Sharing information about vulnerabilities and attacks is essential to defend information systems against threats such as malware, phishing and unauthorised access. By identifying this information sharing as a legitimate interest of data controllers, and highlighting the public interests that it serves, the draft Network and Information Security Directive provides a framework to encourage European participation in global information sharing, benefitting all users of the Internet.