Safeguarding critical infrastructure has emerged as a key security priority for European governments in recent years. Neo Tsotetsi discusses the threat landscape driving this reprioritisation, and evaluates the risk posed to commercial operators in these sectors across the coming year.
In August, British authorities reported that a cyberattack had forced a small-scale power generator to suspend operations for four days in July. The government did not identify those responsible, although public reporting linked the incident to Iran-affiliated hackers. The disruption was limited, but it illustrates the growing threat to European critical infrastructure from geopolitically motivated sabotage and terrorism. Iran-linked actors have used such attacks to impose costs on states aligned with the US and Israel beyond the conventional battlefield. Russian-linked actors, meanwhile, have sought to damage and disrupt transport, energy and communications infrastructure as part of a broader ‘grey zone’ campaign against European North Atlantic Treaty Organisation (NATO) members and supporters of Ukraine. Over the coming year, European infrastructure is likely to face an elevated risk of deniable and opportunistic disruption, ranging from cyber intrusions and interference with communications systems to proxy-enabled physical sabotage. Such activity will heighten geopolitical tensions and increasingly carry operational and commercial consequences.
Critical sectors
As stipulated by European Union (EU) Commission
European Union (EU)

In the crosshairs
Critical infrastructure has become an increasingly attractive target for hostile actors because disruption at a single site can generate cascading economic, political and social effects far beyond the immediate point of attack. The EU’s Critical Entities Resilience Directive (CERD) defines critical entities as providers of services essential to societal functions, economic activity, public health and safety, or the environment. Yet, the preparedness of many such operators for the present threat environment remains uneven. Much of Europe’s infrastructure was designed during a less contested security era and was not necessarily built to withstand the combined physical and digital threats they currently face.
The risk is heightened by the interdependence of essential systems: disruption to power, telecommunications or transport can rapidly affect businesses, public services and supply chains. Perpetrators also frequently seek to preserve plausible deniability, using proxies and covert methods to obscure responsibility. This complicates not only prevention, but also the political and legal threshold for a proportionate response. For hostile actors, attacks on civilian-facing services can therefore generate outsized disruption, financial loss and public anxiety without requiring a large-scale or openly attributable attack.
Critical sectors
As stipulated by European Union (EU) Commission
European Union (EU)

Threading the needle
European governments are acutely aware of the current threat environment and need to strengthen critical infrastructure resilience, but converting broad political commitments into effective protection will prove to be politically challenging. The EU’s CERD, which details the need for member states to comprehensively address the resilience of critical entities, required members to transpose common rules into national law by October 2024. It also requires them to develop national resilience strategies, assess systemic risks and identify operators providing essential services. Designated entities need then assess their own exposure and implement proportionate resilience measures. However, delivery is varied between countries, due to differences in regulatory capacity, public funding, threat perception and the fragmented ownership of infrastructure, much of which is privately operated or crosses national borders.
NATO’s 2025 commitment to spend 5 percent of GDP on defence by 2035 includes at least 3.5 percent on core defence requirements and up to 1.5 percent on broader security investments, such as critical infrastructure protection, network defence, and civil preparedness. However, this increased funding does not automatically guarantee improved infrastructure security. Governments are having to balance such investments against competing military, fiscal and social priorities, while operators face the practical challenge of upgrading ageing systems without interrupting essential services. National initiatives such as Sweden’s Total Defence model can strengthen continuity planning and civil preparedness, but the scale, cost and cross-border character of Europe’s infrastructure will make comprehensive protection difficult.
Weathering the storm
As Europe’s security environment becomes more volatile, companies that operate, or depend heavily on, critical infrastructure face a more turbulent risk outlook. For operators themselves, the immediate concern is direct damage to their property and personnel. However, the commercial exposure is usually far broader: even a contained incident can halt production, interrupt access to essential inputs, and require costly rerouting. The resulting costs can spread rapidly through dependent businesses and supply chains, particularly where firms rely on just-in-time operations or have limited alternatives to a disrupted service. For companies, the approach to building resilience will include investing in the physical security of their assets and understanding dependencies on logistics routes, communications networks and contingency capacity.
| Case study: | 2024 cargo flight sabatoage |
|
Target countries
|
United Kingdom (UK), Poland
|
|
Targeted sectors
|
Transport (Logistics)
|
|
Method of sabotage
|
Courier parcels containing sophisticated self-igniting incendiary devices, mailed from Lithuania to destinations in the UK and Poland. Intended to detonate on transiting cargo airplanes
|
|
Outcome
|
|
|
Immediate impact
|
Severe damage to truck and customers' cargo in Poland, including the full payload of one freight trailer (estimated to be roughly USD 200,000); limited damage in Leipzig and Birmingham
|
|
Knock-on impact
|
|
While European governments broadly concur on the importance and urgency of critical infrastructure resilience, the tension between their long-term strategic priority and present political realities has the potential to be a stumbling block. Governments are likely to strengthen planning, intelligence-sharing and protective capabilities, particularly where recent incidents have exposed clear vulnerabilities. However, improving resilience requires substantial, long-term spending on systems whose value is often most apparent when disruption does not occur. In a constrained fiscal environment, governments will need to balance these investments against competing priorities, while making a clearer case for how increased infrastructure resilience protects both essential services and wider economic security.