Cyber criminals in the European Union face harsher penalties proposed in new rules adopted by the European Parliament last Thursday.
The draft directive, which member states have already informally agreed upon, aims to enable prevention and enhance cooperation between police and judicial authorities in this area. In the event of a cyber attack, member states will have to respond to emergency requests for assistance within eight hours. According to the draft, member states must impose a minimum prison sentence of two years for crimes of illegal access and interference with computer systems, illegal use of data, interception of communications, or intentional creation and sale of tools for committing these acts. Minor offenses are not covered by this, but it is up to each member state to determine what exactly constitutes a ‘minor’ offense.
Emergency assistance Furthermore, the document provides for a penalty of at least three years in prison for the use of ‘botnets’, i.e., establishing remote control over multiple computers by injecting malicious software. An attack on critical infrastructure such as power plants, transport, or government networks could result in a five-year prison sentence, and the same applies if the attack was carried out by a criminal organization or if the attack caused significant damage. Member states are required to respond quickly to emergency requests for assistance in the event of a cyber attack, which should be achieved through more efficient police cooperation. This cooperation, for example, relates to better use of the existing continuous network of contact points for responding to emergency requests, enabling a response within eight hours.
