Crisis Management Frameworks
Crisis management is defined as ‘an institutional and organisational design process’, a ‘[broad] structure [that] encompasses decision-makers [with specific roles and actions]’. In general terms, crisis management is understood as ‘making and effecting difficult decisions under difficult circumstances. With NIS2, MS have to develop a specific framework for cyber crisis management – including processes for business continuity and disaster recovery, designate or establish one or more competent authorities responsible for the management of large-scale cybersecurity incidents and crises (cyber crisis management authorities). Member States shall ensure that those authorities have adequate resources to carry out, in an effective and efficient manner, the tasks assigned to them. Member States shall ensure coherence with the existing frameworks for general national crisis management
However, because cyber crises tend to have a transboundary nature, any cyber crisis management framework must remain part of an overarching crisis management for overall coherence. This overarching crisis management framework is an integral part of the cybersecurity strategy and it set the structures for preparing, responding and recovering from major incidents that involve critical infrastructure.
In addition, MS should organise regular exercises and crisis management simulations as part of their preparedness processes to respond to large-scale cyber crisis, often including of cross-border nature.
Organising Exercises and Simulations: National cybersecurity strategies should incorporate regular cybersecurity exercises to test emergency plans, identify vulnerabilities, and improve sector cooperation. These exercises foster resilience by simulating real-world threats, from cyber-attacks to natural disasters, and ensure that national response teams can effectively coordinate across sectors and borders.