A typology of cybersecurity and public-private partnerships in the context of the EU

  1. One should, however, that there are alternative framings of technical IT security and problems with the general label of “cyber”, which will be briefly taken up below.

  2. In contrast to informal working arrangements for security and intelligence agencies

  3. For instance, or

  4. At the time of writing, the legislative proposal had gained political agreement from all EU institutions, but was not formally concluded yet. See:

  5. Information and computer scientist tend to prefer other more technical and precise concepts, such as information security, which is composed of definable attributes of integrity, availability and confidentiality. Security scholars, in contrast, have highlighted the dangers of “securitizing” the digital communications or simply just ‘cyber’ and merging distinct issues of cybercrime, cyber-assisted crime with more state-centred notion of security, which can legitimate “offensive” methods and the involvement of the military.

  6. Again, we cannot go into the question whether cyberspace is a suitably precise analytical concept. For a widely cited official definition, see

  7. For instance, See also Farrand and Carrapico in this issue for a more detailed discussion on the historical development from public to private management of critical infrastructures.

  8. An especially controversial response to this challenge has been to create separate market incentives through programs such as ‘bug bounties.’

  9. Such as “hate” speech, weapons instructions, child sexual abuse material, etc.

  10. These functionally differentiated tasks or processes have been inductively derived by the authors from the diverse social science literature on cybersecurity referred above. For reasons of space this differentiation cannot be systematically related to wider theories of public (economic) regulation and security governance here, but this may prove a worthwhile research agenda for the future. On the one hand, one could test whether the proposed tasks are truly exhaustive and comprehensive in the area of cybersecurity. On the other hand, more elaborate formal reasoning on collective action dynamics, such as with regard to the public good qualities of information or reliable access, could be explored beyond the cursory remarks made below.

  11. If one applies a broad or multi-level understanding of cybersecurity, this can range from questions of rights management, privacy and data protection to secure communication protocol standards or product safety and security.



  14. This point can be unlined by the fact that PPPs for a more secure internet provision at the infrastructural level have not yet been funded in Europe, as illustrated by the failed idea of a “Schengen-net” for secure data transfers in Europe.

  15. The typological fields are referred to in the respective subheadings of the different sections

  16. ENISA has organised several annual major ICT incident exercises for EU member states that were triggered official EU conclusions in the aftermath of the 2009 Estonian cyber-attacks. Assessments of these exercises are limited to official document, where the large number of participants (500+) and positive resonance had highlighted

  17. See

  18. See also Art. 3 of the EU regulation establishing ENISA (revised 526/2013)






  24. This has been modelled on a corresponding US Forum with global reach.



  27. ENISA, 2012a. European Public + Private Partnership for Resilience. Activity Report 2012. Available at:

  28. Compare also for an incomplete survey of information-sharing platforms across EU member states

  29. This would hitherto be limited to some cases that are covered by the 2009 EU telecommunications regulation (Directive 2009/140/EC). See

  30. Public authorities from 18 member state are taking part, while the rest is constituted by academic institutions or experts See full list of members

  31. See Especially the second working group provide the most detailed recommendations on how to differentiate, improve and link up the variety of information-sharing initiatives for CIIP, see


  33. Or computer security incident response teams in alternative European parlance (CSIRT), see


  35. For instance, one could point to frameworks for data sharing or best practice collection, see




  39. p-15







  46. Barclays, ING Group, Citibank, the European Banking Federation, and the association for ATM Security (EAST). See and and










    See on the joint EUROPOL INTERPOL MoU

    And conference





  60. This particular action even seems to have involved the British signals intelligence service GCHQ

  61. Austria, France, Germany, Italy, Spain, the Netherlands and the UK



  64. EU DOC 6785/16, p. 35









