Skip to content

Cyber defence

The EU cyber defence policy aims to enhance cooperation and investments to better detect, deter, and protect and defend against  a growing number of cyberattacks.

Cyberspace as a warfare domain

Cyberspace is considered as the fifth domain of warfare, and is as critical to military operations as land, sea, air, and space. It is a domain encompassing everything from information and telecommunication networks and infrastructure and the data they support, to computer systems, processors and controllers.

Cyberspace has become an increasingly contested strategic domain and a field for strategic competition. Moreover, digital and physical infrastructure are interdependent, meaning that significant cybersecurity incidents can disrupt or damage critical infrastructure – such as energy and transport networks – that armed forces in the EU rely on.

In recent years, state and non-state actors have intensified cyberattacks, espionage and disinformation campaigns targeting the EU and its member states, including the defence sector. Malicious behaviour by these actors has increased exponentially following Russia’s military aggression against Ukraine. 

The EU and its member states are working together to protect European citizens, national armed forces and EU civilian and military missions and operations against cyber threats. They are boosting cooperation on and investments in cyber defence and enhancing the EU’s ability to prevent, detect, defend against, recover from, and deter cyberattacks.

The main framework for EU cooperation in the area of cyber defence is the EU cyber defence policy. The EU also cooperates on defence in cyberspace through the activities of the European Defence Agency (EDA), in collaboration with the EU cybersecurity agency (ENISA) and Europol. The EDA supports member states in building a skilled military cyber-defence workforce and ensures the availability of proactive and reactive cyber-defence technology.

Cyber defence policy

Building on the cyber defence policy framework adopted in 2014 and updated in 2018, on 22 May 2023, the Council adopted conclusions on the EU policy on cyber defence. The conclusions stress the need for the EU and its member states to further strengthen their resilience to cyber threats and enhance their common cyber security and cyber defence against malicious behaviour and acts of aggression in cyberspace.

In line with the conclusions, in October 2024 the Council approved the first-ever ‘EU cyber census’, tracking progress on implementation of the policy.

The EU cyber defence policy is built around four pillars, which cover a wide range of initiatives: 

act together for a stronger cyber defence

invest in cyber defence capabilities

secure the EU defence ecosystem

partner to address common challenges

Act together for a stronger cyber defence

Cyberattacks are often cross-border in nature and may have a physical impact on critical infrastructure in the EU. Significant cybersecurity incidents can be too disruptive for the member state(s) affected to handle alone. They can also form part of larger hybrid attacks carried out by state or non-state actors with the aim of destabilising the economy and society, weakening critical infrastructure needed to ensure the security of the EU or undermining and harming the functioning of democracies, including through attacks on election infrastructure.

In line with the Strategic Compass, member states and other relevant actors should act together for stronger cyber defence, by strengthening cooperation and coordination between military and civilian cyber communities. 

Concrete initiatives under this pillar include:

  • further developing the EU Cyber Commanders Conference
  • setting up an EU Military Computer Emergency Response Teams Operational Network (MICNET)
  • creating an EU Cyber Defence Coordination Centre to enhance coordination and situational awareness, in particular for CSDP missions and operations
  • enhancing intelligence cooperation on cyber threats and strengthening the EU’s cyber intelligence capacities
  • increasing cyber education, training and exercises 

Secure the EU defence ecosystem

In recent years, the number of cyberattacks has increased dramatically, including supply chain attacks aimed at cyber espionage, ransomware or disruption. In 2020, the SolarWinds supply chain attack affected more than 18 000 organisations globally, including government agencies, major businesses, and defence companies. This and other incidents have demonstrated a clear need to further strengthen the cyber resilience of entities that are active in the EU defence ecosystem, including military entities, the defence industry, and private operators.  

To address issues related to the security of their communication and information systems, the EU and its member states are working on cybersecurity standardisation and certification to secure both military and civilian domains.

The Council encourages member states to:

  • strengthen the European cyber defence industrial and technological base to develop and deliver full-spectrum cyber defence capabilities
  • reduce their strategic dependencies across their capabilities and supply chains
  • develop and master cutting-edge cyber defence technologies

Invest in cyber defence capabilities

Technology improvements are essential to maintain an advantage over competitors and adversaries, who are also investing heavily in new technologies. Furthermore, skills and competences are essential to overcome strategic dependencies in the areas of cybersecurity and cyber defence in Europe. The European defence industry needs to retain key skills and acquire new ones to remain in a position to deliver high-tech solutions in a global setting.

In this context, member states need to significantly increase investments to build, maintain and further develop interoperable cyber defence capabilities. In doing so, they should make the best possible use of EU cooperation platforms, such as the European Defence Agency (EDA) and permanent structured cooperation (PESCO), and funding mechanisms, such as the European Defence Fund, Horizon Europe and the Digital Europe Programme.

The Council also invites member states to address the cybersecurity skills gap, leveraging the synergies between military, civilian and law enforcement initiatives.

Partner to address common challenges

As cyber threats go beyond national borders, the EU cooperates with partner countries and international organisations – such as the North Atlantic Treaty Organization (NATO) – to enhance collective security and protect citizens. The EU is seeking to set up tailored partnerships in the area of cyber defence, including on cyber defence capacity building through the European Peace Facility.  

Cyber defence is to be discussed with partners in the framework of dialogues and consultations on cyber and on security and defence.

Cyber constitutes one of the key priority areas of EU-NATO cooperation. The EU is promoting further synergies with NATO, including on responses to malicious cyber activities, capacity building efforts in third countries, training, exercises and situational awareness.

See also

Security and defence

Security and defence

Cybersecurity

Cybersecurity

Hybrid threats

Hybrid threats

Last review: 21 March 2025