The European Union’s efforts to tackle the phenomenon of ransomware attacks (Part I) – Lexology
1. Introduction
As the transition to a digital society is accelerating in recent years, especially after the coronavirus outbreak, the expectations of the European Citizens for a safer digital environment are growing. There is then an urgent need to combat cybercrime. In two different articles we will address, in particular, the surging phenomenon of the ransomware attacks and how this issue is being tackled within the European Union. In this contribution we will introduce the relevant phenomenon (Chapter 2). In addition, it will be assessed what are the legislative and policy frameworks in place in the European Union for facing this issue (Chapter 3).
2. The ransomware attacks
Ransomware can be described as a type of malware (like viruses, trojans, etc.) that infect the computer systems of users and manipulates the infected system in a way, that the victim cannot (partially or fully) use it and the data stored on it. The victim usually shortly after receives a blackmail note by pop-up, pressing the victim to pay a ransom (hence the name) to regain full access to system and files 1.
The criminality resorts to different types of tactics to achieve their finalities. Ransomware attacks have the primary goal of making monetary gains by way of unlawful means. Ransomware typically encrypts target files and displays notifications, requesting payment before the data can be unlocked. Ransomware demands are usually in the form of virtual currency, such as bitcoin. This because these types of payments are difficult to be tracked2.
Ransomware attacks have certainly a global impact.
A report issued on 2021 has revealed that the frequency and the complexity of ransomware attacks increased (by more than 150% in 2020 such that ransomware can now be defined as one of the greatest threats that organizations face today regardless of the sector to which they belong 3.
The above findings speak volumes on how this issue is serious and of concern for all the world. Consequently, it does not come as a surprise that it has been clearly recognized nowadays that ransomware is a prime item in agendas for meetings on strategy among global leaders 4.
In the fight against ransomware, several challenges need to be addressed. One of the main issues results in the lack of coordination and collaboration between the agencies and the authorities all over the world. There is indeed a lack of legislation in many countries that clearly criminalises ransomware attacks5.
This problem holds true also for the European Union given that: (i) it is made of different Member States which, in some cases, have different internal law frameworks when it comes to cybersecurity and modalities to tackle the ransomware problem; (ii) the issue must be addressed also with reference to the States which are external to the European Union (in which the ransomware phenomenon flourishes).
3. How the European Union is dealing with the issue
Considering all the above, in the following chapter we will look at how the European Union is trying to face the ransomware attacks.
3.1. The European Union legislative interventions
The first step towards the creation and development of an EU cybersecurity ecosystem was the adoption of a cybersecurity strategy in 20136. This strategy identified the achievement of cyber-resilience and the development of industrial and technological resources for cybersecurity as its key objectives. As part of this strategy, the European Commission proposed the EU Network and Information Security directive 2016/1148 (NIS Directive)7.
In particular, the NIS Directive8 sets out that the EU Member States must have certain national cybersecurity capabilities and that there shall be a cooperation in the exchange of information amongst the same EU countries. Moreover, according to the NIS Directive, the EU Member States shall promote a culture of security across sectors very relevant for the EU and which rely on ICTs such as energy, transport, water, banking, financial market infrastructures, healthcare and digital infrastructure 9.
It is interesting to note that the NIS Directive limited to provide for measures by way of which the EU States shall increase their attention when it comes to cyber-attacks. On the other hand, it did not envisage a common and specific framework (for example in terms of sanctions to be applied) for tackling cyber-crimes (such as the ransomware attacks).
That is probably why in June 2017, the EU tried to reinforce its global response to the cyber-attacks (including ransomware) by establishing a Framework for a Joint EU Diplomatic Response to Malicious Cyber Activities (the so called Cyber Diplomacy Toolbox)10.
This framework basically allows the EU and its Member States (by way of an initiative to be taken by the Council) to use all necessary measures ... to prevent, discourage, deter and respond to malicious cyber activities [and thus also to the ransomware attacks] targeting the integrity and security of the EU and its member states .... In particular, the Cyber Diplomacy Toolbox gives the possibility to the Council to impose ... sanctions on persons or entities that are responsible for cyber-attacks or attempted cyber-attacks, who provide financial, technical or material support for such attacks or who are involved in other ways ... 11.
Finally, also in the attempt to reinforce the attack to the malicious cyber activities (such as the ransomware) a revised version of the NIS Directive (to be named NIS2 Directive) has been proposed by the European Commission in 2020. In particular12:
The proposed NIS2 Directive though is now still under discussion13.
3.2. The European Union policy interventions
The European Union has then dealt with the issue of the ransomware attacks also pursuing specific policies of international cooperation on this topic.
In particular, the European Union has soon realized that this problem was global and that it was thus necessary to tackle it also involving the other stakeholders.
That is why the European Union signed for example a joint EU-U.S. statement for working together in the fight against ransomware through law enforcement action, raising public awareness on how to protect networks as well as the risk of paying the criminals responsible, and to encourage those states that turn a blind eye to this crime to arrest and extradite or effectively prosecute criminals on their territory ...14.
Moreover, the EU takes part on a regular basis in international summits (together with important partners such as U.S.A., India and Australia) where it is discussed how to counter this plague on a global scale15.
4. Conclusions
As we have seen above, the current framework set by the European Union to tackle the ransomware attacks is rather complex and worthy to be carefully assessed.
In a subsequent article to be published soon on Lexology, reference will then be made to the main actors in charge of dealing with such phenomenon in Europe and to the strengths and weaknesses of the current EU system of defence against this invasive form of cyber-criminality.
Read more:
The European Union's efforts to tackle the phenomenon of ransomware attacks (Part I) - Lexology
- Poland Assumes the Presidency of the Council of the European Union - Kyiv Post - January 6th, 2025 [January 6th, 2025]
- Far From Ignorant: The European Union, Arms Exports and Israel - CounterPunch - January 3rd, 2025 [January 3rd, 2025]
- Major changes in the European Union - summary of 2024: everything you need to know in 2025 - Visit Ukraine - January 3rd, 2025 [January 3rd, 2025]
- Hungary's controversial presidency of the Council of the European Union comes to an end - Euronews - January 1st, 2025 [January 1st, 2025]
- 30 years together: Austria, Finland and Sweden in the EU - European Union - January 1st, 2025 [January 1st, 2025]
- AI and Employee Data Protection in the European Union: 8 Key Takeaways for Multinational Businesses - JD Supra - January 1st, 2025 [January 1st, 2025]
- Pro-European Union Protests in Georgia Continue into New Years Eve - AL24 News - January 1st, 2025 [January 1st, 2025]
- 2025, between the reformist drive and the structural challenges of the European Union - The Diplomat in Spain - January 1st, 2025 [January 1st, 2025]
- Statement on behalf of the European Union and its Member States by H.E. Ambassador Stavros Lambrinidis, Delegation of the European Union to the United... - December 30th, 2024 [December 30th, 2024]
- European Union to resume Association Council meetings with Israel - The Times of Israel - December 18th, 2024 [December 18th, 2024]
- Its time for the European Union to rethink personal social networking - Bruegel - December 18th, 2024 [December 18th, 2024]
- Mistral 3 project to receive 60 million from European Union - MBDA - December 18th, 2024 [December 18th, 2024]
- The European Union and Palestinian Authority convene Investment Platform and announce EUR 28.3 million of investments for the Palestine Financial... - December 18th, 2024 [December 18th, 2024]
- The EVERY Company Further Expands its IP Estate with European Union Patent for Recombinant Ovalbumin - Business Wire - December 18th, 2024 [December 18th, 2024]
- European Union sanctions 26 individuals and two entities in Belarus - euneighbourseast.eu - December 18th, 2024 [December 18th, 2024]
- European Union: What do CG&R companies need to know about the European Accessibility Act? - GlobalComplianceNews - December 18th, 2024 [December 18th, 2024]
- New EU norms to reduce environmental impact of smitheries and foundries - European Union - December 14th, 2024 [December 14th, 2024]
- Syria: Statement by the High Representative on behalf of the European Union on the fall of the Assad regime - consilium.europa.eu - December 10th, 2024 [December 10th, 2024]
- European Union and the Gates Foundation to co-host Gavi 6.0 High Level Pledging Summit - Bill & Melinda Gates Foundation - December 10th, 2024 [December 10th, 2024]
- European Union orders TikTok to preserve data related to Romanian election - The Associated Press - December 10th, 2024 [December 10th, 2024]
- European Union - United Republic of Tanzania: Joint Communique of the 2024 Partnership Dialogue - EEAS - December 10th, 2024 [December 10th, 2024]
- Human Rights Day: Statement by the High Representative on behalf of the European Union - consilium.europa.eu - December 10th, 2024 [December 10th, 2024]
- We are waiting to return home - helping refugees in Sudan - European Union - December 10th, 2024 [December 10th, 2024]
- Revised Regulation on Classification, Labelling and Packaging of Chemicals enters into force - European Union - December 10th, 2024 [December 10th, 2024]
- CCS legal framework for the development of carbon capture and storage technologies in Poland and the European Union - Dentons - December 10th, 2024 [December 10th, 2024]
- Mercosur and the European Union sign trade agreement - Fresh Fruit Portal - December 10th, 2024 [December 10th, 2024]
- European Union To Spend Over $4 Million And 3 Years To Create Report On European Animation Industry - Cartoon Brew - December 4th, 2024 [December 4th, 2024]
- Speech by President von der Leyen at the European Parliament Plenary on the new College of Commissioners and its programme - European Union - December 4th, 2024 [December 4th, 2024]
- ASSEMBLY | EU bishops reflect on Europes future and challenges of the new institutional cycle - The Catholic Church in the European Union - December 4th, 2024 [December 4th, 2024]
- Georgia suspends talks on joining the European Union and accuses the bloc of blackmail - The Associated Press - November 30th, 2024 [November 30th, 2024]
- An update on political advertising in the European Union - The Keyword - November 30th, 2024 [November 30th, 2024]
- Protesters met with force in Georgia following suspension of talks on European Union accession - Civil Rights Defenders - November 30th, 2024 [November 30th, 2024]
- European Union Food Week is Coming to Hyundai Food Market - EEAS - November 30th, 2024 [November 30th, 2024]
- The European Union and International IDEA organised a study visit to Kenya for the National Assembly Gender Committee and the CSO Gender Platform -... - November 30th, 2024 [November 30th, 2024]
- Malawi and the European Union hold Partnership Dialogue - EEAS - November 30th, 2024 [November 30th, 2024]
- Georgia suspends talks on joining the European Union and accuses the bloc of blackmail - News-Press Now - November 30th, 2024 [November 30th, 2024]
- If you're traveling outside the United States this Christmas, you'll have to meet a new requirement to enter the European Union - it's now official -... - November 14th, 2024 [November 14th, 2024]
- What the European Union should expect from Trumps tariffs - Bruegel - November 14th, 2024 [November 14th, 2024]
- Ten countries hope to join the European Union. Here is their formal status - Reuters - November 5th, 2024 [November 5th, 2024]
- What Does an European Union Investigation Mean for Temu? - The Fashion Law - November 5th, 2024 [November 5th, 2024]
- Joint Statement by the European Commission and High Representative Josep Borrell on the second round of Presidential Elections in Moldova - European... - November 5th, 2024 [November 5th, 2024]
- Spanish fugitive deported to European Union country: NIA - Focus Taiwan - October 21st, 2024 [October 21st, 2024]
- Trump says Tim Cook called him to complain about the European Union - The Verge - October 21st, 2024 [October 21st, 2024]
- Joint Press Release : First Partnership Dialogue between the Republic of Seychelles and the European Union - EEAS - October 21st, 2024 [October 21st, 2024]
- European Union member States must shield the International Criminal Court from critical threats - FIDH - October 21st, 2024 [October 21st, 2024]
- Can the European Union get it together on capital markets? This is whats at stake - World Economic Forum - October 21st, 2024 [October 21st, 2024]
- Migration And Asylum Offshoring Top Of European Union Council Agenda - Forbes - October 21st, 2024 [October 21st, 2024]
- Intrigue is unfolding in Moldova around the referendum on joining the European Union - Eurasia Daily - October 21st, 2024 [October 21st, 2024]
- The European Union as a strong actor at the 57th session of the Human Rights Council - EEAS - October 21st, 2024 [October 21st, 2024]
- Meta to European Union: Your Tech Rules Threaten to Squelch the AI Boom - The Wall Street Journal - September 19th, 2024 [September 19th, 2024]
- European Union Considers Suspending Visa Free Travel for Georgia After October 16 Elections Amid Political Tensions and Strained Relations - Travel... - September 19th, 2024 [September 19th, 2024]
- Teva faces European Union antitrust fine over shenanigans to thwart rivals - The Times of Israel - September 12th, 2024 [September 12th, 2024]
- Auditors say European Union is likely exaggerating green spending - The Hindu - September 12th, 2024 [September 12th, 2024]
- China's Wang Wentao to discuss the high European Union tariffs on electric cars next week - HT Auto - September 12th, 2024 [September 12th, 2024]
- Travel Update- Schengen Travelers To Experience A New Era As European Union will begin automated stamping for passports - Travel And Tour World - August 25th, 2024 [August 25th, 2024]
- The Largest Standing Armies of the European Union - Worldatlas.com - August 25th, 2024 [August 25th, 2024]
- China questions, begins probe of European Union subsidies for dairy industry exports - Voice of America - VOA News - August 25th, 2024 [August 25th, 2024]
- Von der Leyen, Costa and Kallas have been approved for EU top jobs. Who are they? What do they do? - KELOLAND.com - June 27th, 2024 [June 27th, 2024]
- Von der Leyen, Costa and Kallas have been approved for EU top jobs. Who are they? What do they do? - WRIC ABC 8News - June 27th, 2024 [June 27th, 2024]
- Apple Intelligence Features Not Coming to European Union at Launch Due to DMA - MacRumors - June 27th, 2024 [June 27th, 2024]
- European Union leaders set to endorse Von der Leyen, Costa and Kallas for the bloc's top jobs | Daily Independent - Daily Independent - June 27th, 2024 [June 27th, 2024]
- European Union leaders agree on top officials who will be the face of world's largest trading bloc - Citrus County Chronicle - June 27th, 2024 [June 27th, 2024]
- Not All Tariffs Are the Same: The Core Differences between U.S. and EU Tariffs against Chinese EVs - CSIS | Center for Strategic and International... - June 27th, 2024 [June 27th, 2024]
- Seeking Safety in Cyprus, They're Stuck in Island's U.N. Buffer Zone - The New York Times - June 12th, 2024 [June 12th, 2024]
- What to Know About Europe's Extra Tariffs on Chinese Electric Cars - The New York Times - June 12th, 2024 [June 12th, 2024]
- The EU slaps additional tariffs on Chinese EV imports - The Verge - June 12th, 2024 [June 12th, 2024]
- Battered by Far Right in E.U. Vote, Macron Calls for New Elections in France - The New York Times - June 12th, 2024 [June 12th, 2024]
- Chinese EV makers face additional tariffs of up to 38 percent in the EU - Engadget - June 12th, 2024 [June 12th, 2024]
- Poland exit polls: PM Tusk keeps upper hand over PiS in EU elections - Euronews - June 12th, 2024 [June 12th, 2024]
- The European Union mobilises additional assistance to support Ukraine - European Union - June 12th, 2024 [June 12th, 2024]
- Far-right parties make stunning gains in EU election, prompting Macron to call snap vote in France - Fortune - June 12th, 2024 [June 12th, 2024]
- EU's Borrell: Rafah offensive will cause civilian casualties, no matter what Israel says - The Times of Israel - May 7th, 2024 [May 7th, 2024]
- Who would run the EU if decided by Eurovision? - POLITICO Europe - May 7th, 2024 [May 7th, 2024]
- Opinion | Europe Is About to Drown in the River of the Radical Right - The New York Times - May 7th, 2024 [May 7th, 2024]
- Poland's Tusk Calls on EU to Build Joint Air-Defense System - Yahoo! Voices - May 7th, 2024 [May 7th, 2024]
- Xi visits Europe amid growing tensions with the West - Courthouse News Service - May 7th, 2024 [May 7th, 2024]
- Netherlands joins call to shetler intercepted asylum seekers in non-EU countries: report - NL Times - May 7th, 2024 [May 7th, 2024]
- More civilians will be killed in Israel's Rafah offensive 'whatever they say' - EU's Borrell - The Jerusalem Post - May 7th, 2024 [May 7th, 2024]
- Lawyer: EU taxpayers might have to pay billions for Russian billionaire's unjustified inclusion on a sanctions list - bnn-news.com - May 7th, 2024 [May 7th, 2024]
- EU urged to have fair perception of China - China Daily - May 7th, 2024 [May 7th, 2024]