Divided EU cyber defence faces real-life Russian and Chinese threats

Divided EU cyber defence faces real-life Russian and Chinese threats

Europe is facing more immediate cyber threats, but whether its member states are prepared to deal with it collectively is becoming a question harder to answer. Even as drone threats, such as Russia’s bomb plot at the Leipzig-Halle airport in Germany in August, dominated European headlines in September, other, less visible hybrid attacks are also being waged against the EU every day, whose sheer weight of numbers should also cause grave concern. Poland, for instance, recorded 4,200 cyber-security incidents in military networks and systems in 2024 and 7,100 in 2025, Polish cyber command spokesperson, Przemek Lipczyński, told EUobserver. In 2025, Polish security systems blocked four million phishing emails targeted at soldiers and defence personnel. And Poland aside, evolving technology meant Russian cyber-attacks “do not know any border”, said Jamila Boutemeur, the EU’s head of cybersecurity body, in what amounted to a single market for hacking. For its part, the European Union has built its cybersecurity architecture around the Boutemeur’s European Union Agency for Cybersecurity, ENISA, in Athens, as well as the 27 national cybersecurity agencies. But as Russia’s threat levels up, the European structure is seeing familiar problems: information is not always shared, responsibilities remain divided between national governments and EU institutions, while ENISA itself is being asked to do more with limited resources. And the European Court of Auditors (ECA) confirmed it on 21 September in its ENISA study. “The architecture is there, the structure is there. Now it's a matter of willingness and trust,” to effectively fight back, said George-Marius Hyzler, the ECA's main auditor. Stress test shows EU cracks “It always boils down to the same thing, lack of information sharing,” he said, identifying the EU's key weakness. And for Czech Greens MEP Markéta Gregorová, who is also the lead rapporteur on the EU's incoming Cybersecurity Act 2 (CSA2), duplication of work also bedevilled the EU's response. “The [ECA] auditors describe a system that does not work" and was "wasteful", she told EUobserver. “Six European legal acts force the same company to report the same incident to different authorities. Two EU bodies monitor the same threats,” Gregorová said. She also advocated a stronger operational role for ENISA. But the EU fault lines have underlying political as well as legal tensions. Cybersecurity remains largely within the competence of the member states, and governments differ in how much new power they are willing to delegate to European institutions. And for Dimitar Lilkov, from the Wilfried Martens Centre for European Studies, there were three main sources of friction: national security, trust, and money.

Original Source

Read the full article at Euobserver →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.