On Wednesday 6 December, to Committee of Permanent Representatives to the EU (Coreper) approved an action plan for the implementation of the European cyber security strategy. This action plan calls on the Council to look at possibilities for setting up an emergency fund to help member state victims of cyber-attacks. It will be on the agenda of the General Affairs Council on 11-12 December.
It should be recalled that the Commission presented a joint communication mid-September entitled, “Resilience, Deterrence and Defence: Building strong cybersecurity for the EU” (see EUROPE 11865). This suggested enhancing EU resilience against cyber-attacks and increasing the EU’s cyber security capacity by creating an effective response at a criminal justice level and stepping up international cyber security cooperation. It was the subject of the conclusions of heads of state and government on 19 October (see EUROPE 11891), as well as the conclusions by the Ministers for European Affairs on 20 November (see EUROPE 11908).
The action plan presented today to Coreper represents, “A vehicle for the control and horizontal follow-up of the implementation of the Council conclusions”. It takes the shape of a continually changing graph that will be regularly reviewed and updated by the Council.
In practice, it will be based around the 10 key ideas inspired by the European Commission strategy (implementation of the directive on network security, the adoption and implementation of the regulation on the cyber security agency, etc.). In view of stepping up the fight against crime and eliminating the obstacles to effective criminal justice, the action plan calls on Europol to develop a road map by the beginning 2018 as a means of checking the criminality developing on the dark web and developing and validating an emergency response protocol for large-scale attacks. It is calling on the Commission to present a legislative proposal by the beginning of 2018 on the cross-border access to e-evidence and to launch by the middle of 2019, a platform that will enable member states to exchange online and in total security, European investigation request formulas and e-evidence. Another example: in view of creating a Network Centre for Cyber-security Competencies (NCCC) and a European Research and Cybersecurity Competencies Centre, the document calls on the Commission to carry out an impact study before June 2018 into the area, as well as a budgetary forecast and to forecast the necessary legal instruments. It also demands that the member states develop a framework for assessing encryption benefits for single digital market products and services. The action plan can be seen at the following page: http://bit.ly/2AdvgXg. (Original version in French by Sophie Petitjean)