Sittings · Document
On the proposal for a regulation of the European Parliament and of the Council on Measures to strengthen solidarity and capacities in the Union to detect, prepare for and respond to cybersecurity threats and incidents
Committee on Transport and Tourism · Rapporteur: Gheorghe Falcă
PA_Legam
SHORT JUSTIFICATION
Organizations affected by cyberattacks, including in the transport sector, rarely report them, especially private sector companies, since they tend to see them as ‘bad publicity’. Most organizations prefer to deal with them internally and it is often the attackers who publicize them. In the EU, the good news is that the entry into force of Directive 2022/2555 on network security (known as the ‘NIS2 Directive’), which Member States have until October 2024 to transpose, harmonises the incident reporting obligations across the Member States. Therefore, a better understanding of the nature and scale of the problem is likely to emerge in coming years.
The European Union Agency for Cybersecurity (ENISA) published a recent report that provides information on cybersecurity threats in the transport sector, where it emphasizes that cybercriminals were responsible for more than half of the incidents observed in the 2022 reporting period (55%) and that the leading motivation behind these attacks was financial gain. It also notes that most cyber-attacks in the transport sector target IT systems, causing operational disruptions.
As regards preparedness and response to cybersecurity incidents, there is currently limited support at Union level and solidarity between Member States. The Council Conclusions of May 2022 highlighted the need to address these gaps, by calling for the Commission to present a proposal on a new Emergency Response Fund for Cybersecurity.
This Regulation implements the EU Cybersecurity Strategy adopted in December 2020 that announced the creation of a European Cyber Shield, reinforcing the cyber threat detection and information sharing capabilities in the European Union through a federation of national and cross-border Security Operations Centres (SOCs). The actions of this Regulation will be supported by funding under ‘Cybersecurity’ Strategic Objective of DEP (Digital Europe Programme).
The total budget includes an increase of EUR 100 million that this Regulation proposes to re-allocate from other strategic objectives of DEP. This will bring the new total amount available for cybersecurity actions under DEP to EUR 842.8 million.
Part of the additional EUR 100 million will reinforce the budget managed by the European Cybersecurity Competence Centre (ECCC) to implement actions on SOCs and preparedness as part of their work programme(s). Moreover, the additional funding will serve to support the establishment of the EU Cybersecurity Reserve. It complements the budget already foreseen for similar actions in the main DEP and Cybersecurity DEP Work Programme for the 2023-2027 period which could boost the total amount to 551 million for 2023-2027, while 115 million were dedicated already in the form of pilots for 2021-2022. Including Member States contributions, the overall budget could amount up to 1.109 billion euros.
Rapporteur’s position
Your rapporteur welcomes the new proposal and believes that it will offer significant benefits to the various stakeholders. The rapporteur underlines the necessity for a deeper understanding of the cybersecurity needs and requirements of transportation, as well as for providing transport critical entities with access to proper funding for preparedness, response and solving incidents.
Your rapporteur endorses the ‘transport cybersecurity toolkit’, which aims at contributing to greater levels of cyber-awareness and cyber-hygiene, with a specific focus on the transport sector. It addresses transport organisations, regardless of their size and domain of activity, as well as taking into account transport critical infrastructure and military mobility, particularly having regards the war in Ukraine, especially but not limited to:
Air carriers, airport managing bodies, core airports, air traffic management and air traffic control centres, the European Union Aviation Safety Agency and Eurocontrol;
Infrastructure managers, railway undertakings and the European Rail Traffic Management System (ERTMS);
Inland, sea and coastal passenger and freight water transport companies, managing bodies of ports, including their port facilities, entities operating works and equipment contained within ports, operators of vessel traffic services;
Road authorities responsible for traffic management control, operators of Intelligent Transport Systems;
Postal and courier services.
Your Rapporteur believes that the size of the budget for the functioning of the Emergency Response Fund for Cybersecurity (ERFC) will determine its success; therefore, it should be sufficiently large to support Member States in preparing for, responding to and recovering from significant and large-scale cybersecurity incidents. Support for incident response shall also be made available to institutions, bodies, offices and agencies of the Union.
The European Cyber Shield will improve the cyber threat detection capabilities of the Member States. The Cyber Emergency Mechanism will complement Member States’ actions through emergency support for preparedness, response and immediate recovery/restoration of the functioning of essential services.