Trusted information-sharing mechanisms

ENISA is supporting the EU Member States since 2012 to develop, implement and evaluate their National Cyber Security Strategies (NCSS). Since 2017, all EU Member States have published their own NCSS.

Trusted information-sharing mechanisms

Information-sharing among private and public stakeholders is a powerful mechanism to better understand a constantly changing environment. Information-sharing is a form of strategic partnership among key public and private stakeholders. Owners of critical infrastructures could potentially exchange information with public authorities on mitigating emerging risks, threats, and vulnerabilities while public stakeholders could provide on a 'need to know basis’ information on aspects related to the status of national security, including findings based on information collected by intelligence and cyber-crime units. Combining both views give a very powerful insight on how the threat landscape evolves. In this sense, Information Sharing and Analysis Centers (ISACs) and public-private partnership (PPPs) can be an effective tool, to pool expertise and resources of the private and public sector. In addition, as part of their national strategy, Member States shall also include relevant procedures and appropriate information-sharing tools to support voluntary cybersecurity information sharing between entities in accordance with Union law.

Austria flag
Austria
Belgium flag
Belgium
Bulgaria flag
Bulgaria
Croatia flag
Croatia
Cyprus flag
Cyprus
Czech Republic flag
Czech Republic
Denmark flag
Denmark
Estonia flag
Estonia
Finland flag
Finland
France flag
France
Germany flag
Germany
Greece flag
Greece
Hungary flag
Hungary
Iceland flag
Iceland
Ireland flag
Ireland
Italy flag
Italy
Latvia flag
Latvia
Liechtenstein flag
Liechtenstein
Lithuania flag
Lithuania
Luxembourg flag
Luxembourg
Malta flag
Malta
Netherlands flag
Netherlands
Norway flag
Norway
Poland flag
Poland
Portugal flag
Portugal
Romania flag
Romania
Slovakia flag
Slovakia
Slovenia flag
Slovenia
Spain flag
Spain
Sweden flag
Sweden
Switzerland flag
Switzerland
Croatia flag
Croatia

PiXi - national platform for collecting, analysing and sharing cyber threat & incident data: Croatia's national information-sharing and incident-reporting platform, established under Art. 43 of the Cybersecurity Act (NN 14/24), the Cybersecurity Regulation (NN 135/24) and the DORA implementation law (NN 136/24). Developed and run by CARNET, PiXi is the single national entry point through which essential/important entities, DORA obligors, competent authorities, CSIRTs and the single point of contact exchange data on cyber threats and incidents and meet their statutory reporting duties. It is a closed, trusted system accessed only by authorised persons via the national NIAS e-authentication system (high/substantial credentials) and e-Authorisations. 

Sources: https://www.carnet.hr/usluga/pixi-platforma/ 
https://www.carnet.hr/en/usluga/pixi-platforma/ 

Voluntary cybersecurity information-sharing mechanism: A voluntary cyber-protection mechanism established by the Cybersecurity Act allowing entities not categorised as essential/important to voluntarily share information on cyber threats and incidents and conduct self-assessments, feeding the national picture and strengthening collective resilience. Non-categorised entities wishing to take part register with NCSC-HR, which then provides instructions for secure data transfer. Part of the Act's broader set of voluntary mechanisms alongside coordinated vulnerability disclosure and the SK@UT detection community. 

Sources: https://ncsc.hr/hr/smjernice-i-upute 
https://ncsc.hr/en/nis2-transposition 
https://ncsc.hr/UserDocsImages/ostalo/Cybersecurity_Act.pdf?vel=1434556 

Denmark flag
Denmark

FSOR: Operational resilience collaboration: Denmark's National Bank has taken the initiative to establish the Financial Sector forum for Operational Resilience, abbreviated FSOR. The FSOR is a public-private collaboration forum in the financial sector, and its objective is to enhance operational resilience across the sector, including resilience to cyberattacks.

Sources: https://www.nationalbanken.dk/en/what-we-do/stable-financial-system/cyber-resilience/fsor-operational-resilience-collaboration
https://www.nationalbanken.dk/da/vores-arbejde/stabilt-finansielt-system/cyberrobusthed/fsor-samarbejde-om-operationel-robusthed

SektorCERT: SektorCERT is the cybersecurity centre for Danish critical infrastructure sectors. It supports participating organisations through cyber threat intelligence sharing, threat assessments, cyber incident information exchange and a large-scale sensor network.

Sources: https://sektorcert.dk/

Hungary flag
Hungary

National Cyber Security Centre of Hungary (NCSC HU) threat-information dissemination

The operational channel through which the national CSIRT shares cyber threat information with government bodies, regulated entities and the public. The National Cyber Security Centre of Hungary (NCSC HU)publishes security warnings, threat notices, a continuously updated critical/high CVE vulnerability feed, weekly press digests drawing on incidents it handled and on data from the distributed government IT trap system (GovProbe1), APT threat-actor analyses, and a public Cyber Threatmap. Through membership of the EU CSIRTs Network it also exchanges threat information with international CSIRT partners and CERT-EU.

Sources: https://nki.gov.hu/
https://en.nki.gov.hu/

Statutory voluntary cybersecurity information-sharing mechanism

The legal basis for trusted inter-entity information sharing, transposing NIS2 Art. 29 into the Cybersecurity Act (Act LXIX of 2024). It enables entities within the Act's scope - and, where relevant, entities outside it - to exchange relevant cybersecurity information (cyber threats, near misses, vulnerabilities, indicators of compromise, tactics, alerts) on a voluntary basis within trusted communities, to prevent, detect and respond to incidents and raise the collective level of cybersecurity. Essential and important entities must notify the national cybersecurity authority when they join or leave such an arrangement.

Sources: https://nki.gov.hu/hatosag/tartalom/jogszabalyok/
https://njt.jog.gov.hu/jogszabaly/en/2024-69-00-00

Netherlands flag
Netherlands

NCSC-NL national information and expertise hub: NCSC-NL produces validated threat information and distributes it through recognised national channels, including its website and MijnNCSC. In practice, Central coordination helps organisations receive authoritative guidance that is relevant to their role and exposure. This national information function supports the more interactive exchange that takes place through ISACs and the National Detection Network. 

Source: https://www.ncsc.nl/over-ons/versterkt-ncsc 

Sectoral Information Sharing and Analysis Centres (ISACs): Sectoral ISACs provide trusted forums in which organisations from the same sector exchange information on threats, incidents and mitigation measures. Confidentiality rules encourage participants to share sensitive operational experience, while NCSC-NL links the communities to national authorities. 

Source: https://www.ncsc.nl/samenwerken/wat-is-een-isac 

National Detection Network (Nationaal Detectie Netwerk, NDN): The National Detection Network allows participating organisations and NCSC-NL to exchange technical detection information, including indicators of compromise. Participants can then use the shared data in their own monitoring systems and coordinate mitigation when related activity is detected. 

Source: https://www.ncsc.nl/over-ons/versterkt-ncsc 

Cyclotron: Cyclotron is a trusted public-private cyber security collaboration in the Netherlands where participating organisations share real-time threat intelligence to detect cyber threats faster, spot attack patterns earlier, and coordinate responses more effectively. It is designed for mature cyber security teams that already collect and analyse threat data, want to collaborate with other expert organisations, and value being part of a trusted intelligence-sharing network. 

Source: https://www.ncsc.nl/en/services/cyclotron 

Cyber Resilience Network (CWN): The CWN is a national collaboration framework that brings together public and private organisations to strengthen collective cyber resilience. It provides a structured way for participants to share threat information, coordinate responses to cyber incidents, exchange expertise, and develop cyber security knowledge and skills. 

Source:  ttps://www.ncsc.nl/nieuws/cyberweerbaarheidsnetwerk-bouwplan-voor-stevigere-basis-van-cyberweerbaarheid-het-koninkrijk-der