Across the European Union (EU), cyberattacks are hitting government ministries, banks, and critical infrastructure, and mounting evidence suggests the bloc’s patchwork of national defense, aging technologies, corporations’ slow pace, and the EU cybersecurity policing are already struggling to keep up with the attackers armed with AI.
Intelligent attacks are testing the EU cybersecurity strategy, with delayed upgrades leaving critical infrastructure open, while AI gives attackers the speed and scale to move faster than governments, regulators, and businesses.
Cyberattacks now reach public administrations, transport, energy, and telecommunications networks. Europe has introduced more rules, yet protection depends on national authorities and organizations with unequal resources. This leaves Europe cybersecurity caught between common ambitions and defenses divided into practice.
Rules Rise as Defenses Remain Fragmented
Between 2024 and 2025, Poland recorded a 145% rise in cyberattacks. In France, hackers stole sensitive information belonging to more than 600,000 taxpayers in July.
In Berlin in August, a Russian-linked group seized government data, including personnel files and passwords, forcing some systems offline. Most reported Europe cyberattack incidents are ideologically driven.
The European Union Agency for Cybersecurity (ENISA) found that hacktivists accounted for nearly 80% of recorded incidents between July 2024 and June 2025, with public administration accounting for 38% of the total and transport and logistics networks also heavily targeted.
France has military cyber capabilities, while Germany is considering broader powers to disrupt foreign operations. Determining whether an EU cyber attack act of war applies would be difficult when attribution is uncertain, and governments set up different response thresholds.
The figures show why EU cybersecurity cannot depend only on legislation alone to fend off an attack.
“We are seeing increased use of AI by cybercriminals to enhance existing techniques, including making phishing campaigns more convincing and supporting reconnaissance and malware development,” said Ilias Bakatsis, a cybersecurity expert at ENISA.
Bakatisis highlighted that state-aligned hacking groups are expected to proliferate their integration of AI into operations built on existing tradecraft. Attackers can improve phishing, reconnaissance and malware development without creating entirely new techniques.
More attacks arrive within the same time frame, deepening the cyberattack EU problem because governments do not share intelligence, tools, and vulnerabilities. National agencies may protect sensitive capabilities, while organizations face different enforcement standards.
An Incomplete Solution
Throughout the past decade, the EU’s cybersecurity policy pivoted from reactive to a more proactive cybersecurity policy, according to Bakatisis. However, experts, officials, and industry figures alike say the EU’s defenses remain split across national borders and institutions.
Sven Herpig, lead cybersecurity advisor at the European think tank, Interface, said Germany alone has roughly 50,000 organizations designed as foundational infrastructure, and that “most critical infrastructure will not be able to defense themselves from military or malicious civilian threat actors.”
Members of the European Parliament’s security committee proposed a new European cybersecurity center, capable of instantaneous threat response, a portal within the new Europe cyber defense strategy that MEP José Cepeda described as a possible seed for a future European cyber command.
Herpig, on the other hand, believes the EU governments remain reluctant to share the tools, vulnerabilities and intelligence such coordination would require.
“We’re not even sharing tools and vulnerabilities among us, so what are we going to achieve by sitting in the same room?” questioned Herpig.
Legacy Technology Will Always Be Systematically Risky
For European regulators, the survival of outdated, unpatched technology inside key networks will always be a systemic weakness that AI attacks are exploiting.
In July, the European Central Bank (ECB) ordered financial institutions to submit remediation plans by the end of October, addressing threats from frontier AI cyberattacks, identifying the modernization of legacy infrastructure as a core requirement for digital Europe cybersecurity.
End-of-life hardware and software no longer receive security patches. Once attackers enter through these systems, they can move across networks, remain undetected, and make removal harder. For EU cybersecurity, replacing obsolete equipment is as important as adopting detection tools.
European financial regulators have urged institutions to remove unnecessary exposure, divide networks and retire legacy systems. They also want asset registers, automated patching, live monitoring, and safer supply chains.
These measures turn EU cyber policy into specific work that operators can measure rather than broad compliance promises.
According to a consulting firm, Wavestone, more than 200 large European organizations found average cybersecurity maturity reached 55.3% in 2026, only 1.3 points above 2025 – with the pace of improvements slowing. A second Europe cyberattack could reach organizations whose spending and staffing have improved but whose architecture remains exposed.
Regulated industries, such as financial services, supported by the EU’s Digital Operational Resilience Act (DORA), reached 67.6% maturity, while unregulated sectors showed no meaningful progress, with an 8.8-point gap. This divide shows that Europe cybersecurity advances fastest where rules carry supervision, deadlines and financial pressure.
Ransomware protection among large organizations reached 58%, but 25% of smaller and mid-sized companies remained in a critical EU cybersecurity situation.
This uneven readiness makes every cyberattack EU concern larger because attackers can enter through suppliers and connected partners, even when institutions have upgraded their central systems.
Europe must strengthen EU cyber capacity building through skills, regulatory resources and support for organizations unable to replace technology quickly. Shared standards matter, but governments must help operators identify outdated assets, fund upgrades and report how legacy equipment contributes to breaches.
The Network and Information Security 2 (NIS2) Directive and reforms to the Cybersecurity Act could expand minimum requirements and strengthen ENISA. Yet EU cybersecurity remains incomplete when national additions recreate fragmentation; regulators lack resources and organizations treat deadlines as paperwork instead of security action.
The digital Europe cybersecurity challenge is to minimize the gap between rules and protection before another attack moves through outdated technology at AI speed. Stronger enforcement, faster upgrades and cooperation will determine whether EU cybersecurity can protect the systems on which societies depend.
Inside Telecom provides you with an extensive list of content covering all aspects of the tech industry. Keep an eye on our Cybersecurity sections to stay informed and up-to-date with our daily articles.
