On Thursday, the European Parliament approved a new bill to combat cybercrime. The new directive, which European Union member states must implement within two years, builds on a set of regulations that have been in force since 2005.
Members of the European Parliament approved the European Commission's proposal with 541 votes in favour and 91 against.
Under the new directive, cybercriminals who interfere with data and information systems, those who monitor communications, and those who sell hacking tools will face at least two years in prison.
Attacks against infrastructure considered vital and causing serious damage will be punishable by at least 5 years in prison. Botnet creators will face at least three years in prison.
The directive also seeks to improve cross-border cooperation by requiring member states to respond to urgent requests within 8 hours.
Member States should collect statistics on cyberattacks occurring in their country and report incidents to the designated authorities.
“This is an important step in strengthening Europe's defence against cyber attacks. Attacks on information systems are a growing challenge for governments and citizens. These attacks can cause serious damage and undermine users' trust in the security and reliability of the internet,” said Cecilia Malmström, EU Commissioner for Home Affairs.
“I am therefore pleased that formal approval has been achieved and we have new rules on the definition of criminal offences and sanctions in the area of cybercrime,” Malmström added.
“Perpetrators of increasingly sophisticated attacks and malware makers can now be prosecuted and face heavier criminal penalties. Member States will also have to respond more quickly to urgent requests for assistance in the event of cyber attacks, and European judicial and police cooperation will be improved.”
