Cybersecurity: New level of cooperation
On March 5, 2024, an agreement was reached between the European Parliament and the European Council on a draft Cybersecurity7 Solidarity Act :
Из выпуска мониторинга No. 3, March 2024 · выпуск целиком, PDF · на сайте Института Гайдара

The EU experience
On March 5, 2024, an agreement was reached between the European Parliament and the European Council on a draft Cybersecurity1 Solidarity Act :
1) A pan-European infrastructure of Security Centers - the European Cyber Shield. Consists of national and cross-border cyber centers, and will use AI, among other things, to identify cyber threats and provide real-time information to individuals.
2) An emergency cybersecurity mechanism to respond to cyber incidents. Will operate in 3 areas:
а) Coordination of testing in critical sectors, including health care and energy. б) EU cybersecurity reserve of trusted providers ready to intervene in case of cyber incidents. в) Financial support for mutual assistance.
3) European cybersecurity incident management mechanism.
On March 20, 2024, the European Commission and the U.S. announced initiative to analyze cyber incident reporting to better align transatlantic approaches in 6 areas . The goal is to respond to cross-border cyber incidents and reduce reporting costs for multinational companies.
The ASEAN experience
In February 2024, Singapore's Cybersecurity Agency announced a collaboration with ASEAN member states to establish a Regional Computer Emergency2 Response Team.
The experience of Russia and
BRICS
In Russia, the Law on Critical Infrastructure Security provides for a system for detecting, preventing and eliminating the consequences of computer attacks on information resources, and a National Computer Incident Coordination Center has been established. The Center exchanges information on computer incidents between “subjects of critical information infrastructure and authorized bodies of foreign states, international, international non-governmental organizations and foreign organizations engaged in activities in the field of response to computer incidents. However, there is no information about such interaction with the EAEU and BRICS countries.
- EU - for gatekeepers with annual sales of €7.5 bn or more, 45 mn consumers per month and 10,000 business users per year; US - for platforms with sales of $550 bn, 50 mn consumers and 100,000 business users per month. In China, the size of platforms is not taken into account. 8,9 ↑
- https://ec.europa.eu/commission/presscorner/detail/en/IP_24_1332. ↑
- https://digital-strategy.ec.europa.eu/en/news/dhs-and-dg-connect-announce-initiative-comparing-cyber-incident-reporting-better-align. ↑
- 1) Definitions and reporting thresholds, 2) timelines, triggers and types of cyber incident reporting, 3) reports content, 4) reporting mechanisms, 5) aggregation of incident data and 6) public disclosure of cyber incident information. ↑
- https://www.csa.gov.sg/News-Events/Press-Releases/2024/singapore-moves-ahead-to-establish-the-asean-regional-cert-to-strengthen-regional-cybersecurity. ↑
- Explanatory memorandum on the updated OECD definition of an AI system. OECD artificial intelligence papers no. 8. March 2024;. ↑
From the monitoring issue No. 3, March 2024. Download the full issue (PDF) · issue page at the Gaidar Institute