EU Member States (including CSIRTs Network Other types of CSIRTs and PSIRTs members and CyCLONe), EU Institutions, bodies and agencies, other technical and operational blueprint actors, partnership programme for 5.3 (with trusted vendors, suppliers and partners)
Work Programme 2023 Key performance indicators
ENISA ability and preparedness Unit of Frequency Data Results Target to support response to massive measurement source 2021 2023 cyber incidents
5.1 Number of relevant incident Number Annual Report 775 TBD responses to which ENISA contributed in accordance with the CSA Art. 7
5.2 Number of incidents analysed Number Annual OSINT report 775 or curated
5.3 Number of high visibility Number Annual Flash report 38 incidents analysed
5. 4 Number of large-scale cross- Number Annual Joint Rapid 13 border incidents with high impact Report analysed
5.5 Number of incidents to which Number Annual Cyber Assistance 1 ENISA contributed in response Mechanism
5.6 Timeliness and relevance of N/A Biennial Survey N/A Baseline to be information shared and expertise established provided by ENISA in relation in 2023 to incidents in which ENISA contributes efforts to mitigate
5.7 Take up of ENISA support Number Annual Report N/A Baseline to be services established in 2023
5.8 Number of trusted vendors Number Annual Report N/A Baseline to be established in 2023
5.9 Stakeholder satisfaction N/A Biennial Survey N/A Baseline to be with ENISA’s ability to provide established operational support in 2023
Resource forecast
Outputs Service A B C Total package (reserved for (reserved for other (reserved for ad related to tasks to maintain regular statutory hoc statutory category A statutory service) tasks) tasks)
FTE EUR FTE EUR FTE EUR FTE EUR 5.1 SITAW, INDEX 7.40 764,432 0.00 0 0.00 0 7.40 764,432 5.2 SITAW 1.4 97,701 0.00 0 1.40 97,701 5.3 SITAW 0.25 51,379 0.95 0 0.00 0 1.20 51,379
Activity total FTE: 10 Budget: 913,512
Work Programme 2023 ACTIVITY 6: Development and maintenance ofEUcybersecuritycertification framework Overview of activity
This activity emcompasses actions that seek to establish and support the EU cybersecurity certification framework by preparing and reviewing candidate cybersecurity certification schemes in accordance with Article 49 of the CSA, at the request of the Commission or on the basis of the Union's Rolling Work Programme. Actions also include maintaining and evaluating adopted cybersecurity certification schemes and participating in peer reviews. In addition in this activity, ENISA assists the Commission in providing the secretariat of the European Cybersecurity Certification Group (ECCG), co-chairing and providing the secretariat to the Stakeholder Cybersecurity Certification Group (SCCG). ENISA also makes available and maintains a dedicated European cybersecurity certification website according to Article 50 of the CSA. The activity leads the CERTI service package and contributes to the NIS service package. The legal basis for this activity is Article 8 and Title III Cybersecurity Certification Framework of the CSA.
Objectives
• Trusted ICT products, services and processes • Increase use and uptake of European cybersecurity certification • Efficient and effective implementation of the European cybersecurity certification framework • Improve the management of the security posture of certified products, services and processes by applying continuous compliance monitoring for high level assurance
Results Link to strategic objective (ENISA strategy)
• Certified ICT products, services and processes are preferred by consumers and businesses • High level of trust in secure digital solutions • Empowered and engaged communities across the cybersecurity ecosystem
Outputs Validation
6.1. Drafting and contributing to the preparation • Ad hoc working groups on certification and establishment of candidate cybersecurity (output 6.1 and 6.2.) certification schemes • ECCG (6.1.6.2, 6.3 and 6.4) 6.2. Implementing and maintaining established • European Commission (outputs 6.1, 6.2, 6.3, 6.4) schemes including the evaluation of adopted schemes, participation in peer reviews etc. • SCCG (output 6.3. and 6.4.)
6.3. Supporting statutory bodies in carrying out their duties with respect to governance roles and tasks 6.4. Developing and maintaining the necessary provisions and tools and services concerning the Union’s cybersecurity certification framework (including a certification website, supporting the Commission in relation to the core service platform of CEF (Connecting Europe Facility) for collaboration and publication, and promoting the implementation of the cybersecurity certification framework etc.
Stakeholders and levels of engagement
Partners Involve / Engage
EU Member States (including National Private sector stakeholders with an interest Cybersecurity Certification Authorities, ECCG), in cybersecurity certification, conformity European Commission, EU institutions, bodies and assessment bodies, national accreditation agencies, Selected stakeholders as represented in bodies consumer organisations the SCCG
Key performance indicators
1.UptakeoftheEuropeancybersecurity Unit of Frequency Data Results Target certificationframeworkandschemesas measurement source 2021 2023 an enabler for secure digital solutions
2.Effectivepreparationofcandidate certificationschemespreparedbyENISA
6.2 Stakeholders' level of trust in the digital Biennial Survey N/A Baseline to be solutions of certification schemes (citizens, established public sector and businesses). in 2023
6.3 Uptake of certified digital solutions Biennial Survey N/A Baseline to be (products, services and processes) using established certification schemes under the CSA in 2023 framework
Work Programme 2023
1.UptakeoftheEuropeancybersecurity Unit of Frequency Data Results Target certificationframeworkandschemesas measurement source 2021 2023 an enabler for secure digital solutions
2.Effectivepreparationofcandidate certificationschemespreparedbyENISA
6.4 Number of candidate certification Number Annual Report N/A Minimum 75% schemes prepared by ENISA of schemes formally requested to be under ongoing development
6.5 Number of people or organisations Number Annual Report N/A Minimum: 10 engaged in the preparation of certification organisations; schemes 10 individual experts; 50% of EU MSs joining an AHWG; 30% of organisations to be an SME; 5% to be from a third country
6.6 Satisfaction with ENISA’s support for the Biennial Survey N/A Baseline to be preparation of candidate schemes established in 2023
Resource forecast
Service A B C Outputs Total package (reserved for (reserved for other (reserved for ad hoc related to tasks to maintain regular statutory statutory tasks) category A statutory service) tasks)
FTE EUR FTE EUR FTE EUR FTE EUR
6.1 CERTI, NIS 4.65 565,936 0.70 945 0.00 0 5.35 566,881
6.2 CERTI 1.35 90,720 0.00 - 0.00 0 1.35 90,720
6.3 CERTI 1.05 0.00 0.00 0 1.05 –
6.4 CERTI 1.10 75,859 0.15 71,118 0.00 0 1.25 146,977
Activity total FTE: 9 Budget: 804,578
ACTIVITY 7: Supporting European cybersecurity market and industry Overview of activity
This activity seeks to foster the cybersecurity market for products and services in the European Union along with the development of the cybersecurity industry and services, in particular SMEs and start-ups, to reduce dependence on outside sources and increase the capacity of the Union and to reinforce supply chains to the benefit of the internal market. It involves actions to promote and implement ‘security by design’ and ‘security by default’ measures in ICT products, services and processes, including through standardisation. Actions to support this activity include producing analyses and guidelines as well as good practices on cybersecurity requirements, facilitating the establishment and take up of European and international standards across applicable areas such as risk management as well as performing regular analyses of cybersecurity market trends on both the demand and supply side including monitoring, collecting and identifying dependencies among ICT products, services and processes and vulnerabilities present therein. It also involves creating platforms for collaboration among the cybersecurity market players, in order to improve the visibility of trustworthy and secure ICT solutions in the internal digital market. In addition, this activity supports cybersecurity certification by monitoring official standards being used by European cybersecurity certification schemes and recommending appropriate technical specifications where such standards are not available. This activity contributes to the CERTI and NIS service packages. The legal basis for this activity is Article 8 and Title III Cybersecurity certification framework of the CSA.
Objectives
• Improve the conditions for the functioning of the internal market • Foster a robust European cybersecurity industry and market
Work Programme 2023 Results Link to strategic objective (ENISA strategy)
• Contributing towards an understanding of cybersecurity market dynamics • High level of trust in secure digital solutions • A more competitive European cybersecurity • Empowered and engaged communities across industry, SMEs and start-ups the cybersecurity ecosystem
Outputs Validation
7.1. Market analysis of the main trends in the • SCCG (outputs 7.2 & 7.3) cybersecurity market on both the demand • ENISA Advisory Group (output 7.1) and supply side, and evaluation of certified products, services and processes • NLO (as necessary) 7.2. Monitoring developments in related areas • ECCG (output 7.4) of standardisation, analysis of gaps in • Ad hoc working groups cybersecurity market standardisation and the establishment analysis (output 7.1) and take-up of European and international cybersecurity standards for risk management in relation to certification 7.3. Guidelines and good practices on cybersecurity for ICT products, services and processes and recommendations to the EC and the ECCC 7.4. Monitoring and documenting the dependencies and vulnerabilities of ICT products and services
Stakeholders and levels of engagement
Partners Involve / Engage
EU Member States (including entities with an Private sector stakeholders with an interest in interest in cybersecurity market monitoring e.g. cybersecurity market and/or standardisation, NCCA, National Standardisation Organisations), International Organisation for Standardisation European Commission, EU institutions, bodies / International Electrotechnical Committee, and agencies, European Standardisation consumer organisations Organisations (CEN, CENELEC, ETSI), Private sector or ad hoc standards setting organisations
Key performance indicators
Effectivenessof Unit of Frequency Data Results Target ENISA's supportingrolefor measurement source 2021 2023 participants in the European cybersecurity market
7.1. Number of market analyses, guidelines and good practices issued by ENISA Cybersecurity market analysis Number Annual Reports 2 1 framework 7.2. Uptake of lessons learned or % Annual Survey 49% 60% recommendations from ENISA reports (average of responses) 7.3. Stakeholder satisfaction with % Biennial Survey N/A Baseline to be the added value and quality of established ENISA’s work in 2023
Resource forecast
Outputs Service A B C Total package (reserved for (reserved for other (reserved for ad related to tasks to maintain regular statutory hoc statutory category A statutory service) tasks) tasks)
FTE EUR FTE EUR FTE EUR FTE EUR 7.1 CERTI, INDEX, 2.90 116,161 0.35 0 0.00 0 3.25 116,161 CERTI 7.2 CERTI, NIS 1.60 112,132 0.20 0 0.00 0 1.80 112,132 7.3 CERTI 0.50 73,017 0.00 0 0.00 0 0.50 73,017 7.4 CERTI 0.50 54,716 0.00 0 0.00 0 0.50 54,716
Activity total FTE: 6 Budget: 356,027
Work Programme 2023 ACTIVITY 8: Knowledge of emerging cybersecurity challenges and opportunities Overview of activity
This activity delivers on ENISA’s strategic objectives SO7 (efficient and effective management of cybersecurity knowledge for Europe) and supports SO6 (foresight on emerging and future cybersecurity challenges). In particular, work under this activity shall provide strategic long-term analyses, guidance and advice on emerging and future technologies, based on the results of regular cybersecurity foresight exercises. Typical examples may include artificial intelligence, quantum computing, space technology, etc Moreover, on the basis of risk management principles and the consolidation of information and knowledge the Agency will identify cyber threats, vulnerabilities and risks, and map threat landscapes and provides topic-specific as well as general assessments on the expected societal, legal, economic and regulatory impact, as well as targeted recommendations to Member States and the Union's institutions, bodies, offices and agencies. In doing so, the Agency will take into account work on incident reporting in accordance with relevant EU legislations. In this respect, the Agency will continue analysing and reporting on incidents as required by Art 5(6) of the CSA and will, upon request, support incident reporting and analysis in other legislative acts such as Art.10 of eIDAS Regulation, DORA, etc. In terms of the management of knowledge, ENISA will work towards consolidating data, information and knowledge concerning the status of cybersecurity across MSs and the EU and continue its effforts in developing and maintaining the EU cybersecurity index. The Agency will also continue its efforts to organise and make available to the public information on cybersecurity by means of a dedicated infohub that will cater for the needs of different stakeholders. These activities leverage the expertise on relevant legal, regulatory, economic and social trends and data by aggregating and analysing information. The strategic goal is to provide timely, reliable and useful information and knowledge (across the past-present-future timeline) to various target audiences in accordance with their needs and contribute to the improvement of the state of cybersecurity across the Union. This activity leads ENISA’s efforts towards delivering the cybersecurity index (INDEX) service package, while contributing in parallel to the delivery of the NIS, TREX and situational awareness (SITAW) service packages. The legal basis for this activity is Article 9 and Article 5(6) of the CSA.
Objectives
• Identify and understand emerging and future cybersecurity challenges and opportunities and assess the interlinks between cybersecurity and relevant disrupting technologies in current and future digital transformation • Increase the resilience and preparedness of Member States and the Union in handling future cybersecurity challenges and opportunities • Increase knowledge and information for specialised cybersecurity communities • Greater insight of the current state of cybersecurity across the Union
Results Link to strategic objective (ENISA strategy)
• Decisions about cybersecurity are future proof and take account of the trends, developments • Foresight on emerging and future cybersecurity and knowledge across the ecosystem challenges • MSs have the tools for assessing and • Efficient and effective management understanding their cybersecurity maturity of cybersecurity information and knowledge for Europe • Empowered and engaged communities across the cybersecurity ecosystem
Outputs Validation
8.1. Develop and maintain the EU cybersecurity • NLO Network (for Output 8.4 and 8.5, index and as necessary for other outputs) 8.2. Collect and analyse information to report on • ENISA Advisory Group (as necessary) the cyber threat landscapes • ENISA ad hoc working groups (for Outputs 8.1, 8.3. Analyse and report incidents as required by 8.2, 8.4 and 8.6 as necessary Art 5(6) of the CSA as well as other sectorial • CSIRT Network (output 8.1 and 8.2) legislation (e.g. DORA, eIDAS Art. 10, etc.) • Formally established bodies and expert groups as 8.4. Develop and maintain a portal (information necessary (output 8.3) hub), respectively identify appropriate tools for a one-stop-shop to organise and • NIS Directive Cooperation Group (output 8.1) make available to the public information on cybersecurity, and the establishment of a procedural framework to support knowledge management activities maximising synergies with the European Cybersecurity Atlas 8.5. Foresight on emerging and future cybersecurity challenges and recommendations. 8.6. Building and exchanging knowledge on ransomware threat (incl. capacity building and awareness raising and education)
Stakeholders and levels of engagement
Partners Involve / Engage
EU and national decision-making bodies Industry, research and academic institutions and authorities, ECASEC and Art. 19 Expert and bodies Group members
Work Programme 2023 Key performance indicators
ENISA’s abilitytocontributeto Unit of Frequency Data Results Target Europe’s cyberresiliencethrough measurement source 2021 2023 timelyandeffectiveinformationand knowledge including foresight on emerging and future challenges
8.1 Number of users and frequency of use of N/A a dedicated portal (observatory) 8.2. Number of recommendations, analyses Number Annual ENISA 288 300 and challenges identified and analysed reports and (reports) studies 8.3 Number of recommendations, analyses Number Biennial Survey N/A and challenges identified and analysed (reports) 8.4 The influence of foresight on the Number Annual SPD N/A Applicable development of ENISA's work programme as of 2023 8.5 Uptake of reports generated in activity 8 Number Annual Media N/A Applicable monitoring as of 2023 report 8.6 Uptake of the cybersecurity index Number Annual Index N/A Applicable platform as of 2023
Resource forecast
Outputs Service package A B C Total related to (reserved for (reserved for other (reserved for category A tasks to maintain regular statutory ad hoc statutory statutory service) tasks) tasks)
FTE EUR FTE EUR FTE EUR FTE EUR 8.1 INDEX 2.50 181,982 0.00 0.00 2.50 181,982 8.2 INDEX, SITAW, NIS 2.00 156,616 0.35 0.25 15,000 2.60 171,616 8.3 INDEX, SITAW, NIS 1.00 58,791 0.20 0.00 – 1.20 58,791 8.4 INDEX, TREX 1.00 152,235 0.00 0.00 – 1.00 152,235 8.5 INDEX 1.10 207,257 0.10 40,000 1.20 247,257 8.6
Activity total FTE: 8.50 Budget: 811,881
ACTIVITY 9: Outreach and education Overview of activity
This activity seeks to raise the overall awareness of cybersecurity risks and practices. In cooperation with Member States, Union institutions, bodies, offices and agencies and the EU’s international partners, it aims to build an empowered European community with an allied global community which can counter risks in line with the values of the Union. Under this activity the Agency will be organising regular outreach campaigns, providing guidance on best practices and supporting coordination across MSs on awareness and education. Moreover, the Agency will facilitate the exchange of best practices and information on cybersecurity in education between MSs. The added value of this activity comes from building communities of stakeholders which improve and enhance current practices in cybersecurity by harmonising and amplifying stakeholder actions. The activity will also seek to contribute to the Union's efforts to cooperate with third countries and international organisations on cybersecurity. This activity contributes to the NIS, CERTI and TREX service packages. The legal basis for this activity are Articles 10, 12 and 42 of the CSA.
Objectives
• Advance cyber-secure behaviour by essential service providers in critical sectors • Elevate the understanding of cybersecurity risks and practices across the EU and globally • Foster EU cybersecurity values and priorities • Increase the supply of skilled professionals to meet market demand, and promote cybersecurity education
Results Link to strategic objective (ENISA strategy)
• Greater understanding of cybersecurity risks and practices • High level of trust in secure digital solutions • Stronger European cybersecurity through higher • Empowered and engaged communities across global resilience the cybersecurity ecosystem
Work Programme 2023 Outputs Validation
9.1 Develop activities to enhance behavioural • Management Board (as necessary) change by essential service providers in critical • SCCG (for certification related issues sectors (as defined by the NISD) under output 9.2) 9.2 Promote cybersecurity topics, education and • NLO Network (as necessary) good practices on the basis of the strategy of ENISA's stakeholders • ENISA Advisory Group (outputs 9.1 and 9.2) 9.3 Implement ENISA's international strategy and • AHWG on cybersecurity skills (output 9.5) outreach 9.4 Organise European cybersecurity month (ECSM) and related activities 9.5 Report on needs and gaps in cybersecurity skills, and support skills development, maintenance and implementation (including the Digital Education Action Plan and a report on higher-education programmes) 9.6 Implement the Cybersecurity in Education roadmap
Stakeholders and levels of engagement
Partners Involve / Engage
ECSM Coordination Group, National Competent Authorities through the NIS Cooperation Group ENISA National Liaison Officers (NLOs), DG Work Streams, AHWG on Awareness Raising and CONNECT, NIS Operators of Essential services, Education, Enterprise Security AHWG (SMEs), European Cybersecurity Competence Centre, AHWG on Skills International partners (CISA, NIST etc)
Key performance indicators
Level of awareness of Unit of Frequency Data Results Target cybersecurity, cyber hygiene and measurement source 2021 2023 cyber literacy across the EU
Level of outreach
9.1 Number of cybersecurity Number Annual Report N/A Baseline to be incidents reported having human established in error as a root cause 2023
9.2 Number of activities and participation in awareness-raising actions organised by ENISA on cybersecurity topics
Social media impressions Average Annual Social media 20,756,630 20,000,000 number (Facebook, LinkedIn, Twitter)
Social media engagement Average Annual Social media 117,720 150,000 number (Facebook, LinkedIn, Twitter)
Video views Average Annual Social media 2,021,129 3,000,000 number (Facebook, LinkedIn, Twitter)
Website visits Average Annual ENISA website 123,504 150,000 number
Participation in events Average Annual Media 5 10 number monitoring
References Average Annual Website 40 50 number announcements
9.3 Number of cybersecurity programmes (courses) and participation rates (a)
Total number of students enrolled Number Annual Report 4,843 6,000 in the first year of academic programmes (2020)
Number of male students % Annual Report 80% 70%
Number of female students % Annual Report 20% 30%
Total number of cybersecurity Number Annual Report 119 130 programmes (2020)
30 https://www.enisa.europa.eu/publications/addressing-skills-shortage-and-gap-through-higher-education.
Work Programme 2023
Level of awareness of Unit of Frequency Data Results Target cybersecurity, cyber hygiene and measurement source 2021 2023 cyber literacy across the EU
Level of outreach
Number of postgraduate % Annual Report 6% 5% programmes Number of masters programmes % Annual Report 77% 80% Number of bachelors programmes % Annual Report 17% 15% 9.4 Geographical and community Number Annual Baseline to be coverage of outreach in the EU established in 2023 9.5 Level of awareness of Biennial N/A Baseline to be cybersecurity across the EU / general established public (e.g. EU barometer) in 2023
Resource forecast
Outputs Service A B C Total package (reserved for (reserved for other (reserved for related to tasks to maintain regular statutory ad hocstatutory category A statutory service) tasks) tasks)
FTE EUR FTE EUR FTE EUR FTE EUR 9.1 NIS 1.00 66,482 0.50 43,688 0.00 0.00 1.50 110,170 9.2 INDEX, CERTI 0.75 42,701 0.75 31,314 0.00 0.00 1.50 74,014 9.3 SITAW, TREX 0.75 – 0.75 26,544 0.00 0.00 1.50 26,544 9.4 TREX 0.10 – 0.90 95,147 0.00 0.00 1.00 95,147 * 9.5 INDEX, TREX 0.40 47,441 0.60 59,775 0.00 0.00 1.00 107,216 9.6 INDEX 0.20 38,059 0.80 38,059 0.00 0.00 1.00 76,117
Activity total FTE: 7.50 Budget: 489,209
31 Outputs 9.1 and 9.5 would be priority outputs for the consuming of any surplus budget in 2023.
ACTIVITY 10: Advise on research and innovation needs and priorities Overview of activity
This activity aims to provide advice to EU Member States (MSs), EU institutes, bodies and agencies (EUIBAs) on research needs and priorities in the field of cybersecurity, thereby contributing to the EU's strategic research and innovation agenda. To prepare this strategic advice, ENISA will take full account of past and ongoing research, activities in development and technology assessment, and scan the horizon for emerging and future technological, societal and economic trends that may have an impact on cybersecurity. ENISA will also conduct regular consultations with relevant user groups, projects (including EU funded projects), researchers, universities, institutes, industries, start-ups and digital innovation hubs to consolidate information and identify gaps, challenges and opportunities in research and innovation from the different quadrants of the community. This activity contributes to the delivery of ENISA NIS service package. The legal basis for this activity is Article 11 of the CSA.
Objectives
• Advance the response to current and emerging cyber risks and threats with the use of effective risk prevention technologies • Ensure that the EU strategic research and innovation agenda in cybersecurity is aligned with the needs and priorities of the community • Reduce dependence on cybersecurity products and services from outside the Union and to reinforce supply chains within the Union
Results Link to strategic objective (ENISA strategy)
• Research and development of cybersecurity technology reflecting the needs and priorities • Foresight on emerging and future cybersecurity of the Union challenges • Funding the development of cybersecurity • Empowered and engaged communities across technologies that meet the Union’s ambition the cybersecurity ecosystem to become more resilient, autonomous and competitive
Work Programme 2023 Outputs Validation
10.1 Consolidated cybersecurity research and • The European Cybersecurity innovation roadmap across the EU Competence Centre and Network of National Coordination Centres and 10.2 Collect and analyse information on new and Competence Centre Governing Board emerging information and communications (output 10.2 & 10.3) technologies in order to identify gaps, trends, opportunities and threats (research & • NLO as necessary innovation observatory) 10.3 Provide strategic advice to the EU agenda on cybersecurity research, innovation and deployment
Stakeholders and levels of engagement
Partners Involve / Engage
Member States (including the National Market actors – in particular the NIS sectors’ Coordination Centres), EU-IBAs (Including the EC, stakeholders (e.g. OES), academia and research ECCC and JRC) communities, cybersecurity industry as well as solution and service providers
Key performance indicators
ContributingtoEurope’s Strategic Unit of Frequency Data Results Target Research and Innovation Agenda in measurement source 2021 2023 thefieldofcybersecurity.
10.1 Number of requests from the EU- Number Annual Report N/A Baseline to be IBAs (including the ECCC) and MSs to established contribute, provide advice or participate in 2023 in activities
10.2 Number of references to ENISA Number Annual Report N/A Baseline to be advice and recommendations in the established EU Strategic Research and Innovation in 2023 Agenda including Annual and Multiannual Work programmes
10.3 Stakeholder satisfaction on the Biennial Survey N/A Baseline to be usefulness, relevance and timeliness established of ENISA’s advice on cybersecurity in 2023 research needs and funding priorities (Survey)
Resource forecast
Outputs Service A B C Total package (reserved for (reserved for other (reserved for ad hoc related to tasks to maintain regular statutory statutory tasks) category A statutory service) tasks)
FTE EUR FTE EUR FTE EUR FTE EUR 10.1 1 41,428 0.00 0 1 41,428 10.2 NIS 0.10 0 0.90 123,453 0.00 0 1 123,453 10.3 1.8 25,490 0.20 5,000 2 30,490
Activity total FTE: 4 Budget: 195,371
Work Programme 2023 CORPORATE ACTIVITIES
Activities 11 to 12 encompass enabling actions that support the operational activities of the agency.
ACTIVITY 11: Performance and risk management Overview of activity
This activity seeks to achieve the requirements set out in Art 4(1) of the CSA that sets an objective for the Agency to: 'be a centre of expertise on cybersecurity by virtue of its independence, the scientific and technical quality of the advice and assistance it delivers, the information it provides, the transparency of its operating procedures, the methods of operation, and its diligence in carrying out its tasks'. This objective requires an efficient performance and risk management framework, and the development of single administrative practices. It also includes building an internal capacity for contribution, e.g. via shared services, to the EU Agencies network and in key areas of the Agency’s expertise (e.g. cybersecurity risk management). Under this activity ENISA will confinue to enhance the key objectives of the renewed organisation, as described in the MB decision No MB/2020/5, including the need to address the gaps in the Agency’s quality assessment framework, enhance proper and functioning internal controls and compliance checks. In terms of resource management the budget management committee ensures the Agency adheres to sound financial management. The legal basis for this activity is Art 4(1) and Art 32 of the CSA, the latter of which focuses strongly on sound financial management principles with a view to maximising value to stakeholders.
Objectives
• Increased effectiveness and efficiency in achieving Agency objectives • Compliant with legal and financial frameworks in the performance of the Agency (build a culture of compliance) • Protect the Agency’s assets and reputation, while reducing risks • Full climate neutrality of all operations by 2030
Results Link to strategic objective (ENISA strategy)
• Maximise quality and value provided to stakeholders and citizens • Sound resource and risk management • Building lasting credibility and trust
Outputs Validation
11.1 Maintain the framework for performance • Management Team management including through single • Chairs of statutory bodies (Output 10.5) administrative practices across the Agency • Budget Management Committee 11.2 Develop and implement annual communications strategy • IT Management Committee 11.3 Develop and implement risk management • Intellectual Property Rights Management plans including cybersecurity risk assessment Committee for IT systems, including focus on quality • Staff Committee management framework and business processes as well as relevant policies • ENISA Ethics Committee
11.4 Maintain and monitor the implementation of Agency wide processes for IT management and develop processes for budgetary management 11.5 Manage and provide secretariats for statutory bodies (EB, MB, NLO and AG) 11.6 Obtain and maintain the EU Eco-Management and Audit Scheme (EMAS) certificate through continuous overview of the impact of CO2 on all operations of the Agency in line with the applicable legal framework and publish a statement on the environment
Stakeholders and levels of engagement
Partners Involve / Engage
Members of statutory bodies such All ENISA stakeholders as Management Board, Advisory Group and National Liaison Officers
Work Programme 2023 Key performance indicators
Organisational performance culture Unit of Frequency Data Results Target Trust in ENISA brand measurement source 2021 2023
11.1. Proportion of key performance % Annual Report N/A 65% indicators reaching targets
11.2. Individual staff contribution to % Annual Objectives 2021 60% 85% achieving the objectives of the agency via clear link to KPIs in staff career development report (CDR report) (all units aggregated)
11.3. Exceptions in the risk register Number Annual Internal control 16 11
Deviation from financial regulations Number Annual Internal control 14 10
Deviation from staff regulations Number Annual Internal control 2 1
11.4. Number of complaints filed Number Annual Report 19 12 against ENISA, including number of inquiries or complaints submitted to the European Ombudsman
11.5 Number of complaints Number Annual Internal control N/A Baseline to be addressed in a timely manner and files established according to relevant procedures in 2023
11.6 Number of high risks identified Number Annual Internal control N/A Baseline to be in annual risk assessment exercise files established in 2023
11.7 Implementation of risk Number Annual Report N/A Baseline to be treatment plans established in 2023
11.8 Number and types of activities Number Annual Report N/A Baseline to be at each level of engagement established in 2023
11.9. Observations from external Number Annual Report 4 2 audit bodies (e.g. European Court of Auditors ECoA) requiring followup actions by ENISA (i.e. number of ‘critical’, ‘significant’ or ‘very important’ findings and number of observations successfully completed and closed
11.10 Level of trust in ENISA Biennial Survey N/A Baseline to be established in 2023
Resource forecast
Outputs Service package A B C related to category (reserved for tasks to (reserved for other (reserved for ad hoc A maintain statutory regular statutory statutory tasks) service) tasks)
FTE EUR FTE EUR FTE EUR 11.1 All service packages 1 5.5 160,850 11.2 All service packages 2 2 304,000 11.3 All service packages 0.5 3 197,000 11.4 1.5 0 11.5 2 126,500 11.6 0.5 61,500
Activity total FTEs: 18 Budget: 849,000
Work Programme 2023 ACTIVITY 12: Staffdevelopmentandworking environment Overview of activity
This activity seeks to support ENISA's aspirations as stipulated in Art 3(4) which obliges the Agency to: develop its own resources, including /…/ human capabilities and skills, necessary to perform the tasks assigned to it under this Regulation. The actions which will be pursued under this activity will focus on making sure that the Agency’s HR resources fit the needs and objectives of ENISA, by attracting, retaining and developing talent and building ENISA’s reputation as an agile and knowledge-based organisation where staff can evolve personally and professionaly, where staff are kept engaged, motivated and have a sense of belonging. Emphasis will be placed on the development of competency and ways to make ENISA an ‘employer of choice’ in order to support ENISA’s objectives This activity will seek to build an attractive workspace by establishing an effective framework enabling teleworking outside the place of assignment, developing and maintaining excellent working conditions (premises, layout of office space) and implementing modern user-centric IT and teleconferencing tools delivering state-of-the-art corporate services and supporting ENISA's business owners and stakeholders in line with the Agency’s objectives. ENISA will strive to maximise the efficiency of its resources by maintaining its focus on developing a flexible, highly-skilled and fit-for-purpose workforce through strategic workforce planning in order to ensure the effective functioning of the Agency and to maintain high quality services in the administrative and operational areas. ENISA will further improve the support given to it in strategic planning and resource management, leading to a constant optimisation of resources under short- and long-range time-frames. This will enable ENISA to enhance its capabilities in future-readiness and continue its path towards an agile, knowledge-based and matrix way of working. The Agency will continue to look into flexible (50/50) working arrangements to better balance work requirements in a pragmatic manner. In parallel, ENISA will continue to enhance its secure operational environment to the highest level, and strive for excellence in its infrastructure services based on best practices and frameworks. It will also explore cloudenabled services that are fit for purpose and provide services in accordance with recognised standards. Besides that, ENISA will strive to promote and foster eco-system solutions, explore opportunities for shared services with other EU agencies, leverage standard technologies where possible and support flexible ways of working. As ENISA aspires to become a trusted partner it will continue to provide customer-focused multi-disciplinary teams that demonstrate a customer centric, can-do and agile attitude.
Objectives
• Engaged staff, committed and motivated to deliver, and empowered to fully use their talent, skills and competences • Consistent and regular reviews of the Agency’s resources to seek an appropriate match with the needs of the organisation, along with obtaining internal and external gains in efficiency across the organisation • Digitally enabled work-place environment (including home work-space) which promotes performance and balances social and environmental responsibility • Enable operations at the highest level of security • Build a culture of continuous improvement, agility, customer centred and can-do attitude
Results Link to strategic objective (ENISA strategy)
• ENISA as an employer of choice, enabling growth and excellence in a secure environment • Build an agile organisation focused on people
Outputs Validation
12.1 Manage and provide recurring quality • Management Board (Output 12.2) support services in the area of resources, 34 • Management Team security and infrastructure for ENISA staff, employees, corporate partners and visitors • IT Management Committee 12.2 Develop and implement the • Budget Management Committee Agency’s corporate strategy (including • Staff Committee HR strategy) with an emphasis on talent development and growth, innovation and inclusiveness; 12.3 Enhance operational excellence and digitalisation through modern, secure and streamlined ways of working and self-service functionalities 12.4 Provide a secure, safe, modern and welcoming place to work (and telework) including staff welfare 12.5 Establish standards for the provision of services and processes for optimising services
Stakeholders and levels of engagement
Partners Involve / Engage
ENISA staff members and EU institutions, bodies Private sector and international organisations and agencies
Work Programme 2023 Key performance indicators
Staffcommitment,motivation Unit of Frequency Data Results Target and satisfaction measurement source 2021 2023
12.1 . Staff satisfaction survey % Annual Staff satisfaction 72% 75% (including the attractiveness survey of ENISA as an employer, staff empowerment, organisational culture, opportunities for internal mobility, workspace, work environment and work tools)
12.2-. Quality of ENISA training % Annual Staff satisfaction 49% 55% and career development activities survey organised for staff
12.3. Reasons for staff departure Scale 1–10 As required HR files 7.1 7.5 (exit interviews)
12.4 Turnover rates % Annual HR files 3% 3%
12.5 Establishment plan posts filled % Annual HR files 91% 95%
12. 6. Resilience and quality of ENISA % Annual IT reports and 78% 80% IT systems and services staff satisfaction survey
12.7 Percentage of procurement % Annual Procurement > 80 % procedures launched via e-tool files (PPMT)
12.8 Percentage of payments made % Annual Finance files > 90% within 30 days
12.9 Late Payments % Annual Finance files <10%
Resource forecast
Outputs Service package A B C related to category (reserved for tasks (reserved for (reserved for A to maintain statutory other regular statutory ad hoc statutory tasks) service) tasks)
FTE EUR FTE EUR FTE EUR 12.1 9 2,138,000 12.2 3 383,000 12.3 1.5 964,000 12.4 1.5 832,000 12.5 2 100,000
Activity total FTEs: 17 Budget: 4,417,000
SECTION I. General context TP-AH-23-002-EN-N ABOUT ENISA The European Union Agency for Cybersecurity, ENISA, is the Union’s agency dedicated to achieving a high common level of cybersecurity across Europe. Established in 2004 and strengthened by the EU Cybersecurity Act, the European Union Agency for Cybersecurity contributes to EU cyber policy, enhances the trustworthiness of ICT products, services and processes with cybersecurity certifi cation schemes, cooperates with Member States and EU bodies, and helps Europe prepare for the cyber challenges of tomorrow. Through knowledge sharing, capacity building and awareness raising, the Agency works together with its key stakeholders to strengthen trust in the connected economy, to boost resilience of the Union’s infrastructure, and, ultimately, to keep Europe’s society and citizens digitally secure. More information about ENISA and its work can be found here: enisa.europa.eu. ENISA European Union Agency for Cybersecurity AthensOffice Agamemnonos 14 Chalandri 15231, Attiki, Greece HeraklionOffice 95 Nikolaou Plastira 700 13 Vassilika Vouton, Heraklion, Greece enisa.europa.eu ISBN 978-92-9204-630-9
Fotnoter
- ADOPTED SINGLE PROGRAMMING DOCUMENT 2023–2025 3
- ADOPTED SINGLE PROGRAMMING DOCUMENT 2023–2025 5
- ADOPTED SINGLE PROGRAMMING DOCUMENT 2023–2025 7
- 1 Policy initiatives such as the forthcoming Cyber Resilience Act and initiatives on Artificial Intelligence (AI), 5G, quantum computing, blockchain, big data, data spaces, digital resilience and response to current and future crises
- ADOPTED SINGLE PROGRAMMING DOCUMENT 2023–2025 9
- 4 Biennial surveys for each activity will be conducted in Q1 2023 for reference year 2022. Results will be recorded in annual activity report 2022 and single programming document 2024-2026.
- 5 The NIS2 covers a) critical operators such as telecoms and trust service providers, which were not covered by the NIS1 but by other legislation (EECC and eIDAS), b) sectors which were already covered by the NIS1 such as energy, finance, health and c) new sectors, such as space and public administration. 6 Such cross-cutting issues include namely security measures, technical aspect of cybersecurity, supply chain risk management, and vulnerability disclosure policies.
- ADOPTED SINGLE PROGRAMMING DOCUMENT 2023–2025 11
- 7 Including DORA, Electricity Code, privacy and eIDAS.
- ADOPTED SINGLE PROGRAMMING DOCUMENT 2023–2025 13
- 23 CSIRT training and Capture the Flag (CTF) and Attach Defence (AD) competitions.
- 8 (Including Cyber Europe, Blueprint operational level exercise (BlueOLEx), Cyber Exercise to test SOPs (CyberSOPEx etc) and through cyber ranges. NIS cooperation group exercise postponed due to resource constraints. 9 Output is supressed in 2023 work programme due to insufficient resources. 10 Would be priority output for the consideration of consuming any surplus budget in 2023. 11 In the context of this output ENISA is also preparing a few Service Levels Agreements with key EU Agencies with advanced requirements for capacity building activities (e.g. eu LISA).
- ADOPTED SINGLE PROGRAMMING DOCUMENT 2023–2025 15
- 12 Average number of improvements across all exercises. 13 Relates to 2022 exercises executed as of October 2022.
- 14 The % out of a total of 10 EU ISACs (as per NIS and NIS2). 15 Output to be suppressed in 2023 given resource constraints.
- ADOPTED SINGLE PROGRAMMING DOCUMENT 2023–2025 17
- 16 This is especially relevant for the year 2023 and onwards because the support contract procured by the Commission finishes by the end of 2022. 17 the Agency will prepare where possible for the future Emergency Response Fund, providing that ENISA will be asked to support it and without pre-empting the outcome of the legislative process.
- 18 CSIRTs Network, CyCLONe, SOCs network, potentially JCU.
- ADOPTED SINGLE PROGRAMMING DOCUMENT 2023–2025 19
- 19 CSIRTs Network, CyCLONe, SOCs network, potentially JCU.
- 20 The Agency will prepare where possible for the future Emergency Response Fund, provided ENISA will be asked to support it and without pre-empting the outcome of the legislative process.
- ADOPTED SINGLE PROGRAMMING DOCUMENT 2023–2025 21
- 21 Advisory group proposal for standby emergency incident analysis team provisioned within output 5.1.
- 22 As of October 2022 for the year 2022. 23 Structured cooperation with CERT-EU.
- ADOPTED SINGLE PROGRAMMING DOCUMENT 2023–2025 23
- ADOPTED SINGLE PROGRAMMING DOCUMENT 2023–2025 25
- 24 Number of schemes formally requested by the Commission or given the go ahead on the basis of the Union Rolling Work Programme, and the number of cybersecurity certification schemes under development by ENISA. 25 Numerical value from ENISA records on a per scheme basis to produce number of: organisations, individual experts, EU Member States, percentage of SMEs, percentage of third country organisations involved that support the promulgation of a cybersecurity certification scheme.
- ADOPTED SINGLE PROGRAMMING DOCUMENT 2023–2025 27
- ADOPTED SINGLE PROGRAMMING DOCUMENT 2023–2025 29
- ADOPTED SINGLE PROGRAMMING DOCUMENT 2023–2025 31
- 26 Output supressed during the 2023 work programme due to insufficient resources.
- 27 InfoHub is in the process of being developed. 28 Output suppressed in 2023 due to insufficient resources.
- ADOPTED SINGLE PROGRAMMING DOCUMENT 2023–2025 33
- 29 Roadmap developed by ENISA during the course of 2022.
- ADOPTED SINGLE PROGRAMMING DOCUMENT 2023–2025 35
- ADOPTED SINGLE PROGRAMMING DOCUMENT 2023–2025 37
- ADOPTED SINGLE PROGRAMMING DOCUMENT 2023–2025 39
- ADOPTED SINGLE PROGRAMMING DOCUMENT 2023–2025 41
- 32 Baselines were available as of the 2021 annual activity report therefore proportion of metrics reaching targets will be assessed in the 2022 annual activity report. 33 Relates to the stakeholder strategy and its implementation, refers to activities such as conferences, workshops etc.
- ADOPTED SINGLE PROGRAMMING DOCUMENT 2023–2025 43
- ADOPTED SINGLE PROGRAMMING DOCUMENT 2023–2025 45
- 34 Including full accreditation of the Agency to handle and manage EUCI by end of 2023 confirmed by DG Human Resources and Security.
- 35 Standardised set of ten questions with a scale of 1 to 10 that provide an opportunity for ENISA to seek feedback about a staff member’s experience. The higher the number the better the experience.
- ADOPTED SINGLE PROGRAMMING DOCUMENT 2023–2025 47
- 36 Indicated budget excludes staff (TA, CA, SNE) salaries and allowances.
- ADOPTED SINGLE PROGRAMMING DOCUMENT 2023–2025 3