Information Sharing in a Network of Trust

EU Commission Public Consultations

EE-ISAC Position on | The EU Cybersecurity Act

The EE-ISAC welcomes the revision of the EU Cybersecurity Act as an important opportunity to strengthen the Unions cyber resilience in response to growing geopolitical tensions, increasingly sophisticated cyber threats, and vulnerabilities in ICT supply chains. As a central information-sharing platform for the European energy sector, the EE-ISAC emphasises that the revised framework should prioritise timely and effective operational information exchange to enable critical infrastructure operators to assess risks and implement appropriate mitigation measures.

EE-ISAC Position on | Draft Commission guidance on the Cyber Resilience Act

The European Energy Information Sharing and Analysis Centre (EE-ISAC) welcomes the opportunity to contribute to the European Commissions guidance on the implementation of Regulation (EU) 2024/2847, stressing that the effectiveness of the Cyber Resilience Act (CRA) depends on its alignment with the operational realities of critical energy infrastructure.

EE-ISAC Position on | Simplification – digital package and omnibus (Response for Call of Evidence)

The European Energy Information Sharing and Analysis Centre (EE-ISAC) welcomes the European Commissions Digital Package and the Digital Omnibus initiative, which aim to simplify the EUs digital regulatory framework while maintaining strong cybersecurity and data protection standards. For the energy sector, this initiative is particularly important because operators currently face a complex landscape of overlapping regulations, including the NIS2 Directive, Cyber Resilience Act (CRA), Cybersecurity Act, GDPR, AI Act, CER Directive, and the Network Code on Cybersecurity.

EE-ISAC Position on | Cybersecurity – terms & conditions for delaying the notification of incidents (delegated act)

EE-ISAC welcomes the European Commissions consultation on the Delegated Act defining the conditions under which national CSIRTs may temporarily delay the sharing of vulnerability notifications with other Member States. As the EU strengthens its cyber resilience, it is essential that new rules reflect the operational realities of critical infrastructure operators, particularly in the energy sector. Premature disclosure of sensitive information can increase systemic risk, while excessive delays can hinder coordinated defence.

EE-ISAC Position on | EU energy security framework (revision)

The European Energy Information Sharing and Analysis Centre (EE-ISAC) welcomes the European Commissions initiative to revise the EU Energy Security Framework as a crucial step toward a resilient, future-proof European energy system.

EE-ISAC Position on | The  European grid package

The European Energy Information Sharing and Analysis Centre (EE-ISAC) welcomes the European Commissions initiative to modernise and strengthen the EUs electricity infrastructure through the European Grid Package. The call for evidence demonstrates a forward-looking vision that recognises the growing interdependencies between digitalisation, resilience, and cross-border energy integration.

EE-ISAC Position on | The first stage of The Digital Networks Act

The European Energy Information Sharing and Analysis Centre (EE-ISAC) welcomes the European Commissions initiative to develop a unified Digital Networks Act (DNA). EE-ISAC recognises the DNAs potential to modernise Europes digital infrastructure through harmonisation, resilience measures, and regulatory simplification, while ensuring alignment with sectoral needs such as energy systems security and operational continuity.

EE-ISAC Position on | The revision of the EU Cybersecurity Act

The European Energy Information Sharing and Analysis Centre (EE-ISAC) welcomes the opportunity to contribute to the European Commissions consultation on the revision of Regulation (EU) 2019/881 (the Cybersecurity Act). EE-ISAC is a trust-based, industry-driven information-sharing network that brings together stakeholders from the energy sector, academia, public authorities, and cybersecurity providers to enhance the cyber resilience of Europes energy critical infrastructure.

EE-ISAC Position on | EU electricity supply – sector-specific rules on cybersecurity (network code)

The European Energy – Information Sharing and Analysis Centre (EE-ISAC) welcomes the opportunity to submit its feedback to the European Commission legislative proposal Network Code on Cybersecurity (NCCS), Regulation (EU) 2019/943, aimed at developing sector-specific rules (network code) that address the cybersecurity aspects of cross-border electricity flows. This will help make the EUs electricity system more resilient and secure.

EE-ISAC Position on | Feedback Submission to the European Commission Proposal: Cyber Solidarity Act

The European Energy – Information Sharing and Analysis Centre (EE-ISAC) welcomes the opportunity to submit its feedback to the European Commission legislative proposal “Cyber Solidarity Act” (CSA) aimed at enhancing cybersecurity and improving cyber resiliency in the Union.

EE-ISAC Position on | Proposal for a Directive on measures for a high common level
of cybersecurity across the Union, repealing Directive (EU) 2016/1148

The European Energy – Information Sharing and Analysis Centre (EE-ISAC) welcomes the
opportunity to set out its position and submit its comments to the European Commission on the
new legislative proposal for the NIS Directive, issued on 16 December 2020, for what concerns
information-sharing on threats and incidents in the energy sector, with the objective of
strengthening the security of the network and information system within the scope of the new
EU Cybersecurity Strategy.

EE-ISAC Position on | Proposal for a Directive on the resilience of critical
entities

The European Energy – Information Sharing and Analysis Centre (EE-ISAC) welcomes the
opportunity to set out its position and submit its comments to the European Commission on the
new legislative proposal for the Directive on the resilience of critical entities (CER), issued on 16
December 2020, for what concerns information-sharing on threats and incidents for the energy
sector, with the objective of strengthening the security of the digital and physical world within
the scope of the new EU Cybersecurity Strategy.

Publications

EE-ISAC Practical Cybersecurity Solution for the Energy Sector

A recent survey of cybersecurity assessment methods proposed by the scientific community revealed that their practical adoption constitutes a great challenge. Further research that aimed at identifying the reasons for that situation demonstrated that several factors influence the applicability, including the documentation level of detail, the availability of supporting tools, and the continuity of support. This paper presents the European Energy Information Sharing and Analysis Centre (EE-ISAC)—a cybersecurity platform for the energy sector that has been adopted by multiple organisations. The platform facilitates sharing information about cybersecurity incidents, countermeasures, and assessment results. Prospectively, it is envisaged to be integrated with the threat intelligence platform that enables real-time situational awareness. By considering both fault and attack scenarios together, threat awareness can be mapped onto operational contexts to prioritise decisions and responses. This paper analyses EE-ISAC’s approach based on the conceptual applicability framework developed during the research, to improve the applicability and usefulness of this platform for energy sector participants and to identify areas that require further development.

Tania Wallis, Rafal Leszczyna (2022)  

Threat Intelligence Management

EE-ISAC members believe that Threat Intelligence can play a very important role in both, preventive and reactive cyber security. Considering the additionally complexity arising from Industrial Control System (ICS) Attack Vectors, the energy sector, more than other sectors, seems to depend even more on good Threat Intelligence Management. This paper explicitly addresses the needs of small and medium enterprises (particularly, these are enterprises with a headcount of less than two thousand employees and cyber security departments with a headcount of one to five) in the energy sector, planning to use Threat Intelligence to improve detective and reactive cyber security controls in their organisation.

Alexander Harsch, Marcel Kulicke, Kostantinos Moulinos, Andreas Seiler, Christina Skouloudi, Antigone Zisi (2020)  

Cyber Security Incident Response

EE-ISAC has gathered a synthesis of experience from their membership to offer some useful guidance, especially to assist smaller businesses to prepare and respond adequately to cyber incidents. In recent years several incidents have targeted critical infrastructures, including the energy sector. As devices used in Operational Technology (OT) facilities trust each other and their users, one compromised device can allow a compromise to the whole system. With an increasing likelihood of incidents, and both small and larger organisations being targeted, it is essential to prepare incident response capability in order to safeguard society’s dependency on energy. Regulations such as the Network and Information Security (NIS) Directive are now enforcing the requirement for an Incident Response capability. This document aims to offer some assistance in building that capability.

Paul Smith, Tania Wallis, Christina Skouloudi, Konstantinos Moulinos, Alexander Harsch, Marius Staggenbrog, Massimo Rocca, Daniel dos Santos, Jalal Bouhdada, Marcel Kulicke, Aleksander Wiśniewski, Alexander Novotny, Michael Knuchel, Dmytro Cherkashyn, Ivan Dragnev, Andreas Seiler (2020)

Developing Novel Solutions to Realise the EE-ISAC

For more effective decision making in preparation for and response to cyberevents in the energy sector, multilevel situation awareness, from technical to strategic is essential. With an uncertain picture of evolving threats, sharing of the latest cybersecurity knowledge among all sector stakeholders can inform and improve decisions and responses. This paper describes two novel solutions proposed during the formation of the EE-ISAC to build situation awareness and support information sharing. The development of EE-ISAC towards regular information sharing among members is described. This demonstrates the foundations achieved so far upon which a situation awareness network can be built for the energy sector.

Rafal Leszczyna, Tania Wallis, Michal R. Wrobel (2019)

Cyber Security Risk Management for Digitalized Energy Systems: Challenges & Solutions

The challenges and solutions of cyber security risk management for digitalised energy systems are presented and discussed in EE-ISAC’s white paper (2018). Developed by members who are lead researchers selected from academia and the sector’s solution providers, it gives an ultimate overview of standards and methodologies and that can be taken as the cutting edge for experts who are designing advanced threat identification and analysis in their companies. The tools and methods described here can offer a useful vision to work towards and contribute to more effective management of risks for the energy sector.

Massimo Rocca, Stefan Schauer, Paul Smith, Reinder Wolthuis (2018)