EU Steps Up Cybersecurity Role Amid Fears of Over-Reliance on U.S. Infrastructure

The EU’s vulnerability platform had been in development prior to the U.S. funding crisis but has now been fast-tracked.

2 mins read
Ursula von der Leyen, President of the European Commission. [EU Photo]

The European Union is accelerating efforts to take greater control of its cybersecurity capabilities, following a recent funding scare in the United States that exposed Europe’s dependence on American-led digital security systems. The initiative, which includes the launch of a European vulnerability database, is being spearheaded by the EU’s cybersecurity agency, Enisa.

In an interview with the Financial Times, Enisa’s executive director Juhan Lepassaar said Europe must “step up our game” in the global cybersecurity landscape. “We just haven’t had the global system so far, which relies to a large extent on capabilities in the United States,” he noted. “We as Europe are ready to take part in strengthening the global vulnerability framework.”

The urgency of Lepassaar’s comments follows a funding disruption in April that briefly threatened the operation of a critical U.S. cyber infrastructure program — the vulnerability disclosure platform managed by the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The platform, run by a nonprofit with U.S. government backing, is a global clearinghouse for cyber threats and vulnerability mitigation strategies.

Although the U.S. programme remained online after what officials described as an “administrative error,” the episode underscored Europe’s heavy reliance on Washington for threat reporting and digital risk management — a risky posture amid increasing geopolitical instability and signs of retrenchment in U.S. defense commitments under President Trump.

A draft budget from the Trump administration for 2026 proposes slashing CISA’s funding by nearly $495 million and eliminating over 1,000 staff. These cuts add further weight to EU concerns over future reliability.

In response, the EU last month quietly established its own vulnerability reporting platform. The “European vulnerability database” is designed to help European businesses and public institutions identify and patch software flaws more autonomously.

“This is about taking care of our backyard, but by doing so, also strengthening the global vulnerability management framework,” Lepassaar told the Financial Times. He added that the EU’s new structure will allow it to propose security fixes and issue guidelines tailored to European needs, particularly for sectors where cybersecurity maturity remains low.

Lepassaar said Europe faces growing threats from state-linked cyber actors, particularly from China. “We see a rise in state-nexus actors targeting critical infrastructure, but also of course public administration,” he said, adding that in Q1 of 2025, Chinese threat groups had targeted European telecom systems. The Czech government recently blamed Beijing for a malicious campaign against its foreign ministry.

The EU’s vulnerability platform had been in development prior to the U.S. funding crisis but has now been fast-tracked. Currently, more than 100 new vulnerabilities are reported globally each day, with at least one classified as critical, according to Enisa.

While sectors such as electricity, telecoms, and banking have shown maturity in their cybersecurity practices, others — including healthcare, public administration, and wastewater management — remain in what Lepassaar called a “risk zone.” These areas are now a top priority for the EU’s cyber resilience push.

In response, the EU adopted new cyber resilience regulations last year, mandating that manufacturers of connected products — from smart watches to baby monitors — build stronger protections into their designs. The European Commission is also reviewing its Cybersecurity Act, with the aim of expanding Enisa’s mandate.

Lepassaar said Enisa could take a more proactive role in helping companies implement the new rules: “We want to help market players better align with cyber resilience requirements, not just respond to threats after the fact.”

As state-sponsored attacks, ransomware threats, and politically motivated cyber incidents proliferate, the EU’s efforts signal a turning point. What was once a backseat role in global cybersecurity may now evolve into an assertive and strategic European capability.

Sri Lanka Guardian

The Sri Lanka Guardian is an online web portal founded in August 2007 by a group of concerned Sri Lankan citizens including journalists, activists, academics and retired civil servants. We are independent and non-profit. Email: editor@slguardian.org

Leave a Reply

Your email address will not be published.

Latest from Blog