Research and Development (R&D) and Innovation
Research and development in cyber security is needed in order to develop new tools for deterring, protecting, detecting, and adapting to and against new kinds of cyber-attacks. NIS2 mandates MS in supporting academic and research institutions to develop, enhance and promote the deployment of cybersecurity tools and secure network infrastructure.
In addition, Member States should encourage the use of any innovative technology, including artificial intelligence and post quantum cryptography, the use of which could improve the detection and prevention of cyberattacks, enabling resources to be diverted towards cyberattacks more effectively. Member States should therefore encourage in their national cybersecurity strategy activities in research and development to facilitate the use of such technologies, in particular those relating to automated or semi-automated tools in cybersecurity, and, where relevant, the sharing of data needed for training users of such technology and for improving it. The use of any innovative technology, including artificial intelligence, post quantum cryptography, etc., should comply with Union data protection law, including the data protection principles of data accuracy, data minimisation, fairness and transparency, and data security, such as state-of-the-art encryption. The requirements of data protection by design and by default laid down in Regulation (EU) 2016/679 should be fully exploited.