From Cyber Security Incident Management to Cyber Security Crisis Management in the European Union

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Ruohonen, Jukka, Rindell, Kalle, Busetti, Simone
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915534354776064
author Ruohonen, Jukka
Rindell, Kalle
Busetti, Simone
author_facet Ruohonen, Jukka
Rindell, Kalle
Busetti, Simone
contents Incident management is a classical topic in cyber security. Recently, the European Union (EU) has started to consider also the relation between cyber security incidents and cyber security crises. These considerations and preparations, including those specified in the EU's new cyber security laws, constitute the paper's topic. According to an analysis of the laws and associated policy documents, (i) cyber security crises are equated in the EU to large-scale cyber security incidents that either exceed a handling capacity of a single member state or affect at least two member states. For this and other purposes, (ii) the new laws substantially increase mandatory reporting about cyber security incidents, including but not limited to the large-scale incidents. Despite the laws and new governance bodies established by them, however, (iii) the working of actual cyber security crisis management remains unclear particularly at the EU-level. With these policy research results, the paper advances the domain of cyber security incident management research by elaborating how European law perceives cyber security crises and their relation to cyber security incidents, paving the way for many relevant further research topics with practical relevance, whether theoretical, conceptual, or empirical.
format Preprint
id arxiv_https___arxiv_org_abs_2504_14220
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle From Cyber Security Incident Management to Cyber Security Crisis Management in the European Union
Ruohonen, Jukka
Rindell, Kalle
Busetti, Simone
Cryptography and Security
Computers and Society
Incident management is a classical topic in cyber security. Recently, the European Union (EU) has started to consider also the relation between cyber security incidents and cyber security crises. These considerations and preparations, including those specified in the EU's new cyber security laws, constitute the paper's topic. According to an analysis of the laws and associated policy documents, (i) cyber security crises are equated in the EU to large-scale cyber security incidents that either exceed a handling capacity of a single member state or affect at least two member states. For this and other purposes, (ii) the new laws substantially increase mandatory reporting about cyber security incidents, including but not limited to the large-scale incidents. Despite the laws and new governance bodies established by them, however, (iii) the working of actual cyber security crisis management remains unclear particularly at the EU-level. With these policy research results, the paper advances the domain of cyber security incident management research by elaborating how European law perceives cyber security crises and their relation to cyber security incidents, paving the way for many relevant further research topics with practical relevance, whether theoretical, conceptual, or empirical.
title From Cyber Security Incident Management to Cyber Security Crisis Management in the European Union
topic Cryptography and Security
Computers and Society
url https://arxiv.org/abs/2504.14220