EU Cybersecurity Month: Enhancing Resilience and Detection of Cyber Threats
As Europe's digital landscape continues to grow, cybersecurity has become a top priority for protecting the region's infrastructure and citizens. The European Commission's ProtectEU Internal Security Strategy, adopted in April 2025, places a strong emphasis on enhancing the EU's capacity to prevent, detect, and respond to cyber threats. This comprehensive strategy incorporates advanced technologies, international cooperation, and cybersecurity education to bolster Europe's cyber resilience.
Key Takeaways:
- ProtectEU integrates cybersecurity as a central pillar of the EU's internal security, outlining existing legal instruments to be implemented and identifying actions to be further developed.
- The strategy focuses on resilience against hybrid threats, critical infrastructure protection, and cybersecurity strengthening through the full implementation of the EU Cybersecurity Act and NIS2 Directive.
- New legal instruments, roadmaps, and processes, such as the revision of the Cybersecurity Act, measures to ensure a cybersecure use of cloud and telecom services, and the development of a Technology Roadmap on encryption, are being developed.
- Operational and institutional capacity building is being strengthened through the enhancement of ENISA, the EU's cybersecurity agency, and cooperation between law enforcement authorities, cybersecurity authorities, and the private sector.
- Technological sovereignty is being pursued through the reduction of dependencies on single foreign suppliers in ICT and telecom, and the deployment of a European quantum communication infrastructure (EuroQCI).
- Lawful access to data is being ensured through a roadmap that respects fundamental rights and safeguards cybersecurity.
Statistics:
- The European Cybercrime Centre (EC3) has been established in 2013 and is a specialized department within Europol dedicated to combating cybercrime across the European Union.
- EC3 supports EU Member States and international partners by providing advanced technical, analytical, and digital forensic expertise.
- EC3's primary focus areas include cyberattacks, online child sexual exploitation, and payment fraud.
- The Joint Cybercrime Action Taskforce (J-CAT), established in September 2014, helps fight cybercrime within and outside the EU.
- The Internet Organized Crime Threat Assessment (IOCTA) is produced annually by EC3 to inform strategic and operational priorities.
Sources:
- European Commission, ProtectEU Internal Security Strategy (https://home-affairs.ec.europa.eu/policies/internal-security_en)
- European Commission, Cybersecurity Act (https://eur-lex.europa.eu/EN/legal-content/summary/the-eu-cybersecurity-act.html)
- European Commission, NIS2 Directive (https://eur-lex.europa.eu/eli/dir/2022/2555/2022-12-27/eng)
- ENISA (European Union Agency for Network and Information Security) (https://enisa.europa.eu/)
- Europol, European Cybercrime Centre (EC3) (https://europol.europa.eu/about-europol/european-cybercrime-centre-ec3#:~:text=Since%20its%20establishment%20in%202013,child%20sexual%20exploitation)
- Europol, Joint Cybercrime Action Taskforce (J-CAT) (https://europol.europa.eu/how-we-work/services-support/joint-cybercrime-action-taskforce#:~:text=The%20Joint%20Cybercrime%20Action%20Taskforce%20(J%2DCAT)%2C%20which%20was%20launched%20in%20September%202014.%20Located%20at%C2%A0Europol%E2%80%99s%20European%20Cybercrime%20Centre%20(EC3)%2C%20it%20helps%20fighting%20cybercrime%20within%20and%20outside%20the%20EU.)
- Europol, Internet Organized Crime Threat Assessment (IOCTA) (https://europol.europa.eu/publications-events/main-reports/iocta-report)