report

Government of data sharing in cybersecurity

Published in Regulatory Frameworks by

AA

Ransomware is one of the most frequent types of cyberattacks: it involves taking control of data and demanding payment to restore access (i.e., a ransom). This type of attack is evolving into a sophisticated form of extortion, leveraging cybercriminal organizations that provide infrastructure and services (i.e., ransomware-as-a-service) to exploit vulnerabilities in target entities (e.g., industries, public administrations, small and medium-sized enterprises, and critical infrastructures) [1].

This digital form of “protection racket”, which holds encrypted data hostage until the ransom is paid, differs from its physical counterpart by transcending geographic boundaries, enabling perpetrators to operate remotely and anonymously, thereby amplifying the reach and impact of their attacks.

Ransomware breaches thus represent a significant threat to small and medium-sized enterprises (SMEs), which often lack the robust cybersecurity infrastructure of larger companies, risking substantial financial loss, reputational damage, and even business closure.

The case of an Italian SME [2] that refused to pay the ransom—adhering to ethical and legal principles—exemplifies the potential impact of such an attack. While upholding these values and rules is a source of European pride, the inability to adequately defend them remains a vulnerability: the company was forced to halt all production activities and temporarily suspend its staff.

Therefore, intrusions by these cybercriminals not only threaten the economic sustainability and existence of the affected business but also negatively affect its broader network of stakeholders, including individuals and other companies.

In this context, the increasing sophistication and frequency of ransomware and cyberattacks underscore the urgent need for greater cybersecurity awareness and the adoption of proactive measures by SMEs. These organizations must implement a multilayered approach involving employees, organizational processes, and technologies to address well-known and exploited vulnerabilities, such as backup strategies, human error, data management, access control policies, and technological obsolescence [1][3][4].

Awareness and proactivity can be achieved through a robust and collaborative defense strategy. The creation of a shared and continuously evolving body of knowledge (BoK) dedicated to countering cyber threats is no longer just an advantage—it is a critical imperative to safeguard digital assets and ensure operational resilience. This BoK should serve as a dynamic compendium of attack methodologies, threat actor profiles, effective mitigation techniques, best practices for incident response, and lessons learned. A consolidated and shared knowledge base would be a valuable asset for significantly improving threat landscape understanding, identifying vulnerabilities, and developing more effective security controls.

Moreover, the inherent interconnectedness of cyber threats demands the smooth sharing of information with appropriate stakeholders. Cyberattacks rarely operate in isolation; threat actors often adopt similar tactics across multiple targets. A well-governed BoK would promote the timely and secure dissemination of actionable intelligence (e.g., emerging attack patterns and effective defensive strategies) to relevant entities, such as SMEs, government bodies, and security providers. This collaborative approach would strengthen collective defense, enabling organizations to anticipate and counter attacks based on community-shared experiences. The sharing of information, in compliance with appropriate legal and ethical frameworks, turns individual efforts into a coordinated and stronger defense, ultimately reducing the impact and prevalence of cyberattacks in the digital landscape. The BoK, therefore, stands as a cornerstone of a proactive and collaborative cybersecurity posture essential to addressing the complexity of today’s threat environment.

On the other hand, the collaborative creation of a shared BoK requires coordination through adequate support tools. Participants in this initiative should be able to share and grant access to a wide range of cyber threat intelligence (CTI), including emerging threats, attack vectors, tactics, techniques and procedures (TTPs) used by threat actors, and indicators of compromise (IOCs).

Such data sharing requires explicit consent, respecting the protection of personal data (privacy) in accordance with EU Regulation 2016/679 GDPR [5]. This consent mechanism, which governs data processing based on specific policies, enables the controlled and governed creation of collective knowledge, fostering trust and encouraging responsible intelligence sharing among participants.

The ReD Service, developed by CyberEthics Lab. [6], supports the collaborative sharing of CTI data among appropriate entities based on consent and smart contracts. While consent mechanisms ensure privacy and transparency, smart contracts on immutable ledgers (i.e., blockchain) securely contain the necessary information to automatically enable access and data sharing among stakeholders, ensuring integrity, availability, and confidentiality.

As a standalone module, the ReD Service can be integrated into existing or new platforms to add compliant data-sharing features, policy management, and consent handling. To better protect potentially personal, confidential, or sensitive data from policies and consents, the ReD Service uses a technique called pseudonymization. This process replaces identifiable information with unique and anonymised codes using a robust cryptographic method (i.e., SHA-2 family cryptographic hash functions). This design choice ensures that the ReD Service never stores personal data in smart contracts or on the blockchain, maintaining compliance with regulatory constraints (e.g., Articles 16 and 17 of the GDPR).

The ReD Service represents the core engine of the Smart Consent component (SMAC – “Smart contracts and icons for consent management in the context of an SSI approach”). This innovation was recognized by the European Commission’s Key Innovation Radar in 2024 [7] in the “Smart & Sustainable Society INNOVATION” category, contributing to Sustainable Development Goal 16: “Peace, Justice and Strong Institutions” [8].

CyberSocial Lab. and CyberEthics Lab. collaborate to test, optimize, and extend the ReD Service in the CyberNEMO [9] and INTERSOC [10] projects.

 

Disclaimer

This work was supported by the CyberNEMO project (Grant Agreement No. 101168182), which has received funding from the European Union’s Horizon Europe research and innovation program, and by the INTERSOC project (Grant Agreement No. 101145853).

The opinions expressed in this document reflect only the author’s view and in no way reflect the European Commission’s opinions. The European Commission is not responsible for any use that may be made of the information it contains.

 

References

[1] ENISA Threat landscape 2024 – https://www.enisa.europa.eu/sites/default/files/2024-11/ENISA%20Threat%20Landscape%202024_0.pdf

[2] Alf Dafrè case – https://decripto.org/en/treviso-hacker-attack-on-alf-dafre-furniture-company-350-workers-end-up-on-lay-off/

[3] ISO/IEC 27001:2022 https://www.iso.org/standard/27001

[4] NIST Cybersecurity Framework (CSF) – https://www.nist.gov/cyberframework

[5] EU General Data Protection Regulation 2016/679 – https://eur-lex.europa.eu/eli/reg/2016/679/

[6] ReD in the CEL Portfolio – https://cyberethicslab.com/en/portafoglio/

[7] Smart Consent in the Innovation Radar – https://innovation-radar.ec.europa.eu/innovation/56307

[8] United Nations SDG no.16 – https://sdgs.un.org/goals/goal16

[9] CyberNEMO project – GA. no. 101168182 – https://cybersoclab.com/cybernemo-eng/

[10] INTERSOC project – G.A. no. 101145853 – https://cyberethicslab.com/en/intersoc/

 

Service involved

Assessment of technology impact on privacy
We help our clients and partners to achieve their business goals while addressing ethics, privacy and cybersecurity concerns in a manner that prevents conflicts, sanctions and loss of money derived by the lack of ethical and legal compliance to national and European applicable regulations. All information technologies must respect human fundamental rights and ensure the rights of people in relation to the protection of their private life, personal data and freedom. The new EU General Data Protection Regulation (GDPR) that replaced the Data Protection Directive in all EU member states on May 2018 introduces many new obligations for companies and a comprehensive set of rights for data subjects, including the right to an effective judicial remedy against a controller or a processor and the right to compensation. Therefore, in addition to being at the receiving end of an enforcement action, data controllers and processors may be subject to court proceedings and have to pay compensation to data subjects for their infringements of the GDPR. Our approach to help our clients to avoid this kind of issues consists of a holistic service composed by the following main components: providing a Data Protection Officer to drive the organization’s legal compliance action; mapping the data processed by the organisation to measure its impact on the ethical principles and legal framework; assessing the cybersecurity mechanisms used by the organisation technologies; conducting an impact assessment for all data processing mechanisms identifying ethical, legal and security risks; making recommendations for the implementation of the organisational and technical means to be compliant with the legal framework while ensuring data confidentiality (preserving authorized restrictions on information access and disclosure, including personal privacy and proprietary information protection), integrity (assurance that data is not modified or deleted in an unauthorized and undetected manner), availability (ensuring there’s timely and reliable access to and use of information) and accountability (supporting non‐repudiation, deterrence, fault isolation, intrusion detection and prevention, and after‐action recovery and legal action).