Sfetcu, Nicolae (2025), Cybersecurity and Cyber Warfare in the European Union: Current State, Threats, and Responses, IT & C, 4:3, 81-109, DOI: 10.58679/IT15160, https://www.internetmobile.ro/cybersecurity-and-cyber-warfare-in-the-eu/
Abstract
Cybersecurity has become an integral part of modern society, with the digital revolution significantly affecting our daily lives, and is one of the most important challenges of the contemporary world, due to both the complexity of information systems and today’s society. The European Union increasingly finds itself on the front lines of cyberspace. As government services, critical infrastructure, businesses, and society become ever more digital, the EU faces a rising tide of cyber threats that endanger economic stability and even national security. Cybersecurity and cyber warfare are intertwined in a complex relationship that shapes our digital world. Cybersecurity has moved from the periphery to the center of European security concerns. Over roughly fifteen years, the European Union and its member states have been forced to reckon with cyber incidents ranging from nuisance website defacements to crippling ransomware on hospitals, from stealthy state espionage to operations amounting to cyber warfare.
Keywords: cybersecurity, cyber-attacks, European Union, cyber warfare, advanced persistent threats, ransomware, threats
Securitatea cibernetică și războiul cibernetic în Uniunea Europeană: starea actuală, amenințările și răspunsurile
Rezumat
Securitatea cibernetică a devenit o parte integrantă a societății moderne, revoluția digitală afectându-ne semnificativ viața de zi cu zi și fiind una dintre cele mai importante provocări ale lumii contemporane, atât datorită complexității sistemelor informatice, cât și a societății actuale. Uniunea Europeană se află din ce în ce mai mult în prima linie a spațiului cibernetic. Pe măsură ce serviciile guvernamentale, infrastructura critică, întreprinderile și societatea devin din ce în ce mai digitale, UE se confruntă cu un val tot mai mare de amenințări cibernetice care pun în pericol stabilitatea economică și chiar securitatea națională. Securitatea cibernetică și războiul cibernetic sunt împletite într-o relație complexă care modelează lumea noastră digitală. Securitatea cibernetică s-a mutat de la periferie în centrul preocupărilor europene de securitate. De-a lungul a aproximativ cincisprezece ani, Uniunea Europeană și statele sale membre au fost nevoite să se confrunte cu incidente cibernetice, de la modificări nedorite ale site-urilor web la ransomware paralizant asupra spitalelor, de la spionaj statal ascuns până la operațiuni care echivalează cu război cibernetic.
Cuvinte cheie: securitate cibernetică, atacuri cibernetice, Uniunea Europeană, război cibernetic, amenințări persistente avansate, ransomware, amenințări
IT & C, Volumul 4, Numărul 3, Septembrie 2025, pp. 81-109
ISSN 2821 – 8469, ISSN – L 2821 – 8469, DOI: 10.58679/it15160
URL: https://www.internetmobile.ro/cybersecurity-and-cyber-warfare-in-the-eu/
© 2025 Nicolae SFETCU. Responsabilitatea conținutului, interpretărilor și opiniilor exprimate revine exclusiv autorilor.
Cybersecurity and Cyber Warfare in the European Union: Current State, Threats, and Responses
Nicolae SFETCU[1]
nicolae@sfetcu.com
[1] Researcher – Romanian Academy (Romanian Committee of History and Philosophy of Science and Technology (CRIFST), Division of History of Science (DIS)), ORCID: 0000-0002-0162-9973
Introduction
Cyber security is the totality of measures to protect computer systems and networks against attacks by malicious actors that can affect digital or physical assets, or the image of a person or organization, disrupt a certain activity or negatively influence a certain trend (Schatz et al. 2017).
The field of cyber security is in constant flux, adapting to the ever-changing digital landscape. As technology advances, so do the tactics of cybercriminals.
Cybersecurity has become an integral part of modern society, with the digital revolution significantly affecting our daily lives, and is one of the most important challenges of the contemporary world, due to both the complexity of information systems and today’s society. As we increasingly rely on interconnected systems, the need to protect our data and infrastructure from cyber threats becomes paramount (Stevens 2018).
Cybersecurity is an ever-evolving field that requires constant adaptation to new challenges. To meet these challenges, advanced threat detection, user education and international cooperation are key components of an effective cyber security strategy.
Cyber security in European Union
The European Union (EU) increasingly finds itself on the front lines of cyberspace. As government services, critical infrastructure, businesses, and society become ever more digital, the EU faces a rising tide of cyber threats that endanger economic stability and even national security (European Council 2024). Cyberattacks in Europe have grown not only in volume but in sophistication, with threat actors ranging from profit-motivated criminal gangs to state-sponsored hackers deploying advanced techniques. High-profile incidents – from ransomware paralysing hospitals to espionage operations infiltrating diplomatic networks – underscore the severe impact cyber operations can have on EU member states. This article examines the current state of the EU’s cybersecurity infrastructure and policies, surveys major cyber incidents and threat actors (including both nation-state and cybercriminal activities), reviews EU-level initiatives such as the European Union Agency for Cybersecurity (ENISA) and the NIS2 Directive and analyzes evolving cyber warfare tactics targeting and emanating from within EU member states. The analysis is grounded in a computer science perspective, focusing on the technical and strategic dimensions of cybersecurity and cyber warfare in the EU, and draws on academic research, official EU reports, and reputable news sources.
EU Cybersecurity Governance: Infrastructure and Policy Framework
The EU has developed an increasingly robust cybersecurity governance framework over the past two decades. At its core is the EU Cybersecurity Strategy, updated in December 2020 to strengthen Europe’s resilience against cyber threats and ensure citizens and businesses benefit from secure digital tools (European Council 2025). This strategy, endorsed by the Council in 2021, emphasized that cybersecurity is essential for a resilient and digitally sovereign Europe, calling for “achieving strategic autonomy while preserving an open economy” in the cyber domain (European Council 2025). In practice, the EU’s cybersecurity approach involves both dedicated institutions and a growing body of laws and initiatives aimed at bolstering defenses across member states.
Institutional Infrastructure
A cornerstone of the EU’s cybersecurity infrastructure is the European Union Agency for Cybersecurity, ENISA. Established in 2004, ENISA was initially a small coordination body, but it has since been significantly reinforced (European Council 2025). The EU Cybersecurity Act of 2019 gave ENISA a permanent mandate, additional resources, and an expanded role in EU cybersecurity efforts (European Council 2025). Headquartered in Athens, ENISA’s mission is to achieve a high common level of cybersecurity across Europe by supporting member states and EU institutions in improving their cyber resilience and in responding to attacks (European Council 2025). ENISA plays a key role in threat analysis (producing the annual Threat Landscape reports), in coordinating the CSIRTs Network of national Computer Security Incident Response Teams, and in developing best practices. In November 2024, ENISA – in cooperation with the EU Commission and the NIS Cooperation Group – published the first comprehensive Report on the State of Cybersecurity in the Union as mandated by the NIS2 Directive (Ribeiro 2024). This inaugural assessment found the overall cyber threat level in the EU to be “substantial,” warning that threat actors are actively targeting essential entities and exploiting newly discovered vulnerabilities – making serious disruptions of critical services a realistic possibility (Ribeiro 2024). The report also highlighted improvements in member states’ capabilities alongside persisting gaps and issued recommendations to bolster EU-wide cyber resilience in areas such as crisis response, supply chain security, and skills development (Ribeiro 2024).
In addition to ENISA, the EU has other cooperative structures. A dedicated Computer Emergency Response Team for EU institutions (CERT-EU) handles cybersecurity for EU bodies. At the political level, a NIS Cooperation Group (comprised of member state authorities) facilitates policy coordination, while a Cyber Crisis Liaison Organisation Network (CyCLONe) was created to assist coordination during large-scale cyber incidents. In 2025, the Council of the EU adopted a new “Cyber Crisis Blueprint” – an EU-level framework for managing major cross-border cyber crises (European Council 2025). This blueprint builds on earlier plans from 2017 and aims to ensure an effective, efficient response to large-scale incidents by clarifying crisis triggers and fostering structured cooperation between civilian and military cyber authorities (European Council 2025). In short, the EU’s institutional cybersecurity infrastructure is now multi-layered: it includes agencies like ENISA, networks linking national authorities, and strategic frameworks for crisis management and collective response.
EU Cybersecurity Legislation and Key Policies
Over the last decade, the EU has also enacted ground-breaking cybersecurity legislation to harmonize and raise security standards across member states. The first major step was the Directive on Security of Network and Information Systems (NIS), adopted in 2016, which was the EU’s “first ever EU-wide cybersecurity law” (European Council 2025). The NIS Directive required member states to identify operators of essential services in critical sectors (energy, transport, health, finance, etc.) and impose security and incident-reporting obligations on them, as well as on key digital service providers (European Council 2025). It also set up mechanisms for cooperation (the CSIRTs Network and NIS Cooperation Group). While pioneering, the original NIS Directive left some gaps and inconsistencies in implementation (Nohre 2023). In response to an evolving threat landscape – and lessons learned from NIS – the EU adopted a revised NIS2 Directive in 2022 to replace the 2016 rules (European Council 2025). NIS2 significantly expands the scope of coverage to include a broader range of sectors and services (for example, providers of digital infrastructure, space, waste management, chemicals, food, and manufacturing of critical products are now included) (Nohre 2023). It imposes enhanced cybersecurity risk management obligations on covered entities and establishes a stricter supervisory and enforcement regime, including the possibility of fines for non-compliance (Nohre 2023). Notably, NIS2 introduces a two-tier categorization of covered entities into “essential” and “important” entities, with largely similar security requirements but differing oversight and penalty levels – essential entities face proactive audits and higher fines (up to €10 million or 2% of global turnover) while important entities are mainly supervised post-incident with slightly lower fines (Nohre 2023). NIS2 came into force in January 2023, and EU member states were given until October 18, 2024, to transpose it into national law (Nohre 2023). Once implemented, NIS2 is expected to level up cybersecurity maturity across the Union by mandating “appropriate and proportionate” technical, operational, and organizational measures (ranging from risk analysis and incident response planning to encryption and supply chain security) for a much wider array of critical operators (Nohre 2023).
Complementing NIS2, the EU has rolled out additional legal initiatives as part of a comprehensive cybersecurity package. The EU Cybersecurity Act (2019) not only bolstered ENISA’s mandate, as noted, but also created the first EU-wide cybersecurity certification framework for ICT products and services (European Council 2025). Prior to this, differing national certification schemes led to fragmentation; under the Cybersecurity Act, common EU certification schemes are being developed to ensure that digital products (such as cloud services or IoT devices) meet uniform security standards, thereby building trust and facilitating cross-border trade (European Council 2025). In late 2024, this Act was even amended to extend EU certification to “managed security services” like incident response and penetration testing (European Council 2025).
Recognizing emerging vulnerabilities in the digital ecosystem, the EU approved a new Cyber Resilience Act (CRA) in October 2024. This law establishes mandatory cybersecurity requirements for products with digital elements (e.g. software, smart devices) throughout their lifecycle (European Council 2025). In effect, manufacturers of connected products (from smart toys to industrial software) will need to ensure basic security by design, provide security updates, and transparency about vulnerabilities, so that consumers and businesses are not exposed to unduly insecure products (European Council 2025). The CRA aims to tackle the long-standing problem of insecure consumer and IoT devices, which are often exploited in attacks (for instance, poorly secured IoT cameras being hijacked for botnets).
Another novel tool is the EU Cyber Solidarity Act, adopted in December 2024, which seeks to improve collective capacities for cyber defense and incident response across member states (European Council 2025). This regulation sets up an EU-wide cyber emergency mechanism and funding to help detect and respond to significant cyber threats (European Council 2025). It will establish a European Cybersecurity “shield”: a network of national and cross-border Security Operations Centers (SOCs) to enhance early detection of attacks (through a “cybersecurity alert system”) (European Council 2025). It also creates joint incident response support, so that in a major crisis (such as a large-scale attack overwhelming a single country’s resources), assistance can be provided in a coordinated way – essentially strengthening solidarity and mutual aid in cyber defense (European Council 2025). The Cyber Solidarity Act entered into force in early 2025 (European Council 2025), reinforcing the message that cybersecurity in the EU is a shared responsibility requiring concerted action.
Beyond these, the EU has developed policies on securing emerging technologies and critical infrastructure. For example, in 2020 the EU issued a 5G Security Toolbox to help member states mitigate risks from untrusted suppliers in next-generation telecom networks (European Council 2025). The EU has also been building a Cybersecurity Competence Centre (in Bucharest) and network of national coordination centers to channel research & innovation funding (under programs like Horizon Europe and Digital Europe) into cybersecurity, fostering home-grown expertise and cutting-edge solutions. In the realm of defense, while primary responsibility lies with member states and NATO, the EU’s Common Security and Defence Policy has started to incorporate cyber defense cooperation – for instance, several member states launched a Cyber Rapid Response Teams project under the EU’s PESCO framework to allow joint cyber units to be deployed in crises.
Finally, the EU has established a diplomatic toolkit to deter and respond to malicious cyber activities. Since 2017, it operates a Cyber Diplomacy Toolbox that enables the Union to impose sanctions on individuals or entities involved in significant cyberattacks. This has been used to sanction offenders from Russia, China, and North Korea in coordination with allies (Caulcutt 2025). For example, the GRU hacking unit (APT28) behind a 2015 breach of the German Parliament was sanctioned by the EU (Caulcutt 2025). In June 2024, the EU updated its sanctions regime to allow new listings in response to cyber-attacks (European Council 2025). Such measures signal that cyber aggression will face EU-wide consequences, complementing the technical and policy measures described above.
In sum, the EU’s cybersecurity infrastructure today is a dense web of agencies, laws, and cooperative mechanisms. ENISA and CERT-EU provide expertise and coordination; the NIS2 Directive and related regulations impose common standards and obligations; new acts like Cyber Resilience and Cyber Solidarity address emerging gaps; and strategic frameworks tie these together. While cyber defense in the EU remains partly a national competence, the clear trend is toward greater integration and a “whole-of-EU” approach to counter increasingly borderless cyber threats.
Major Cyber Threats and Incidents Impacting the EU
Challenges in cyber security
Rapid technological advances
- The constant evolution of technology leads to new vulnerabilities.
- Cybercriminals exploit emerging technologies for malicious purposes.
- Keeping up with security measures becomes a daunting task.
Diversity of cyber threats (CloudStrike 2023)
- The range of cyber threats, including malware, ransomware, phishing, and others, pose significant challenges.
- Sophisticated attack techniques are continuously evolving, making detection and prevention difficult.
Human error and insider threats (Lim et al. 2009)
- People often remain the weakest link in cyber security.
- Insider threats, whether intentional or unintentional, can be devastating.
Resource limitations
- Limited budgets and resources prevent comprehensive cybersecurity efforts.
- Smaller organizations are particularly vulnerable to these constraints.
International and geopolitical challenges
- Cyberspace knows no borders, leading to international and geopolitical conflicts in the digital realm.
- International cooperation and cyber diplomacy are essential.
Challenges in maintaining cybersecurity
More than 120 countries have developed ways to use cyber warfare as a weapon and target financial markets, government IT systems and utilities. It can be used to support traditional warfare, or for espionage and propaganda purposes. Cyber weapons have the potential to be as destructive as traditional ones (Shamah 2013).
Advanced Persistent Threats (APTs): APTs are sophisticated, long-term cyberattacks, often led by nation states or well-funded groups. Detecting and mitigating APTs is a significant challenge because they use advanced tactics to evade traditional security measures.
Human factors: Human error, negligence, or insider threats can undermine cybersecurity. Addressing these issues requires not only technical solutions but also organizational culture and awareness.
Rapid technological advances: As technology advances, new vulnerabilities emerge. There is a need to keep pace with the ever-changing threat landscape through continuous innovation in cybersecurity practices.
Threat landscape in Europe
The threat landscape in Europe is as dynamic as it is dangerous. EU institutions, governments, businesses, and citizens are targeted by a spectrum of threat actors. According to ENISA and the EU Council, the most prominent types of cyber threats affecting the EU include attacks against availability (such as distributed denial-of-service disruptions), ransomware extortion, and attacks against data (breaches and theft), followed by social engineering and malware campaigns (European Council 2024). In fact, threats to availability (e.g. DDoS and sabotage) accounted for roughly 46% of incidents, ransomware for 27%, and data-related breaches 16%, in recent EU analyses (European Council 2024), highlighting the main trends:
- ”Threats against availability (DDoS) and ransomware ranked at the top during the reporting period for another year.
- Living Off Trusted Sites (LOTS): threat actors extended their stealth techniques into the cloud, using trusted sites and legitimate services to avoid detection and disguising Command and Control communications (C2) as ordinary traffic or innocuous messages on platforms like Slack and Telegram.
- Geopolitics continued to be a strong driver for cyber malicious operations.
- Advancements in defensive evasion techniques: cybercrime groups, especially ransomware operators, evaded detection by using Living Off The Land (LOTL) techniques to blend into environments and mask their malicious activities” (ENISA 2024)
These attack types often have direct disruptive impacts on critical services or result in costly losses. Additionally, supply chain attacks – where attackers compromise software or suppliers to infiltrate multiple targets – have emerged as a high-impact vector in Europe, as seen in cases like the SolarWinds incident and others (European Council 2024). Underpinning many of these attacks are tried-and-true techniques: social engineering (phishing users to gain entry) remains a fundamental method to penetrate EU networks (European Council 2024), and the abuse of stolen credentials or unpatched software is a common factor in successful breaches. Attackers are also leveraging new tools such as generative AI to craft more convincing phishing lures or malware that evades detection (European Council 2024), adding complexity to an already challenging landscape.
In terms of threat actors, Europe faces threats from state-sponsored groups, cybercriminal organizations, hacktivists, and even privately-operated mercenary spyware vendors. Each has distinctive motives and methods (European Council 2024). State-related actors—often linked to foreign governments—conduct espionage, influence, or sabotage campaigns for strategic goals (European Council 2024). Cybercriminals seek illicit profit, exemplified by ransomware gangs and fraud schemes (European Council 2024). There is also an overlap between these categories, as some nominally criminal groups act as proxies for states or sell them capabilities. Hacktivists driven by ideological motives have also targeted European entities, sometimes in alignment with state interests (European Council 2024). Notably, the line between nation-state operations and organized cybercrime has blurred: hostile governments (like Russia or North Korea) have been known to tacitly enable or directly employ criminal hackers to advance geopolitical ends (Coker 2025).
Nation-State Threats
The EU’s most persistent and aggressive adversaries in cyberspace have been Russia and China, with Iran and North Korea also posing threats (Coker 2025). Russian and Chinese cyber operations against European targets have been documented for over a decade, primarily involving espionage and intellectual property theft, but increasingly shifting toward disruption and sabotage (Coker 2025). Russia in particular has a history of using cyber attacks as an extension of its foreign policy and military operations in Europe. A watershed moment was the 2007 cyber offensive against Estonia, widely cited as the first instance of large-scale cyber warfare against a nation-state. In April-May 2007, amidst a political dispute with Russia, Estonia suffered waves of coordinated DDoS attacks that crippled government, banking, and media websites (CFR 2007). For three weeks, hackers (ultimately traced to Russia-based networks) flooded Estonian sites with junk traffic, forcing the country to briefly “close its digital borders” by severing international internet links (CFR 2007). This campaign – targeting everything from ministries to news outlets – marked the first time a foreign power had broadly threatened another nation’s security “primarily through cyber operations,” and it served as a wake-up call across the EU and NATO (CFR 2007) (Pernik 2021). Estonia’s experience spurred the EU to deepen cooperation on cybersecurity; the country became a champion of cyber defense initiatives in the EU, and NATO soon established its Cyber Defence Centre of Excellence in Tallinn (Pernik 2021).
Russia has continued to conduct cyber espionage and hybrid warfare operations against EU member states. One notorious group, known as APT28 or “Fancy Bear,” linked to Russia’s GRU military intelligence, has been implicated in several high-impact attacks in Europe. In 2015, Fancy Bear hackers infiltrated the German Bundestag (parliament) network, exfiltrating tens of gigabytes of confidential data (Caulcutt 2025). Germany later revealed that the breach even compromised sensitive parliamentary communications, and in 2020 the EU sanctioned Russian individuals for this incident (Caulcutt 2025). The same GRU unit also targeted electoral processes: in France, during the 2017 presidential race, hackers dumped a trove of emails and documents stolen from Emmanuel Macron’s campaign in a late attempt to sway the vote – the so-called “Macron Leaks.” Only in 2025 did French authorities formally attribute the 2017 Macron hack-and-leak operation to Russia’s APT28, publicly accusing the GRU of orchestrating the attacks on Macron’s campaign team (Caulcutt 2025). This was a rare instance of France “naming and shaming” Moscow for cyber aggression, underlining the continued threat Russian cyber units pose to European democracy and political stability.
In recent years, Russian state cyber operations have taken an even more directly destructive turn, especially in the context of the war in Ukraine. While Ukraine itself (not an EU member) has borne the brunt of Russia’s digital onslaught, there have been significant spillover and direct attacks on EU countries as well. For example, on the very day Russia invaded Ukraine in February 2022, a cyberattack attributed to Russia struck the Viasat satellite network, knocking offline satellite modems across Europe (including affecting wind turbines in Germany). Throughout 2022–2023, European governments and companies have had to be on high alert for cyber retaliation tied to EU support for Ukraine. Russian hackers have probed critical infrastructure in NATO countries; in one alarming case, Western intelligence accused the Russian military of preparing sabotage cyberattacks against energy grids and other critical systems in Europe and North America in 2024 (Coker 2025). EU member states like Poland, the Baltic countries, and Nordic states – all outspoken against Kremlin aggression – have faced repeated intrusions. In May 2023, for instance, Germany revealed that email accounts of the ruling Social Democratic Party (including those linked to Chancellor Olaf Scholz’s office) were compromised by Fancy Bear in a campaign that also hit Poland and the Czech Republic (Starcevic 2024). Such operations show Russia’s intent to spy on and potentially influence EU policy through hacking. Beyond covert espionage, Moscow’s online tactics include hybrid attacks blending cyber with information warfare. An example was a March 2023 incident in Germany: a phone line intercept (likely by Russian agents) of a confidential conversation between German military officials was leaked online along with disinformation – what Berlin described as a “hybrid disinformation attack” aimed at sowing discord in support of Russia’s narrative (Starcevic 2024).
Russia has also indirectly unleashed cybercriminal and hacktivist actors on Europe. Ransomware gangs believed to operate from Russian territory have caused havoc in EU countries (often with at least tacit state approval). Separately, since 2022 pro-Russian hacktivist groups like KillNet have mobilized to attack European targets in retaliation for support to Ukraine. These loosely organized groups conduct disruptive DDoS attacks on government websites, airports, hospitals, and other infrastructure across the EU. For example, in spring 2022, websites of government agencies (including intelligence services) in Estonia, Poland, Romania, and Bulgaria were temporarily taken down by waves of DDoS attacks claimed by KillNetcds (Thales 2023). In early 2023, cybersecurity monitors reported that Russian hacktivists had been targeting Western hospitals with denial-of-service attacks as well (European Parliament 2023). While these attacks generally caused only short-term outages, they underscore a trend of ideologically motivated cyber interference in Europe’s public sphere. EU officials have warned that such operations, even if not directly executed by state hackers, form part of a broader Russian strategy of pressure and intimidation – a kind of cyber “low-intensity warfare” accompanying kinetic conflict.
Turning to China, the primary threat has come in the form of cyber espionage at massive scale. Chinese state-linked hacking groups (often referred to as Advanced Persistent Threats, APTs) have infiltrated European companies, research institutions, and government bodies to steal sensitive data and intellectual property. A striking example was the revelation in 2018 that Chinese hackers breached the EU’s diplomatic communications network. According to an investigation by a cybersecurity firm, attackers (using tools and methods tied to China’s People’s Liberation Army) compromised the EU’s COREU system – used for diplomatic cables – and “accessed thousands of sensitive EU diplomatic cables for more than three years.” (Matthews 2018). The breach, which involved phishing EU officials in at least one member state (Cyprus) to gain an initial foothold, allowed the hackers to quietly monitor discussions on international affairs, EU-US relations, and other strategic topics (Matthews 2018). A cache of intercepted cables (passed to The New York Times) showed EU diplomats’ private assessments of issues like Trump administration moves, Chinese and Russian activities, and the war in Ukraine (Matthews 2018). Security experts had “no doubt” the operation was connected to the Chinese government, illustrating the scope and persistence of Chinese cyber-espionage efforts against the EU (Matthews 2018). Beyond this case, Chinese APT groups have targeted European industries (from aerospace to pharma) and even the African offices of European countries, seeking economic and political intelligence. In some instances, Chinese hackers have exploited supply chain vulnerabilities – for example, the Operation Cloud Hopper campaign (attributed to China’s APT10) compromised IT service providers on whom many European corporations relied, thereby indirectly accessing multiple Western targets. Unlike Russia, China has not typically engaged in outright disruptive cyberattacks in Europe; however, reports in 2022–2024 indicated Chinese state actors quietly positioning malware in critical infrastructure (communications, energy, etc.) in various regions, potentially to have sabotage options in the event of future crises (Coker 2025). This raises concern that Chinese cyber operations, while currently focused on spying, could have a latent destructive capability. EU officials have grown more vocal about such threats; for instance, the EU in mid-2021 joined the U.S. in attributing a major global hack of Microsoft Exchange servers to Chinese state-backed actors and condemned the incident.
Other nation-state threats cannot be ignored. Iran has been accused of probing or attacking European networks on occasion – often targeting dissident groups or Jewish communities in Europe, and in the context of Middle East tensions, attempting disruptive attacks against Western interests (though many of Iran’s confirmed destructive attacks have focused on Israel and the U.S.) (Coker 2025). North Korea, while geographically distant, has a notorious cyber program primarily aimed at financial gain through hacking banks, cryptocurrency platforms, and deploying ransomware worldwide to fund its regime. Europe has not been spared: North Korean actors were behind the 2017 WannaCry ransomware outbreak, which encrypted computers in over 150 countries including many EU hospitals, companies, and government offices. The UK’s National Health Service was especially hard-hit – hospitals across England and Scotland had to divert patients and cancel thousands of appointments due to WannaCry’s impact on their IT systems. North Korean hackers have also conducted cryptocurrency theft from European exchanges and banks. Such activities blur the line between state action and crime: Pyongyang’s operatives behave like cybercriminals, but with a state objective of evading sanctions. This exemplifies the broader trend noted by Microsoft and others that nation-states are converging with financially motivated cybercrime – Russia outsourcing some espionage to criminal gangs, and North Korea essentially using crimeware techniques as state craft (Coker 2025). Microsoft’s 2024 data showed that 3 out of 4 Russian state cyberattacks during a recent period targeted either Ukraine or NATO countries (Coker 2025), highlighting how concentrated nation-state cyber operations have become around current geopolitical flashpoints.
Cybercrime and Major Incidents
Alongside espionage and statecraft, the EU faces an onslaught of cybercriminal activity, chiefly in the form of ransomware attacks, business email compromise fraud, and data breaches for profit. In fact, EU agencies assess that ransomware is the most significant cybercrime threat facing Europe’s public and private sectorsconsilium.europa.euconsilium.europa.eu. The mid- to late-2010s saw an explosion of ransomware attacks globally, and European entities have frequently been victims. These attacks typically involve hackers (often organized gangs based in Eastern Europe/Russia or elsewhere) encrypting an organization’s data and demanding cryptocurrency payment, sometimes combined with theft of data (“double extortion”). Critical services have been disrupted in several EU countries by such attacks, underscoring the real-world harm that cybercrime can inflict.
One of the worst incidents occurred in May 2021, when the Health Service Executive (HSE) of Ireland – the country’s public healthcare system – was hit by a devastating ransomware attack. The perpetrators, a cybercrime group known as Conti (likely operating from Russia), managed to encrypt HSE’s core IT systems, leading to a near-complete IT shutdown across Irish hospitals. The attack was “a landmark event of its type in Ireland” given its impact: it forced doctors and nurses to fall back on paper processes, caused cancellation of appointments and elective procedures nationwide, and even led to temporary service outages in diagnostic and clinical systems (Klappholz 2024). Some areas saw up to an 80% drop in healthcare appointments during the crisis (Klappholz 2024). It took the HSE months to fully recover, and years later they were still dealing with legal and financial fallout (Klappholz 2024). The HSE attack starkly demonstrated the vulnerability of critical infrastructure to criminal hackers, and it galvanized efforts in Ireland (and by extension, the EU) to strengthen cyber resilience in health and other essential sectors (Klappholz 2024). As one expert noted, the incident brought cybersecurity into the public domain in Ireland and was a turning point prompting greater government investment in the national Cyber Security Centre (Klappholz 2024). The HSE case is unfortunately not isolated – hospitals in Germany, France, and other EU countries have similarly been hit by ransomware, with one infamous German hospital attack in 2020 even being linked to the indirect death of a patient who had to be re-routed when hospital systems failed.
European businesses, too, have suffered some of the largest cyber-attacks on record. In June 2017, the NotPetya malware (disguised as ransomware but actually a destructive wiper) spread from Ukraine to devastate multiple multinational companies, including several with major operations in the EU. Denmark’s Maersk, one of the world’s largest shipping firms, saw its global IT network crash in minutes – ships, ports, and offices across Europe and beyond were paralyzed as 17 of Maersk’s terminals (from Rotterdam to Mumbai) had to revert to manual operations (VinciWorks 2018). Maersk later estimated it had to rebuild 4,000 servers and 45,000 PCs in the weeks after, incurring massive losses (VinciWorks 2018). Other Europe-linked companies hit by NotPetya included the German logistics firm DHL’s subsidiary TNT Express, consumer goods giant Reckitt Benckiser, and the European operations of U.S. pharmaceutical Merck – illustrating the global cascade. The White House assessed NotPetya caused over $10 billion in damages worldwide (VinciWorks 2018). NotPetya was attributed to the Russian GRU (Sandworm unit) as part of an attack on Ukraine, but its indiscriminate spread made clear that cyber weapons released by nation-states can easily spill into Europe’s interconnected networks, blurring lines between cyber warfare and cybercrime. Similarly, the WannaCry ransomware (attributed to North Korea) wrought considerable disruption in Europe in 2017, especially to the UK’s NHS, as mentioned.
In addition to ransomware, data breaches have plagued EU companies and institutions. For instance, in 2020, a major hack of a European media conglomerate exposed millions of user records, and breaches of hotel chains, airlines, and banks with EU customers have triggered GDPR fines. The EU institutions themselves are not immune: in 2021, the European Medicines Agency (EMA) was breached, with confidential COVID-19 vaccine documents stolen and leaked by likely state-linked actors. Such incidents emphasize that cyber threats endanger not only security but also privacy and trust.
Another category of concern is the use of spyware and surveillance malware within Europe. The Pegasus spyware (made by Israel’s NSO Group) caused controversy after investigations revealed it had been used to target journalists, activists, and even political figures in EU countries. Notably, in 2021-2022, reports emerged of Pegasus found on devices in Poland, Hungary, Spain, and elsewhere, spurring an EU Parliament inquiry. In 2024, the European Parliament itself disclosed that Pegasus spyware was discovered on the phones of at least two MEPs (Members of European Parliament) and a staffer of a defense committee (Starcevic 2024). One French MEP, who chaired the security and defense subcommittee, had been targeted, as was a Bulgarian member (Starcevic 2024). These revelations suggest that an EU ally or some actor with access to Pegasus targeted European legislators – a serious affront to EU sovereignty. The Parliament responded by urging all members of that committee to have their devices checked (Starcevic 2024). This incident underscores the transnational nature of cyber surveillance: even within the EU, authoritarian-leaning governments or external players might deploy powerful commercial spyware against political opponents or institutions. It led to louder calls in the EU to regulate or ban such tools.
Targeted Sectors and Impacts
According to ENISA, the most targeted sector in Europe by cyberattacks is public administration/government (accounting for ~19% of incidents), followed by transport, financial services, and digital infrastructure, each around 9-11% (European Council 2024). This aligns with observed incidents: government agencies (local and central) are attractive targets for both espionage and hacktivism; meanwhile, ransomware has hit hospitals (health sector), and state hackers have eyed energy grids and telecom networks. The potential consequences of cyber attacks in these sectors are profound. For example, a successful attack on an electricity grid or pipeline could cause blackouts or energy disruptions; an attack on transportation (as seen when railways or shipping firms are hit) can disrupt supply chains. The economic cost of cybercrime in Europe is difficult to fully quantify but is unquestionably large and growing – globally, the cost of cybercrime in 2020 was estimated to be double that of 2015 (European Council 2024), reaching into the trillions of euros. Europe’s share of that includes not just ransom payments or recovery costs, but also productivity losses and reputation damage.
In summary, the EU faces a dual threat spectrum: on one side, highly skilled state-sponsored groups conducting espionage, influence, and potentially sabotage (with Russia and China as prime threats); on the other side, a cybercriminal underground hitting victims opportunistically for profit (ransomware being foremost). Often these realms intersect – for instance, when state actors masquerade as criminals or vice versa. Major incidents in the past 15 years – from Estonia’s DDoS siege in 2007, to the Bundestag hack of 2015, to the NotPetya collateral damage of 2017, to the Irish health service ransomware crisis of 2021, to the ongoing backdrop of Russia-West cyber tensions – have collectively shaped the EU’s awareness and urgency in cybersecurity. These incidents illustrate the need for robust defenses and have informed the EU policies discussed earlier, such as expanding the scope of NIS2 to include healthcare and other critical sectors precisely because of experiences like the HSE attack.
EU-Level Initiatives and Responses to Cyber Threats
Confronted with the above threats, the European Union has steadily scaled up its collective response. We have already outlined many of the policy and legislative initiatives – NIS2, the Cybersecurity Act, Cyber Resilience Act, Cyber Solidarity Act, etc. Here, we consider how these and other actions come together as part of the EU’s strategy to mitigate cyber risks and enhance cyber defense, and what challenges remain.
A major thrust of EU efforts is to harmonize and elevate the cybersecurity baseline across member states. The logic is that a chain is only as strong as its weakest link: a vulnerable system in one country can endanger others (for example, a compromised software supplier in one member state can be a springboard into networks EU-wide). Instruments like NIS2 are thus crucial for ensuring every member state mandates strong security measures for essential services. By October 2024, all EU countries are expected to have transposed NIS2, which should lead to more consistent risk management practices – e.g., regular risk assessments, incident response plans, encryption use, access controls – in hundreds of thousands of organizations that fall under its expanded scope (Nohre 2023). Importantly, NIS2 also requires timely incident reporting (within 24 hours for an initial warning, 72 hours for an incident notification, and a detailed report within one month) (Nohre 2023). This is intended to improve situational awareness and enable faster mutual assistance. The directive also formalizes cooperation through bodies like the NIS Cooperation Group and CSIRTs network, so that information on threats and vulnerabilities is shared more readily among capitals.
The EU is also investing in capability-building. Under the new Cyber Solidarity Act, funds will support the development of a pan-European detection infrastructure – linking national cyber centers to exchange real-time warnings. It also provides for a Cyber Emergency Fund that can be mobilized to assist a country under severe cyberattack (for example, by financing instant support from expert teams or providing hardware/software resources to recover). This kind of solidarity mechanism is somewhat analogous to disaster relief for cyber crises. Additionally, the Cyber Rapid Response Teams mentioned earlier have been trialed: these are small teams of cyber experts from various member states that can, upon request, deploy to help another country investigate or mitigate an incident. Six countries (led by Lithuania) kicked off this concept under PESCO, and they have since conducted exercises and at least one deployment in a real-case support role.
Another key initiative is improving the cyber resilience of critical infrastructure in sectors beyond IT. The EU has aligned its cybersecurity efforts with broader critical infrastructure protection. For example, alongside NIS2, the EU passed the CER Directive (Critical Entities Resilience) in 2022, which covers the physical and cyber resilience of critical entities in sectors like energy, transport, health, and water. The Cyber Resilience Act (focused on product security) and the 5G Toolbox (focused on secure telecom supply chains) are preventive measures addressing systemic risks.
On the law enforcement side, Europol and national agencies are increasingly active in combatting cybercrime through joint investigations, takedowns of criminal marketplaces, and capacity building. The EU’s Joint Cybercrime Action Taskforce (J-CAT), hosted at Europol’s Cybercrime Centre, facilitates cross-border operations against ransomware gangs, fraud rings, and child exploitation networks. There have been notable successes, such as coordinated arrests of ransomware affiliates and infrastructure seizures (often in cooperation with the FBI and other international partners).
In the realm of cyber diplomacy and defense, the EU has been vocal in international forums about promoting a global, open, stable cyberspace governed by international law. The EU supports the norms of responsible state behavior affirmed by the UN. Through its Cyber Diplomacy Toolbox, as discussed, it has not hesitated to impose sanctions – for example, in July 2020 the EU sanctioned individuals from Russia, China, and North Korea for cyberattacks including the WannaCry and NotPetya incidents and the attempted hack of the OPCW in the Netherlands. This was unprecedented and signaled a political willingness to call out state-sponsored cyber aggression (Caulcutt 2025). Additionally, the EU and NATO have deepened cooperation on cyber defense (acknowledging NATO’s role in collective defense). All EU member states (except a few) are NATO members, and they benefit from NATO’s declaration that a cyberattack could trigger Article 5 collective defense. The EU and NATO exchange information and run parallel exercises to improve synergy in responses to cyber contingencies.
One interesting EU initiative is the concept of achieving “cyber deterrence” through joint EU responses. While classical deterrence in cyberspace is complex (attribution is tricky, and cyber retaliation is politically sensitive), the EU’s approach has been to deter through unity and consequences – i.e., naming perpetrators, sanctioning them, improving resilience to deny attackers easy wins, and signaling that severe cyberattacks could result in coordinated diplomatic or even counter-cyber actions. The EU has a Cyber Diplomacy Toolbox for diplomatic action and a Cyber Defence Policy Framework (most recently updated in 2018) to guide its role in military cyber defense. The 2022 Strategic Compass for Security and Defence, an EU policy blueprint, included commitments to enhance cyber defense capabilities of member states, conduct regular cyber exercises, and develop an EU “Cyber Shield” network for threat intelligence sharing – much of which aligns with the subsequently enacted Cyber Solidarity Act.
Another notable development is the launch of the EU Cybersecurity Skills Academy in 2023 to address the workforce shortage in cybersecurity. As identified in ENISA’s reports, the human factor – both in terms of users’ cyber hygiene and the shortage of skilled professionals – is a vulnerability. The Skills Academy initiative aims to coordinate training programs, align qualifications, and attract more talent into the cybersecurity field across Europe (Ribeiro 2024). Improving cyber awareness among the public is also on the agenda; many member states run annual cyber awareness campaigns with ENISA’s support (like the European Cybersecurity Month each October).
Despite these efforts, the EU’s response faces challenges: implementation gaps between countries (some may lag in transposing or enforcing NIS2’s measures), resource disparities (not all member states can invest equally in cyber defenses or hire enough experts), and the ever-moving target of evolving threats. The EU’s patchwork of languages and systems also complicates standardization. However, the trajectory is clearly toward greater integration and collective responsibility. As Juhan Lepassaar, ENISA’s director, stated in 2024,
“Amidst growing cybersecurity threats, technological advancements, and a complex geopolitical landscape, it is vital to assess our capabilities. Through this process, we can effectively evaluate our maturity levels and strategically plan our next steps. The first report on the state of cybersecurity in the Union reflects on our ongoing collective efforts and underscores our shared goal to bolster security and resilience across the EU.” (Ribeiro 2024).
That shared goal is being pursued on multiple fronts – regulatory, technical, and operational – making the EU arguably one of the most proactive regional bodies in cybersecurity governance.
Solutions in cyber security
Advanced threat detection
- Using artificial intelligence and machine learning for real-time threat detection.
- Developing proactive threat intelligence mechanisms to anticipate attacks.
User education and awareness (Townsend 2018)
- Training employees to recognize and respond to cyber threats.
- Promoting a culture of cyber security in organizations.
Multi-Factor Authentication (MFA)
- Using MFA to improve user authentication.
- Reducing the impact of stolen or weak passwords.
Cyber Security Regulations and Compliance (Shirey 2000)
- Develop and enforce regulations to hold organizations accountable for cybersecurity issues.
- Mandatory data protection measures and incident reporting.
International cooperation
- Promoting international collaboration in addressing cyber threats.
- Developing cyber norms and agreements to reduce conflicts in cyberspace.
Evolving Trends in Cyber Warfare Tactics
Cyber warfare – defined broadly as cyber operations that accompany or substitute conventional conflict – has rapidly evolved, and EU member states have both been targets of such tactics and, in some cases, sources of them (as they build their own military cyber units).
Cyber warfare involves the use of cyberattacks at the state level, causing damage comparable to real warfare and/or disrupting enemy infrastructure and systems (Singer and Friedman 2014).
Taddeo offered the following definition of cyber warfare in 2012:
“Warfare based on certain uses of ICT within an offensive or defensive military strategy supported by a state and aimed at the disruption or immediate control of enemy resources and conducted in the information environment, with agents and targets varying both physically. and non-physical domains and whose level of violence may vary according to circumstances.” (Taddeo 2012)
Cybersecurity and cyber warfare have become critical issues. Cybersecurity (the practice of safeguarding digital systems and data from malicious activity) is inextricably linked to cyberwarfare, which involves the use of digital technologies to disrupt, damage, or gain control over adversary computer systems. The line between these two areas is blurred, as cybersecurity strategies often have dual use as applications in cyber warfare and vice versa.
Cybersecurity and cyber warfare are intertwined in a complex relationship that shapes our digital world. As cyber threats continue to evolve, and nation-states engage in offensive cyber actions, the need for robust cybersecurity measures and international cooperation is more critical than ever. To effectively navigate this complicated nexus, stakeholders must continually adapt to the dynamic nature of the cyber domain, recognizing that digital warfare is as important as any physical battlefield in the 21st century.
The threat landscape is constantly evolving, requiring adaptive cybersecurity measures. Cyber threats encompass a wide range of activities, including data theft, malware attacks, denial-of-service attacks, and social engineering. These threats can target individuals, organizations, or even entire nations. As cyber threats grow in complexity, so does the challenge of securing critical infrastructure and sensitive information.
Several key trends in cyber warfare tactics relevant to Europe can be discerned:
Blurring of State and Criminal Methods
As noted, nation-state hackers are increasingly adopting techniques from the cybercriminal playbook, and vice versa. This convergence complicates attribution and response. For example, state actors have been observed deploying ransomware or wiper malware during espionage or military operations to create plausible deniability or throw investigators off track (Coker 2025). Chinese APT groups were found using ransomware attacks against certain targets, not primarily for money but to mask espionage by mimicking crime (Coker 2025). North Korea’s hackers routinely engage in financially motivated attacks (like cryptothefts) that also fund state goals (Coker 2025). Meanwhile, Russia has outsourced aspects of its campaigns against Ukraine to criminal gangs, or encouraged criminal hackers to target Western organizations that are aiding Ukraine (Coker 2025). This trend means European defenders must be prepared for hybrid threats that do not fit neatly into either pure espionage or pure crime: an attack might be both data theft and ransom extortion, or both a military sabotage attempt and an act of cyber vandalism. It also raises legal-policy questions: if a hospital is hit by ransomware traced to a state-tolerated group, is it a national security issue or a criminal matter? The EU’s concept of “hybrid threats” captures this ambiguity – blending cyber, informational, economic pressure tactics by adversaries.
Shift from Espionage to Destructive Attacks
Traditionally, nation-state cyber operations in Europe focused on spying – quietly infiltrating networks to gather intelligence. While espionage remains common, there is a visible shift toward more destructive or disruptive cyberattacks as geopolitical tensions rise (Coker 2025). The Russia-Ukraine war has exemplified this: Russia conducted numerous disruptive attacks on Ukraine’s power grid, government databases, and media. Wipers like “Industroyer” and “HermeticWiper” were used to knock out infrastructure. Western officials have revealed that similar malware was also found in networks outside Ukraine. In one instance, as cited earlier, a coalition of Western governments publicly accused Russia in September 2024 of planning or executing cyber sabotage on critical infrastructure in NATO countries (Coker 2025). Although details were scarce, such warnings imply that Russia might have attempted attacks on European energy or transportation systems (perhaps as signals or tests). Similarly, Western governments have cautioned that Chinese cyber units have pre-positioned access in critical sectors worldwide (communications, energy, transportation, water), potentially to deploy destructive attacks if conflict arises (Coker 2025). For the EU, this trend is worrying because it portends a future where cyber warfare could directly target EU infrastructure to undermine public morale or military readiness in a crisis. The recent EU Cybersecurity Blueprint (2025) explicitly aims to anticipate and manage large-scale cyber incidents that could coincide with broader crises (European Council 2025), showing an acknowledgment that destructive cyberattacks are no longer hypothetical. Another aspect is data sabotage – attackers not only stealing data but altering or destroying it to create chaos (imagine an attack that wipes or corrupts government registries or financial records).
Targeting Critical Infrastructure and Supply Chains
Cyber warfare tactics have gravitated towards targets whose disruption yields high impact. Rather than only stealing confidential documents, attackers now often seek to cause outages or physical effects by attacking industrial control systems (ICS) and operational technology that run utilities. In Europe’s neighborhood, Russia’s cyber attacks on Ukraine’s electric grid in 2015 and 2016 (causing blackouts in Kyiv) were early demonstrations of ICS sabotage. European countries have since hardened their grid defenses, but the threat remains. EU and NATO analysts have also noted increased reconnaissance of power grids, oil & gas networks, and transportation control systems by advanced adversaries (Coker 2025). The goal might be to develop the capability to seriously disrupt these if desired. At the same time, supply chain attacks allow hostile actors to hit many targets through one vector – as seen in the SolarWinds backdoor incident (2020) which affected organizations in EU countries among others, or the CCleaner software compromise (2017) which targeted tech firms including some in Europe. ENISA’s 2024 threat report urges stepping up EU-wide risk assessments of supply chain security (Ribeiro 2024), acknowledging that both states and cybercriminals increasingly exploit third-party trust relationships to amplify their reach. Consequently, one trend is an emphasis on “Secure by design” and vetting of suppliers – hence the Cyber Resilience Act’s focus on product security, and coordinated EU work on cloud and 5G security standards.
Ransomware as a Geopolitical Tool
While ransomware is typically a criminal enterprise, its systemic impact has made it a potential strategic tool. Some experts have observed that during the Ukraine war, certain Russia-based ransomware groups appeared to align their target selection with Kremlin interests – for example, attacking companies in countries seen as adversarial to Russia, sometimes under the banner of patriotism rather than pure profit. This quasi-patriotic ransomware trend blurs warfare and crime. The EU’s law enforcement and security agencies are thus treating major ransomware incidents (like the Irish HSE case) almost as national security events. Joint EU task forces have been formed to tackle ransomware infrastructure and sanctions applied to ransomware operators (the EU sanctioned the Russian-based Trickbot group in 2023, for instance). The deterrence of ransomware also features in cyber diplomacy; in 2021, the U.S. and EU launched a cooperative ransomware initiative to pressure countries harboring these gangs.
Hack-and-Leak and Influence Operations
Cyber operations in Europe have been used in tandem with information warfare. The Macron Leaks in 2017 are a classic example of a hack-and-leak operation intended to influence an election by stealing campaign emails and releasing them with misinformation sprinkled in (Caulcutt 2025). Russian threat actors pioneered this tactic (e.g., the 2016 U.S. election interference) and deployed it in Europe against targets in France, Germany, and elsewhere. In 2020, leaked documents (some forged) were used in a disinformation campaign in the Balkans to destabilize politics. The EU’s Hybrid Fusion Cell monitors such cross-domain threats. The trend is that cyber warfare is not just about technical disruption, but also about stealing information to fuel propaganda or to embarrass and destabilize governments. The EU has responded with teams to combat disinformation (the EEAS East StratCom Task Force, for example) and by improving attribution and public exposure of such campaigns. A recent example: in 2022, European media and security services exposed a Belarusian-linked operation (“Ghostwriter”) that hacked emails and planted fake narratives to target officials in Lithuania, Poland, and other countries – a hybrid campaign likely aligned with Russian interests.
Militarization of Cyber Capabilities by EU States
On the defensive side, EU member states are themselves developing offensive cyber capabilities as part of their military arsenals. Countries like France, Germany, the Netherlands, Italy, and others have established military cyber commands. France released a doctrine for “active cyber defense” and has openly admitted to conducting offensive cyber operations against terrorist networks. The Netherlands’ intelligence agencies famously played a role in counter-hacking Russia’s Cozy Bear team in 2014, illustrating high skill levels. This trend means that within Europe, there is growing expertise not only to defend but to possibly strike back in cyberspace if necessary. While the EU as a union does not conduct offensive operations (those remain national or NATO matters), there is an evolving debate on what a proportionate response to cyberattacks should be, and how to integrate cyber options into collective defense. NATO’s adoption of a new Cyber Operations Centre and its recognition of cyberspace as a domain of warfare are developments that dovetail with EU interests in deterrence.
Advanced Techniques: AI and Post-Quantum Threats
Looking forward, EU experts are also considering how emerging technologies will change cyber warfare. The rise of Artificial Intelligence (AI) can both aid defenders and attackers. Attackers might use AI to automate target selection or adapt malware in real-time, and AI-generated fake content (deepfakes) could amplify information warfare. The ENISA 2024 report highlights AI and also Post-Quantum Cryptography (PQC) as topics gaining traction – meaning that the advent of quantum computers could eventually break current encryption, which would undermine the security of communications unless new cryptographic methods are adopted (Ribeiro 2024). The EU is funding research into quantum-resistant cryptography and promoting its Cybersecurity Competence Centre to invest in innovation that keeps Europe ahead of such game-changing developments (Ribeiro 2024). In the shorter term, the integration of AI in cybersecurity tools (for threat detection) is a positive trend, but there is also worry about AI being used to find vulnerabilities or launch autonomous attacks.
In essence, the tactics of cyber warfare targeting the EU have become more aggressive, more unpredictable, and more intertwined with other forms of conflict. European policymakers often refer to this as the “hybrid threat” challenge – the blending of cyber attacks with traditional military or political warfare to exploit any and all vulnerabilities. The EU’s response (as detailed earlier) is to pursue a holistic resilience strategy: strengthening technical defenses, building redundancy, raising awareness, and solidifying unity so that adversaries cannot easily divide or intimidate member states with cyber operations. As one EU Council report phrased it, cybersecurity in Europe is about protecting not just data and networks, but also ensuring the “security of the digital environment” so that society at large can function and citizens can trust digital services (European Council 2024). That security is increasingly seen as an indispensable component of national security.
Implications of cyber warfare
Geopolitical impact: Nation-states are engaging in cyber warfare to achieve strategic objectives without resorting to traditional military action. Examples include Stuxnet, a computer worm designed to disrupt Iran’s nuclear program, and alleged Russian meddling in foreign elections. Such actions can destabilize international relations.
Role of non-state actors: Non-state actors, such as hacktivists and cyber criminals, play a significant role in cyber warfare. They can be hired or influenced by nation-states to carry out attacks, blurring the lines between independent and state-sponsored cyber warfare.
Escalation dilemma: The anonymity and deniability associated with cyberattacks raises concerns about the potential for unintended escalation in conflict. A minor cyber incident can inadvertently lead to a large-scale conflict.
In an increasingly interconnected global situation, international cooperation is imperative in addressing the challenges of cybersecurity and cyber warfare. Establishing norms and regulations can help mitigate the risks associated with state sponsorship and cyber warfare, promote responsible behavior in cyberspace, and provide a framework for responding to cyber incidents.
Currently, many analysts believe that the sure solution to state cyber threats is a cyber peace through political decision, establishing new rules and international norms and building new tools and infrastructures suitable for this purpose. (Hofkirchner and Burgin 2017).
The future of cyber security and cyber warfare remains uncertain. Emerging technologies such as quantum computing and artificial intelligence are expected to revolutionize both offensive and defensive capabilities. As such, the global community must anticipate the evolving threat landscape and adapt its strategies accordingly.
Conclusion
Cybersecurity has moved from the periphery to the center of European security concerns. Over roughly fifteen years, the European Union and its member states have been forced to reckon with cyber incidents ranging from nuisance website defacements to crippling ransomware on hospitals, from stealthy state espionage to operations amounting to cyber warfare. This article has outlined how the EU has responded by building a layered cybersecurity infrastructure – including laws like NIS2 and agencies like ENISA – and by fostering cooperation and solidarity in the face of cross-border cyber threats. We have surveyed the major threat actors and incidents that have driven these developments: Russian hackers disabling an EU country’s networks in 2007, Chinese APTs exfiltrating troves of European diplomatic cables, ransomware criminals bringing healthcare to its knees, and more. We have also discussed trends in tactics, noting that as the EU strengthens its defenses, adversaries are evolving their playbook with hybrid and more destructive methods.
From a computer science and engineering perspective, the EU’s challenge is as much about technology as it is about policy. Secure network architectures, updated software, encryption, and AI-driven defenses are technical must-haves; but equally important are policy instruments like directives, information-sharing frameworks, and joint preparedness exercises. The EU’s multi-faceted strategy recognizes this duality. Early evidence suggests that initiatives like NIS2 are instigating positive changes – for example, more firms in Europe are conducting risk assessments and reporting incidents than before (Ribeiro 2024). Yet, implementation will be key: some member states may struggle to fully enforce the new requirements or address skill shortages. Constant vigilance is required, as cyber threats do not stand still. The geopolitical events of 2022–2025 (especially the Ukraine war) have injected urgency into EU cyber defense; they have also stress-tested the system. While the EU avoided any catastrophic cyber meltdown, the conflict did see the EU activate its cyber diplomacy toolbox and improve coordination against a barrage of Russian-linked cyber activities.
Looking ahead, the trajectory of EU cybersecurity points toward greater integration and preparedness. The establishment of the EU Cybersecurity Board (under NIS2) to oversee the state of cybersecurity, the regular biennial “State of Cybersecurity in the Union” reports by ENISA (Ribeiro 2024), and the revisions of the EU Cyber Blueprint for crisis response (Ribeiro 2024) all indicate a maturing ecosystem that learns and adapts. The ENISA 2024 report identified priority areas like consistent policy implementation, improved cyber crisis management at the EU level, securing supply chains, and closing the cyber skills gap (Ribeiro 2024) – these are being addressed through targeted recommendations and new programs. In particular, efforts to secure the supply chain (e.g. developing an EU-wide framework for supply chain security assessments) and to stand up the planned Cyber Reserve / Cyber Emergency Mechanism under the Cyber Solidarity Act will likely be accelerated (Ribeiro 2024). There is also recognition that Europe must invest in innovation (from supporting startups in cybersecurity to funding quantum-resistant cryptography research) to stay ahead of adversaries (Ribeiro 2024).
No defense, of course, can be perfect. Cyber warfare and cybercrime will remain an ever-present risk. However, the EU’s collective approach – treating an attack on one as a concern for all, integrating military and civilian efforts, and marrying technical solutions with regulatory mandates – provides a strong foundation for resilience. As threats continue to evolve, the EU is likely to further refine its strategies, perhaps moving toward even more centralized capabilities (like an EU Cyber Command or a unified threat intelligence platform). For now, the European Union has signaled in both words and deeds that it is determined to raise the costs for attackers and reduce the harms for victims. In the words of a recent Council conclusion: achieving a “high common level of cybersecurity” across the EU is not just a legal obligation but “a prerequisite for a prosperous, open, and safe European digital future” (European Council 2025). With continued vigilance, investment, and cooperation, the EU aims to meet the daunting cybersecurity challenges of our era and safeguard its digital society against both criminals and cyber warriors.
Bibliografie
- Caulcutt, Clea. 2025. “Notorious Russian Hackers behind 2017 ‘Macron Leaks,’ France Says.” POLITICO, April 29. https://www.politico.eu/article/macron-leaks-cyberattack-russia-gru-moscow-war/.
- CFR. 2007. “Estonian Denial of Service Incident | CFR Interactives.” https://www.cfr.org/cyber-operations/estonian-denial-service-incident.
- CloudStrike. 2023. “Cyber Attacks on SMBs: Current Stats and How to Prevent Them.” Crowdstrike.Com. https://www.crowdstrike.com/solutions/small-business/cyber-attacks-on-smbs/.
- Coker, James. 2025. “Top 5 Nation State Cyber-Attack Trends.” https://www.infosecurityeurope.com/en-gb/blog/threat-vectors/top-nation-state-cyber-attack.html.
- ENISA. 2024. “Threat Landscape | ENISA.” September 19. https://www.enisa.europa.eu/topics/cyber-threats/threat-landscape.
- European Council. 2024. “Cyber Threats in the EU: Facts and Figures.” Consilium. https://www.consilium.europa.eu/en/policies/top-cyber-threats/.
- European Council. 2025. “EU Cybersecurity: Strategy and Key Policies.” Consilium. https://www.consilium.europa.eu/en/policies/cybersecurity/.
- European Parliament. 2023. “The Role of Cyber in the Russian War against Ukraine: Its Impact and the Consequences for the Future of Armed Conflict.” https://www.europarl.europa.eu/RegData/etudes/BRIE/2023/702594/EXPO_BRI(2023)702594_EN.pdf.
- Hofkirchner, Wolfgang, and Mark Burgin. 2017. Future Information Society, The: Social And Technological Problems. World Scientific.
- Klappholz, Solomon. 2024. “The HSE Cyber Attack Was a ‘Landmark Event’ in Ireland – Has It Learned from the Experience?” IT Pro, May 14. https://www.itpro.com/security/ransomware/the-hse-cyber-attack-was-a-landmark-event-in-ireland-has-it-learned-from-the-experience.
- Lim, Joo, Shanton Chang, Sean Maynard, and Atif Ahmad. 2009. “Exploring the Relationship between Organizational Culture and Information Security Culture.” Australian Information Security Management Conference, ahead of print, December 1. https://doi.org/10.4225/75/57b4065130def.
- Matthews, Alex. 2018. “‘Thousands’ of EU Diplomatic Cables Hacked – DW – 12/19/2018.” Dw.Com. https://www.dw.com/en/thousands-of-eu-diplomatic-cables-hacked-says-report/a-46801480.
- Nohre, Alexander. 2023. “NIS2 – Europe’s Strengthened Cybersecurity Regime.” https://journals.library.columbia.edu/index.php/stlr/blog/view/577.
- Pernik, Piret. 2021. “Cyber Deterrence: A Case Study on Estonia’s Policies and Practice.” https://www.hybridcoe.fi/wp-content/uploads/2021/10/20211012_Hybrid_CoE_Paper_8_Cyber_deterrence_WEB.pdf.
- Ribeiro, Anna. 2024. “ENISA’s 2024 Report on State of the Cybersecurity Focuses on Fortifying Digital Frontier, Provides Recommendations.” Industrial Cyber, December 5. https://industrialcyber.co/reports/enisas-2024-report-on-state-of-the-cybersecurity-focuses-on-fortifying-digital-frontier-provides-recommendations/.
- Schatz, Daniel, Rabih Bashroush, and Julie Wall. 2017. “Towards a More Representative Definition of Cyber Security.” Journal of Digital Forensics, Security and Law 12 (2). https://doi.org/10.15394/jdfsl.2017.1476.
- Shamah, David. 2013. “Cyber Espionage Bug Attacking Middle East, but Israel Untouched — so Far.” http://www.timesofisrael.com/new-cyber-bug-targeting-middle-east-but-israel-untouched-so-far/.
- Shirey, Rob. 2000. Internet Security Glossary. Request for Comments RFC 2828. Internet Engineering Task Force. https://doi.org/10.17487/RFC2828.
- Singer, Peter W., and Allan Friedman. 2014. Cybersecurity: What Everyone Needs to Know. OUP USA.
- Starcevic, Seb. 2024. “Timeline: Europe under Cyber Siege in 2024.” POLITICO, May 9. https://www.politico.eu/article/europe-cyberattacks-russia-china-uk-ministry-of-defence-hacks/.
- Stevens, Tim. 2018. “Global Cybersecurity: New Directions in Theory and Methods.” Politics and Governance 6 (2): 1–4. https://doi.org/10.17645/pag.v6i2.1569.
- Taddeo, Mariarosaria. 2012. “An Analysis for a Just Cyber Warfare.” 2012 4th International Conference on Cyber Conflict (CYCON 2012), June, 1–10. https://ieeexplore.ieee.org/document/6243976.
- Thales. 2023. “KillNet Blocked the Website of Some European Countries Intelligence Service | Cyber Solutions By Thales.” https://cds.thalesgroup.com/en/node/496.
- Townsend, Kevin. 2018. “Knowing Value of Data Assets Is Crucial to Cybersecurity Risk Management.” SecurityWeek, December 3. https://www.securityweek.com/knowing-value-data-assets-crucial-cybersecurity-risk-management/.
- VinciWorks. 2018. “NotPetya: The World’s Worst Cyber Attack.” VinciWorks, October 15. https://vinciworks.com/blog/notpetya-the-worlds-worst-cyber-attack/.
Open Access article distributed under the terms of the Creative Commons CC BY SA 4.0 Attribution License (https://creativecommons.org/licenses/by-sa/4.0/).
PUTI
How is the European Union strengthening its cybersecurity defenses to address the growing threats of cyber warfare and protect critical infrastructure?