Europe’s digital economy is becoming harder to separate from Europe’s security policy, and that is precisely the point of a growing debate in Brussels.
The argument, set out by transport economist Andrea Giuricin in Euronews, is that the continent can no longer treat telecoms, cloud services, data centres and software as neutral utilities. These systems sit behind hospital records, port logistics, industrial production and rail traffic, meaning failures in cyberspace can qu...
Continue Reading This Article
Enjoy this article as well as all of our content, including reports, news, tips and more.
By registering or signing into your SRM Today account, you agree to SRM Today's Terms of Use and consent to the processing of your personal information as described in our Privacy Policy.
ickly become failures in the real world. When digital infrastructure is compromised, he argues, trains can halt, payments can collapse and public services can go offline.
Recent incidents have sharpened that warning. Swedish authorities earlier this year stopped an attack on a thermal power plant that was linked to pro-Russian hackers with connections to Russian intelligence, according to TechRadar Pro. In Poland, researchers said a December 2025 assault on energy infrastructure bore the hallmarks of Sandworm, a Russian state-aligned group, and appeared to use destructive malware designed to wipe data. The attempt did not cause major damage, but it reinforced fears that hostile actors are increasingly willing to target critical systems directly.
That backdrop helps explain why the European Commission moved in January 2026 to revise the Cybersecurity Act. According to the Commission’s proposal, the overhaul would strengthen the security of ICT supply chains, reduce dependence on third-country vendors that pose cyber risks and extend certification beyond products to services, organisational practices and managed security operations. It would also allow mandatory exclusion of high-risk suppliers from telecom networks in certain cases, a significant escalation from the bloc’s earlier 5G security approach.
The proposed changes reflect a broader shift in thinking within the EU. The European Economic and Social Committee, in an opinion adopted in April 2026, described cybersecurity as a question of economic security and geopolitical resilience, while also pressing for a stronger, better-funded ENISA and simpler rules for business. That balance – tougher protection without excessive bureaucracy – is now central to the political debate.
Giuricin’s case is that Europe needs coherence across member states, because a vulnerability tolerated in one country can expose the whole single market. He also argues that safeguards should be proportionate, with especially strict controls in core networks where outages could cascade across critical sectors. And he says the bloc must move quickly, because delayed rules will be overtaken by both technology and adversaries.
The underlying question is not whether Europe should remain open to global trade and investment, but which dependencies it can afford. The distinction matters most in digital infrastructure, where remote access, software updates and control over equipment can create long-term risks that are not visible at the point of purchase. In that sense, Brussels is being pushed towards a more explicit doctrine: openness for trusted partners, caution for suppliers that may be vulnerable to state pressure.
The latest Commission proposal suggests that thinking is already moving in that direction. What remains is whether lawmakers can turn it into a system that is strict enough to matter, fast enough to be useful and broad enough to protect a single market that has become as dependent on code as it is on roads, rails and power lines.
Source: Noah Wire Services