In order to strengthen the European Union’s solidarity and abilities to detect, prepare for and respond to cybersecurity threats and incidents, representatives of the Member States (Coreper) reached a common position on the so-called cyber solidarity act. The draft regulation sets out the Union’s capabilities to make Europe more resilient and reactive to cyber threats, whilestrengthening cooperation mechanisms.

The main objectives of the Commission’s proposal are:
- To support detection and awareness of significant or large-scale cybersecurity threats and incidents.
- To strengthen threat preparedness and protect critical entities and essential services, such as hospitals and public utilities.
- To boost solidarity at the EU level, concerted crisis management and response capabilities among Member States.
- To help ensure a secure digital landscape for both citizens and businesses.
With the aim of identifying major cyber threats quickly and effectively, the draft regulation establishes a European cyber shield, which is a pan-European infrastructure consisting of national and cross-border security operations centres across the Union. They are entities in charge of sharing information to detect cyber threats and take action.
This draft also envisages the creation of a cyber emergency mechanism to increase incident preparedness in the EU and improve response capabilities. It is planned to support:
- Preparedness actions, such as testing entities in highly critical sectors (healthcare, transport, energy, etc.) to detect potential vulnerabilities based on common risk scenarios and methodologies.
- Incident response services from trusted private sector providers pre-contracted and therefore ready to intervene, at the request of a Member State or EU institutions, bodies and agencies, in the event of a major or large-scale problem resulting from a cybersecurity incident.
- Mutual assistance in financial terms, where one member state could offer support to another.
Lastly, the proposed regulation establishes the cybersecurity incident review mechanism with the aim of improving EU resilience by reviewing and assessing significant or large-scale incidents after they have taken place, drawing lessons learned and, where appropriate, giving out recommendations to improve the EU’s cyber stance. At the request of the Commission or national authorities, the European Union Agency for Cybersecurity (ENISA) would review selected incidents and deliver a report with lessons learned and necessary recommendations.
Throughout the text, the voluntary nature of the involvement of the Member States in the mechanisms established by the Commission’s proposal has been emphasised and the interactions between the existing entities and those defined by the draft regulation have been clarified.
The agreement on the Council’s common position will allow the incoming presidency to open negotiations with the European Parliament on the final version of the proposed legislation.
The total budget for all the Union’s cyber solidarity actions amounts to €1.1 billion, of which approximately two thirds will be financed by the EU through the digital Europe Program.
_____
Aquest apunt en català / Esta entrada en español / Post en français








