Divided EU cyber defence faces real-life Russian and Chinese threats

by · EUobserver

The EU analysed some 5,000 cyber incidents over a one-year period (Photo: Rahul Pandit)

EU politics

Unlock article and share
By Petra Pavlovičová,
Brussels
,

Europe is facing more immediate cyber threats, but whether its member states are prepared to deal with it collectively is becoming a question harder to answer.

Even as drone threats, such as Russia’s bomb plot at the Leipzig-Halle airport in Germany in August, dominated European headlines in September, other, less visible hybrid attacks are also being waged against the EU every day, whose sheer weight of numbers should also cause grave concern.

Poland, for instance, recorded 4,200 cyber-security incidents in military networks and systems in 2024 and 7,100 in 2025, Polish cyber command spokesperson, Przemek Lipczyński, told EUobserver.

In 2025, Polish security systems blocked four million phishing emails targeted at soldiers and defence personnel.

And Poland aside, evolving technology meant Russian cyber-attacks “do not know any border”, said Jamila Boutemeur, the EU’s head of cybersecurity body, in what amounted to a single market for hacking.

For its part, the European Union has built its cybersecurity architecture around the Boutemeur’s European Union Agency for Cybersecurity, ENISA, in Athens, as well as the 27 national cybersecurity agencies.

But as Russia’s threat levels up, the European structure is seeing familiar problems: information is not always shared, responsibilities remain divided between national governments and EU institutions, while ENISA itself is being asked to do more with limited resources.

And the European Court of Auditors (ECA) confirmed it on 21 September in its ENISA study.

“The architecture is there, the structure is there. Now it's a matter of willingness and trust,” to effectively fight back, said George-Marius Hyzler, the ECA's main auditor.

Stress test shows EU cracks

“It always boils down to the same thing, lack of information sharing,” he said, identifying the EU's key weakness.

And for Czech Greens MEP Markéta Gregorová, who is also the lead rapporteur on the EU's incoming Cybersecurity Act 2 (CSA2), duplication of work also bedevilled the EU's response.

“The [ECA] auditors describe a system that does not work" and was "wasteful", she told EUobserver.

“Six European legal acts force the same company to report the same incident to different authorities. Two EU bodies monitor the same threats,” Gregorová said.

She also advocated a stronger operational role for ENISA.

But the EU fault lines have underlying political as well as legal tensions.

Cybersecurity remains largely within the competence of the member states, and governments differ in how much new power they are willing to delegate to European institutions.

And for Dimitar Lilkov, from the Wilfried Martens Centre for European Studies, there were three main sources of friction: national security, trust, and money.

To read this story, log in or subscribe

Enjoy access to all articles and 25 years of archives, comment and gift articles. Become a subscriber for as low as €1,75 per week.

Read without limits
Already a subscriber? Login
Unlock article and share

Latest from Defence

Baltic states seek to calm panic on Russia, in role reversal

Lithuania moves to lift ban on nuclear weapons as ‘Russians do not attack the strong’

Latest from Digital

Auditors find EU cyber‑attack response is weakened by overlapping systems and secretive member states

Irish regulator hits Google with €403m GDPR fine over invasive location tracking

Latest from EU politics

Former MEP Rachida Dati’s 2014 emails derided corruption allegations, which now form core of French trial

MEPs vote for €47bn in new Erasmus+ funds, as frugal states seek cuts to EU budget

The EU analysed some 5,000 cyber incidents over a one-year period (Photo: Rahul Pandit)

Topics

Author Bio

Petra Pavlovičová is a reporter at EUobserver. She studied Political Sciences and Journalism in Brussels. She worked and gathered experience in Belgian daily press Le Soir, Slovak redaction of Dennik SME and in the Investigative Center of Jan Kuciak in Bratislava.

+ Follow author by email