Skip to main content Skip to search Skip to main navigation
Menu
Important Cybersecurity Score: 8/10

Cybersecurity in Europe: Critical Infrastructure Between Progress and Risk

An Enisa study shows that while some sectors are catching up on cybersecurity, the risk zone is growing. Rail transport and water supply are causing particular concern.

European cybersecurity: progress and new challenges

The European cybersecurity agency Enisa has published its latest NIS360 report, painting a nuanced picture of Europe's digital resilience. The comprehensive implementation of the NIS2 Directive on network and information security is having an effect and is driving increased investment in critical infrastructures across all sectors. Nevertheless, a dangerous gap remains in many systemically important areas between the real threat situation and actual crisis resilience.

Assessment methodology: from maturity level to risk zone

For the study, Enisa assessed the entire ecosystem of the sectors. The evaluation ranges from the quality of legislation and companies' preparedness through to the effectiveness of supervisory authorities. This security level is set against societal criticality, which is measured by the degree of digitalisation and the potential cascading effects of an outage for citizens.

From the relationship between dependency and security level, Enisa derives a "risk zone" for sectors whose maturity falls below the EU average. Because the general level has risen, new areas have slipped into this danger zone.

Rail transport and water supply in the risk zone

Developments in rail transport as well as in drinking water supply and wastewater disposal are particularly worrying. Both areas have slipped entirely into the risk zone. The criticism amounts to the fact that these sectors are unable to keep pace with the speed of the market.

In rail transport, attackers are focusing on outdated operational technologies and signalling systems. This represents a serious problem, since ageing radio systems and the control centre base are extremely difficult to patch. They even give attackers the ability to stop trains remotely. Its importance for military logistics is also making rail transport an increasingly frequent target of cyberattacks.

Gas supply as a bright spot

Gas supply, by contrast, is showing a positive trend, having made the leap out of the risk zone thanks to more intensive information sharing.

Sector-specific challenges

Space sector: quality disparities and geopolitical risks

The situation in the space sector remains worrying, as it is characterised by enormous differences in quality. Digital society is moving increasingly towards dependence on satellite data for navigation, financial trading and climatology. This key role makes the sector a target for geopolitical cyberattacks, for instance via GPS jamming, which has been causing problems in the Baltic Sea for several years.

Since NIS2 so far covers only parts of the supply chain, there is an imbalance: aviation giants are excellently protected, while smaller suppliers carry considerable security shortcomings with them.

Maritime economy and port security

In the maritime economy, cyberattacks on networked port sectors even threaten to destabilise global supply chains. The growing connection of port cranes and ship systems to the cloud is opening up entry points. National port authorities often lack acute IT expertise.

Healthcare and IT service providers in the middle field

Healthcare and IT service providers are struggling against structural barriers. Hospitals suffer from budget and staff shortages, which under the time pressure of patient care makes them an ideal target for ransomware extortionists. IT service providers, in turn, serve cyber attackers as a strategic springboard for hijacking hundreds of customer networks simultaneously via maintenance access.

Public administrations lag behind

The public sector lacks cybersecurity expertise above all at management level, which is why security updates often take months and government portals regularly fall victim to successful phishing and denial-of-service attacks.

Successful sectors: from banking to power supply

Traditionally heavily regulated sectors such as banking, telecommunications and electricity supply are proving to be rocks in the surf. New to this leading group of high cybersecurity maturity are financial market infrastructures and trust services. Driven by the financial market regulatory framework DORA, security has been successfully anchored there as a business risk at top management level.

Future trends and strategic recommendations

Looking ahead, Enisa identifies three megatrends that are shaking up the security landscape: the rapid advance of AI, which gives attackers new tools such as deepfakes; highly complex software supply chains; and geopolitical upheaval.

The agency strongly recommends that critical sectors move from a purely bureaucratic compliance culture to a lived, resilient practice. This means a fundamental realignment of security strategies that goes beyond merely meeting regulatory requirements.

Conclusion: between progress and growing challenges

The NIS360 report makes clear that Europe's cybersecurity landscape is marked by considerable differences between sectors. While the NIS2 Directive is providing positive impetus and some sectors are making clear progress, advancing digitalisation and new threat situations are also creating new risks. The growing risk zone shows that continuous adjustments and investment in the cybersecurity of critical infrastructures are essential in order to keep pace with the dynamic threat situation.