Plans to create an EU Joint Cyber Unit to tackle growing cybersecurity concerns have been announced by the European Commission.
The task force will combine and coordinate resources and expertise from across the EU to prevent, deter and respond to mass cyberattacks. In addition, the unit will also assist affected states recover from the attacks.
To do so, it will provide member states’ various cybersecurity groups with a virtual and physical platform to help them co-operate. Participants will be asked to provide resources for mutual assistance.
According to a statement from the European Commission: “All relevant actors in the EU need to be prepared to respond collectively and exchange relevant information on a ‘need to share’, rather than only ‘need to know’, basis.”
The plan is currently for the EU Joint Cyber Unit to begin operating by 30 June 2022 before becoming fully established a year later, by 30 June 2023.
Funding will come from the European Commission via the Digital Europe Programme.
The move forms part of the EU Cybersecurity Strategy and the EU Security Union Strategy.
Included in these plans are the need to establish and mobilise EU Cybersecurity Rapid Reaction Teams, along with facilitating the adoption of protocols for mutual assistance among participants. The strategies also call for creating national and cross-border monitoring and detection capabilities, along with Security Operation Centres.
European Commission High Representative of the Union for Foreign Affairs and Security Policy Josep Borrell said: “The Joint Cyber Unit is a very important step for Europe to protect its governments, citizens and businesses from global cyber threats. When it comes to cyberattacks, we are all vulnerable and that is why cooperation at all levels is crucial.
“There is no big or small. We need to defend ourselves but we also need to serve as a beacon for others in promoting a global, open, stable and secure cyberspace.”
Earlier this month at a NATO meeting, UK Prime Minister Boris Johnson emphasised the importance of shared security, including cybersecurity, to the post-pandemic recovery.
Recommended
- What are the wider implications of ransomware payments?
- Under-resourced UK councils reporting over 700 data breaches
- Misplaced tech devices could be putting UK Gov data at risk
The move comes amid a rise in cybercrime, both in terms of the number of attacks being perpetrated and their severity. According to one report, 2020 saw a rise of 485% in ransomware attacks around the world.
Meanwhile, major incidents like the SolarWinds and Microsoft Exchange breaches demonstrate how one breach can affect numerous organisations, while the Colonial Pipeline attack shows the effects an attack can have on society as a whole.
And closer to home, the Scottish Environmental Protection Agency (SEPA) was knocked offline by a ransomware attack at the start of this year. Recently, Ireland’s Health Service Executive had to shut down its computer systems due to a ransomware attack.
European Commission Vice-President Margaritis Schinas said: “The recent ransomware attacks should serve as a warning that we must protect ourselves against threats that could undermine our security and our European Way of Life.
“Today, we can no longer distinguish between online and offline threats. We need to pool all our resources to defeat cyber risks and enhance our operational capacity. Building a trusted and secure digital world, based on our values, requires commitment from all, including law enforcement.”
The trend has prompted governmental action outside of Europe. In May, US President Joe Biden issued an executive order to improve the country’s cybersecurity. Amongst its provisions, the order calls for a software bill of materials (SBOM), essentially a list of ingredients for a program, to help federal agencies to identify potential vulnerabilities.
In addition, it aims to define security standards and create Cybersecurity Safety Review Board.





