Decoding the world of cybersecurity

·

ENISA sets new European cyber strategy

ENISA has set seven strategic objectives spanning EU policy implementation, incident preparedness, cyber capacity, shared intelligence, and trust in secure digital products.

ENISA sets new European cyber strategy
Summary
  • ENISA’s new strategy establishes seven objectives covering policy implementation, preparedness, capacity, foresight, shared knowledge, and secure digital solutions.
  • The strategy arrives as the agency assumes a growing operational role in implementing EU cyber legislation, including the Cyber Resilience Act.
  • Europe’s expanding cyber rulebook increasingly depends on common infrastructure and operational coordination, not legislation alone.

The European Union Agency for Cybersecurity has adopted a new strategy built around seven objectives as its role continues to expand in the practical implementation of Europe’s cybersecurity framework.

ENISA’s strategy divides its priorities between three horizontal objectives — stronger cyber communities, foresight on emerging threats, and shared cybersecurity knowledge — and four operational objectives covering consistent EU policy implementation, Union-level incident and crisis preparedness, cybersecurity capacity, and trust in secure digital solutions.

The wording reflects how much the agency’s remit has broadened. ENISA increasingly sits close to the machinery required to make EU cybersecurity law work consistently across 27 member states, alongside its established work on threat intelligence, guidance, coordination, and technical recommendations.

That operational role is already visible under the Cyber Resilience Act. On 11 September, ENISA launched the initial operating capability of the CRA Single Reporting Platform, through which manufacturers can notify actively exploited vulnerabilities and severe security incidents affecting products with digital elements. The CRA’s reporting obligations began this month, while most of its substantive product-security requirements apply from December 2027.

The agency is also involved in vulnerability coordination, sector resilience, exercises, skills, secure-by-design work, and EU-level response arrangements. Its new strategy therefore lands in a regulatory environment where implementation quality matters as much as the volume of legislation adopted in Brussels.

Consistency is one of the difficult parts. NIS2, the Cyber Resilience Act, DORA, and sector-specific requirements create overlapping expectations across organisations, suppliers, products, and infrastructure. National authorities retain important responsibilities, but incidents and dependencies routinely span borders. An inconsistent interpretation of reporting, vulnerability handling, or risk obligations can weaken a framework intended to create a common level of security.

Preparedness is another strand. The agency’s strategy calls for stronger collective capacity to deal with major incidents and crises, reflecting the reality that cyber disruption can move through shared cloud platforms, telecommunications, supply chains, software components, and managed services more quickly than traditional national boundaries suggest.

The strategy also puts foresight and secure digital solutions alongside incident response. That reflects European policy’s increasing attempt to influence the security properties of technology before it reaches the market. The CRA is the clearest example, shifting part of the responsibility for insecure connected products back towards manufacturers and introducing lifecycle obligations that continue after sale.

ENISA published its latest Threat Landscape immediately before the strategy, finding that 73% of targeted organisations in its dataset were entities classified as essential or important under NIS2. The agency also highlighted continued ransomware impact, vulnerability exploitation, geopolitical DDoS activity, supply chain exposure, and the growing use of AI by malicious groups.

The combination illustrates the environment in which the new strategy will be tested. Europe already has a large body of cyber regulation. The next phase depends increasingly on whether national authorities, EU institutions, suppliers, and regulated organisations can translate that framework into shared reporting, reliable coordination, secure products, and workable crisis arrangements.

×