Paolo Balboni’s View EUROPE’S CYBERSECURITY DILEMMA: SECURITY, SOVEREIGNTY AND THE RISK OF ESCALATION
Europe’s cybersecurity debate is rapidly moving beyond technical security. It is becoming a debate about geopolitical power, economic security, technological sovereignty and the rule of law. A politically sensitive question emerges: should the European Union be able to designate an entire third country as a cybersecurity concern?
Although the proposed Cybersecurity Act does not expressly identify China, the geopolitical target is evident. Europe has been progressively attempting to reduce its dependence on suppliers such as Huawei and ZTE in telecommunications networks and other critical sectors. The new proposal would potentially take this policy considerably further: once a third country is designated as a cybersecurity concern, suppliers originating from that country could potentially be excluded from European critical infrastructure.
This would represent an important transformation of European cybersecurity law. The focus would move from asking whether a particular product, technology or supplier presents an unacceptable risk to asking whether the country behind that supplier creates a security risk. This is where legal, economic and political considerations collide.
The legal dilemma: can cybersecurity risk be attributed to a country?
From a legal perspective, the concern expressed by several Member States is understandable. Austria has argued that restrictions should remain grounded in objective circumstances capable of being demonstrated on a case-by-case basis. Otherwise, supplier exclusions risk becoming political decisions rather than evidence-based cybersecurity measures. Spain has raised a related point: generalized conclusions about a country's legislation, or merely identifying legal obligations imposed on companies by that country, may not be sufficient to justify exclusion.
This raises fundamental questions of proportionality, due process and judicial review. If the European Union designates a country as a cybersecurity concern, the decision cannot simply amount to saying: we do not trust this country. There must be identifiable grounds supporting the designation. The affected parties must have appropriate procedural protections, and ultimately the Court of Justice of the European Union must be capable of reviewing whether the decision has an adequate legal and factual basis.
But there is an obvious problem. The strongest evidence demonstrating that a foreign state represents a cybersecurity threat will frequently come from intelligence services. That information may be classified, sensitive or impossible to disclose publicly without revealing intelligence capabilities and sources. Europe therefore faces a difficult procedural challenge: how can a democratic legal system provide meaningful judicial scrutiny of a national-security decision when the most important evidence supporting that decision cannot readily be made public? If country designations remain in the legislation, the procedural architecture surrounding classified evidence will therefore be almost as important as the substantive power to make the designation.
The economic problem: de-risking has a price
The second dimension is economic. Removing high-risk suppliers from critical infrastructure can improve security, but replacing established technologies can be enormously expensive. Telecommunications networks, energy infrastructure and other critical systems involve long investment cycles. Equipment cannot necessarily be removed overnight without affecting costs, interoperability and security of supply.
Hungary has consequently highlighted another important risk: retaliation. China could respond against the European Union collectively, and selectively against Member States with substantial Chinese trade or investment relationships. Such differentiated economic pressure could itself become a mechanism for dividing European governments.
The concept of de-risking therefore needs to be distinguished from complete economic decoupling. Europe wants to reduce strategic dependencies without unnecessarily destroying economically beneficial relationships. Achieving that balance is difficult because cybersecurity supply-chain decisions increasingly overlap with trade policy, industrial policy and foreign policy.
The underlying economic question is consequently not simply whether Chinese technology should be removed. It is: what will replace it, at what cost, and who will pay? Technological sovereignty cannot consist exclusively of excluding foreign suppliers. Europe must simultaneously develop credible European alternatives. Otherwise, cybersecurity sovereignty becomes expensive dependency management rather than strategic autonomy.
Brussels vs. national capitals
There is also an internal European political struggle. Who should decide whether a foreign technology supplier represents an unacceptable security risk? The European Commission's proposal would strengthen decision-making at EU level. Some Member States see precisely this as a potential transfer of national-security authority toward Brussels. National security remains fundamentally connected to Member State sovereignty.
At the same time, purely national decision-making has obvious weaknesses. A telecommunications network does not stop being strategically relevant when it crosses a national border. Neither do cloud services, software supply chains or cyberattacks. Moreover, fragmented national policies make Europe vulnerable to divide-and-rule strategies by third countries. A foreign government can potentially exert economic pressure on individual Member States to prevent a common European position.
There is therefore a policy dilemma. Centralization may strengthen European geopolitical power, while simultaneously reducing national discretion over highly sensitive security decisions. This may explain why the concept of formally naming countries of cybersecurity concern could ultimately disappear from the final legislation. But even if the terminology disappears, the underlying policy objective is unlikely to disappear with it. More narrowly defined non-technical criteria could potentially achieve similar supplier exclusions without formally blacklisting an entire country.
Another development: CVE and an unexpected form of European sovereignty
Another development appears much more technical but is strategically important. The global Common Vulnerabilities and Exposures, or CVE, system provides standardized identifiers for publicly known cybersecurity vulnerabilities. It is effectively part of the basic infrastructure through which the cybersecurity community communicates about vulnerabilities.
Historically, this ecosystem has been strongly centered on the United States and MITRE. ENISA, the European Union Agency for Cybersecurity, is now increasing its role. NATO’s Communications and Information Agency and European cyber-AI company Aisle have joined the CVE ecosystem under ENISA, bringing the number of organizations operating under ENISA’s umbrella to twenty according to available information.
This might sound administrative, but has further implications. Cybersecurity sovereignty goes beyond manufacturing routers, developing cloud services or regulating foreign suppliers. It also becomes about controlling, or at least diversifying control over, the institutional infrastructure through which cybersecurity operates.
The argument is not necessarily that Europe should replace the American CVE ecosystem. Rather, global cybersecurity infrastructure becomes more resilient when it does not depend excessively upon decisions taken within one country. This is a different conception of digital sovereignty: resilience through diversity rather than sovereignty through isolation.
The bigger picture
Taken together, these developments show that European cybersecurity policy is entering a new phase. The first phase concentrated largely on protecting systems. The second concentrated on regulating organizations, through frameworks such as NIS2.
The emerging third phase concerns economic security and geopolitical power. Who supplies Europe’s critical technology? Who identifies and manages vulnerabilities? Who determines whether foreign suppliers are trustworthy? Who possesses offensive cyber capabilities? Who controls the AI systems increasingly used for cyber defense? And who protects democratic societies against digitally enabled foreign interference? These are no longer questions for CISOs alone. They are questions for governments, boards of directors, intelligence services, regulators, courts and industrial policymakers.
The most difficult challenge for Europe will be maintaining the balance between four objectives that can sometimes pull in different directions: security, fundamental rights, economic competitiveness and technological sovereignty. And perhaps the central question behind the proposed Cybersecurity Act therefore moves from whether Europe should designate a country as a cybersecurity concern, to: Can Europe protect itself against strategic technological dependencies while remaining committed to the rule of law, an open economy and proportionate, evidence-based cybersecurity regulation? How Europe answers that question will determine much more than the future of Chinese suppliers like Huawei or ZTE. It will help define what European digital sovereignty actually means.
Voluntary Transparency Notice
Use of AI: This text includes AI-assisted content.
Workflow: I regularly review a broad range of authoritative sources to stay informed about the topics discussed. I independently develop my analyses, opinions, and conclusions, and use AI solely as a tool to help organize and summarize my thoughts, as well as to assist in preparing the podcast transcript and the accompanying blog post. All content is carefully reviewed, refined, and validated by me before publication, and I take full responsibility for it.
Personal capacity: The views expressed are my own and are provided in my personal capacity. They do not necessarily reflect the views of any organization with which I am affiliated.