ENISA, the EU Agency for Cybersecurity, has published a study on ‘Best Practices for Cyber Crisis Management’ that assists in preparation for crisis management for a wide-area cyber attack in the EU. The study was conducted for the EU Cyber Crisis Liaison Organisation Network (CyCLONe).
The study highlights the complexities behind the notion of cyber crisis in the EU area and the degree of subjectivity it involves. ‘The elevation of a large-scale cyber incident into a cyber crisis relies predominantly on a political decision, and depends largely on the level of risk that EU Member States are prepared to tolerate (i.e. ‘risk appetite’)’ states the study. A cyber crisis is managed at the strategic, operational and technical levels, and involves a variety of actors at the organizational, corporate, sectoral, regional, national and EU levels.
A structure for managing a cyber crisis
The best practices proposed in the study for managing a wide-area cyber crisis are set out in ‘the four phases of the cyber crisis management cycle’. These are prevention, preparedness, response, and recovery.
The items included in each aspect of the cyber crisis management framework are:
Prevention
- Adoption of a national definition of ‘cyber crisis’, taking into account its transboundary dimension.
- Development of information security standards specific to the national public sector, to be reviewed and updated regularly.
- Foster national initiatives which promote the creation of prevention programmes.
Preparedness
- Definition of a governance structure, provision of specific capabilities and appointment of a crisis coordinator.
- Mapping and gathering information on critical entities and their most critical assets to enable rapid action.
- Establishing instantaneous, secured communication channels during a crisis.
- Formalisation of a clear allocation of roles between the parties involved in responding to a cyber crisis in an overall plan.
- Development of escalation criteria for activating the cyber crisis plan and deploying the relevant cooperation units/groups, taking into account factors such as time, priority, players involved, severity of the attack, etc.
- Development of a methodology and risk assessment tools to optimise coordination and interoperability in the event of a crisis.
- Testing of the overall plan for operations in response to cyber crises through a multiannual programme of cyber crisis management exercises and training sessions.
- Setting up training sessions for current and future staff responsible for cyber crisis management at the operational level.
- Development of a communication strategy including a clear format for messaging, stakeholders to involve, priority levels and time factor and communication channels to be used.
Response
- Encourage the mobilisation of private-sector certified ‘trusted providers’ to provide technical assistance to victims.
- Supporting victims’ crisis communication, for instance with a unified and transparent message.
Recovery
- Develop and implement business resumption plans (BRP) defined in reference frameworks, with regular reviewing and updates, in consultation with relevant stakeholders.
- Establishment of a unit tasked with gathering feedback, drawing lessons learnt and producing recommendations for reviewing, updating and modifying procedures and infrastructure, and refining the action plan for cyber crisis management.






