Now on Demand Ransomware Resilience & Recovery Summit - All Sessions Available
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Management & Strategy

ENISA Calls for Cyber Crisis Management Framework

ENISA Calls for Action on Cyber Crisis Management

European Union cybersecurity agency ENISA has urged decision makers in the EU to take action and create a cyber crisis management framework before a major incident occurs.

ENISA Calls for Action on Cyber Crisis Management

European Union cybersecurity agency ENISA has urged decision makers in the EU to take action and create a cyber crisis management framework before a major incident occurs.

Based on lessons learned from the aviation, civil protection, border control, counter-terrorism, and health and disease control sectors, ENISA has compiled a set of recommendations for efficient cooperation and management measures that would lessen the impact of a cyber crisis.

According to the agency, there is a lack of consistency in the EU when it comes to cyber incident response, particularly crisis situations. Until now, only the 2007 cyberattacks that hit Estonia have been classified as a cyber crisis, and while the incident has led to some measures being taken in the EU, ENISA believes a proper cyber crisis management framework needs to be established.

One of the main challenges is related to the fact that the severity of a crisis is usually established based on the severity of its impact. However, ENISA pointed out that a major cyber incident could lead to a crisis in the energy, telecommunications and industrial sectors, which is why, unlike in the case of a “traditional” crisis, not only the impact has to be mitigated, but the cause as well.

Experts believe EU member states and the European Commission should review current legislation to better reflect the distinction between cause and effect, and leverage developments in cyber crisis management for mitigating crises caused by cyber incidents.

ENISA has also advised member states to develop and adopt an EU-level cyber crisis management plan, and cyber standard operating procedures (SOPs).

The European Commission and EU members should also establish a pool of experts tasked with exchanging information and best practices. Finally, ENISA recommends funding the design and development of a cyber crisis cooperation platform.

Advertisement. Scroll to continue reading.

“The message we try to pass with this study is that the effective mitigation of any type of crisis caused by cyber incidents does not only depend on the mitigation of the impacts of that crisis,” said Udo Helmbrecht, executive director of ENISA. “It depends also very much on the effective mitigation of the cyber incidents which caused it. Today, EU decision-makers are in the privileged position to take action before such a cyber crisis occurs; this study offers insight into what can be done.”

ENISA’s complete report on cyber crisis management is available for download in PDF format. The agency has also published a video with testimonials from experts in other sectors:

Related: Joint UK-US Exercise to Test Nuclear Infrastructure Against ‘Major’ Cyber Attack

Related: ENISA Launches Car Security Group

Written By

Eduard Kovacs (@EduardKovacs) is a managing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Bill Dunnion has joined telecommunications giant Mitel as Chief Information Security Officer.

MSSP Dataprise has appointed Nima Khamooshi as Vice President of Cybersecurity.

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

More People On The Move

Expert Insights

Related Content

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

CISO Strategy

SecurityWeek spoke with more than 300 cybersecurity experts to see what is bubbling beneath the surface, and examine how those evolving threats will present...

CISO Conversations

Joanna Burkey, CISO at HP, and Kevin Cross, CISO at Dell, discuss how the role of a CISO is different for a multinational corporation...

CISO Conversations

In this issue of CISO Conversations we talk to two CISOs about solving the CISO/CIO conflict by combining the roles under one person.

CISO Strategy

Security professionals understand the need for resilience in their company’s security posture, but often fail to build their own psychological resilience to stress.

Management & Strategy

SecurityWeek examines how a layoff-induced influx of experienced professionals into the job seeker market is affecting or might affect, the skills gap and recruitment...

Cybersecurity Funding

2022 Cybersecurity Year in Review: Top news headlines and trends that impacted the security ecosystem