惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - Franky
IT之家
IT之家
酷 壳 – CoolShell
酷 壳 – CoolShell
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
C
Check Point Blog
月光博客
月光博客
Jina AI
Jina AI
S
SegmentFault 最新的问题
WordPress大学
WordPress大学
博客园 - 叶小钗
人人都是产品经理
人人都是产品经理
博客园 - 司徒正美
腾讯CDC
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
有赞技术团队
有赞技术团队
博客园 - 聂微东
Hugging Face - Blog
Hugging Face - Blog
小众软件
小众软件
Last Week in AI
Last Week in AI
V
V2EX
罗磊的独立博客
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
阮一峰的网络日志
阮一峰的网络日志
NISL@THU
NISL@THU
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
T
Threat Research - Cisco Blogs
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
L
Lohrmann on Cybersecurity
宝玉的分享
宝玉的分享
爱范儿
爱范儿
T
Troy Hunt's Blog
量子位
Project Zero
Project Zero
S
Secure Thoughts
V
Visual Studio Blog
美团技术团队
AI
AI
博客园 - 【当耐特】
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
The Last Watchdog
The Last Watchdog
V
Vulnerabilities – Threatpost
P
Privacy International News Feed
Spread Privacy
Spread Privacy
Schneier on Security
Schneier on Security
博客园_首页
P
Privacy & Cybersecurity Law Blog
博客园 - 三生石上(FineUI控件)
Apple Machine Learning Research
Apple Machine Learning Research
N
News | PayPal Newsroom

WeLiveSecurity

Recovery scammers hit you when you’re down: Here’s how to avoid a ‘second strike’ As breakout time accelerates, prevention-first cybersecurity takes center stage Digital assets after death: Managing risks to your loved one’s digital estate This month in security with Tony Anscombe – March 2026 edition RSAC 2026 wrap-up – Week in security with Tony Anscombe A cunning predator: How Silver Fox preys on Japanese firms this tax season Virtual machines, virtually everywhere – but not all protected Cloud workload security: Mind the gaps Move fast and save things: A quick guide to recovering a hacked account EDR killers explained: Beyond the drivers Face value: What it takes to fool facial recognition Cyber fallout from the Iran war: What to have on your radar Sednit reloaded: Back in the trenches What cybersecurity actually does for your business How SMBs use threat research and MDR to build a defensive edge Protecting education: How MDR can tip the balance in favor of schools This month in security with Tony Anscombe – February 2026 edition Mobile app permissions (still) matter more than you may think Faking it on the phone: How to tell if a voice call is AI or not PromptSpy ushers in the era of Android threats using GenAI Is Poshmark safe? How to buy and sell without getting scammed Is it OK to let your children post selfies online? Naming and shaming: How ransomware groups tighten the screws on victims Taxing times: Top IRS scams to look out for in 2026 OfferUp scammers are out in force: Here’s what you should know A slippery slope: Beware of Winter Olympics scams and other cyberthreats This month in security with Tony Anscombe – January 2026 edition DynoWiper update: Technical analysis and attribution Love? Actually: Fake dating app used as lure in targeted spyware campaign in Pakistan Drowning in spam or scam emails lately? Here’s why ESET Research: Sandworm behind cyberattack on Poland’s power grid in late 2025 Children and chatbots: What parents should know Common Apple Pay scams, and how to stay safe Old habits die hard: 2025’s most common passwords were as predictable as ever Why LinkedIn is a hunting ground for threat actors – and how to protect yourself Is it time for internet services to adopt identity verification? Your information is on the dark web. What happens next? Credential stuffing: What it is and how to protect yourself This month in security with Tony Anscombe – December 2025 edition A brush with online fraud: What are brushing scams and how do I stay safe? Revisiting CVE‑2025‑50165: A critical flaw in Windows Imaging Component LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Japan ESET Threat Report H2 2025 Black Hat Europe 2025: Was that device designed to be on the internet at all? Black Hat Europe 2025: Reputation is currency – even in the ransomware economy Locks, SOCs and a cat in a box: What Schrödinger can teach us about cybersecurity Seeking symmetry during ATT&CK® season: How to harness today’s diverse analyst and tester landscape to paint a security masterpiece The biggest catch: How whaling attacks target top executives Phishing, privileges and passwords: Why identity is critical to improving cybersecurity posture MuddyWater: Snakes by the riverbank Oversharing is not caring: What’s at stake if your employees post too much online This month in security with Tony Anscombe – November 2025 edition What parents should know to protect their children from doxxing Influencers in the crosshairs: How cybercriminals are targeting content creators MDR is the answer – now, what’s the question? The OSINT playbook: Find your weak spots before attackers do PlushDaemon compromises network devices for adversary-in-the-middle attacks What if your romantic AI chatbot can’t keep a secret? Can password managers get hacked? Here’s what to know Why shadow AI could be your biggest security blind spot In memoriam: David Harley The who, where, and how of APT attacks in Q2 2025–Q3 2025 ESET APT Activity Report Q2 2025–Q3 2025 Sharing is scaring: The WhatsApp screen-sharing scam you didn’t see coming How social engineering really works | Unlocked 403 cybersecurity podcast (S2E6) Ground zero: 5 things to do after discovering a cyberattack This month in security with Tony Anscombe – October 2025 edition Fraud prevention: How to help older family members avoid scams Cybersecurity Awareness Month 2025: When seeing isn't believing Recruitment red flags: Can you spot a spy posing as a job seeker? How MDR can give MSPs the edge in a competitive market Cybersecurity Awareness Month 2025: Cyber risk thrives in the shadows Gotta fly: Lazarus targets the UAV sector SnakeStealer: How it preys on personal data – and how to stay safe Cybersecurity Awareness Month 2025: Building resilience against ransomware Minecraft mods: When ‘hacking’ your game becomes a security risk IT service desks: The security blind spot that may put your business at risk Cybersecurity Awareness Month 2025: Why software patching matters more than ever AI-aided malvertising: How chatbots can help spread scams How Uber seems to know where you are – even with restricted location permissions Cybersecurity Awareness Month 2025: Passwords alone are not enough The case for cybersecurity: Why successful businesses are built on protection Beware of threats lurking in booby-trapped PDF files Manufacturing under fire: Strengthening cyber-defenses amid surging threats New spyware campaigns target privacy-conscious Android users in the UAE Cybersecurity Awareness Month 2025: Knowledge is power This month in security with Tony Anscombe – September 2025 edition Roblox executors: It’s all fun and games until someone gets hacked DeceptiveDevelopment: From primitive crypto theft to sophisticated AI-based deception Watch out for SVG files booby-trapped with malware Gamaredon X Turla collab Small business, big risk: How SMBs can fight back against ransomware HybridPetya: A Petya/NotPetya copycat comes with a twist Introducing HybridPetya: Petya/NotPetya copycat with UEFI Secure Boot bypass Are cybercriminals hacking your systems – or just logging in? Preventing business disruption and building cyber-resilience with MDR Under lock and key: Safeguarding business data with encryption GhostRedirector poisons Windows servers: Backdoors with a side of Potatoes This month in security with Tony Anscombe – August 2025 edition Don’t let “back to school” become “back to bullying”
The quest for greater tech independence
Andy Garth · 2026-05-19 · via WeLiveSecurity

The Trump administration’s shift in tone and approach toward traditional allies has understandably unsettled many nations, raising doubts about U.S. reliability and concerns over dependence on American technology. Many had become used to China and Russia's often belligerent tone, flexing their economic and military muscles, but watching the world’s most powerful nation and flag bearer of liberal democracy reach for similar tactics against its friends has certainly been a wake-up call. 

Europe’s push for tech sovereignty 

In Europe, calls for greater tech sovereignty – the ability to choose and act independently, autonomously, and securely – have become almost deafening. The often rather philosophical debates about strategic autonomy or sovereignty have been ongoing within deliberations on defense and energy for several years now, most prominently following Russia’s full-scale invasion of Ukraine in February 2022. However, concern about an over-reliance on China as a market, a source of goods and a supplier of critical minerals had been bubbling away years before that.

In the last year or so, this concept has visibly seeped into a whole spectrum of industrial and economic policies, digital technologies notwithstanding. Conceptual policy ideas and approaches started to take the form of specific policy proposals and initiatives, currently culminating in a line of legislative measures being put on the table. However, reducing dependencies layered over decades will not be easy. Alternative sources of critical technologies and materials will need to be found or, ideally, developed locally, which requires a complex approach cultivating the right ecosystem more conducive to technological innovation in Europe. At a minimum, it has to facilitate digital infrastructure investments, retain and attract needed talent and nurture home-grown tech companies while giving them space to scale.

US firms dominate the tech space, with profits from their international business arguably helping cement their dominance, often through investment in R&D, healthy marketing budgets, and acquisition – including of talent and emerging start-ups from around the globe, Europe not being the exemption.  And it makes sound business sense for them to do so. Additionally, when it comes to tech, early movers with large investment often stay first, which presents Europe with a two-fold challenge – unleashing the competitiveness on its market without reinforcing the position of established leaders.

In this context, the US has also been quick to robustly defend its tech industry in other nations, particularly against what it views as attempts to overregulate and/or seek to narrow the trade surplus in services that the US generally enjoys. Countries or bodies like the European Union taking a leaf out of the assertive US goods trade playbook and turning it against the US in services is not appreciated in D.C and US ringfencing remains.

The technology landscape is becoming increasingly political, and US technology firms are certainly not immune to growing domestic political pressures. For example, a Microsoft representative acknowledged under oath in a French Senate inquiry that the company could not guarantee full digital sovereignty if US authorities requested access to data stored on Microsoft servers abroad, as permitted under the US CLOUD Act. It has also been reported that Microsoft cancelled services to the International Criminal Court’s chief prosecutor following the decision to open an investigation into actions by Israeli officials in Gaza, to comply with US sanctions. Rumours of backdoors for intelligence agencies (who work with tech firms) and kill switches add to the concern.

Assessing risks 

But of course, it is not just the US that uses trade as a geopolitical lever. Every continent (including Europe) has countries willing or inclined to use such methods, making it essential to factor in the political risk of alternatives. Over the last year in the EU, several groups of countries have coalesced around more or less political approaches to tech sovereignty. The emphasis on operational, technical and legal control over the technology is seemingly presented as being at odds with focusing primarily on the country or origin or geographical location of the infrastructure. On the other hand, the fears of a potential kill switch being used against Europe in a confrontation further fuel the political considerations of digital sovereignty, potentially impacting the quality of evidence-based policy debate rooted in legal and technical realities.

A further challenge arises from the differing cultural and regulatory approaches to technology governance. Despite America First, the US generally prioritizes market openness and international competitiveness, whereas the EU places stronger emphasis on consumer protection, public safety, competition enforcement and now digital sovereignty. Some worry that by accepting US tech, they are forced to accept a US approach that is at odds with their own values. Digital sovereignty is gaining traction beyond political and policy circles – with civil society groups, as well as nationalist narratives, precisely because it appears conducive to enforcing a European digital rulebook providing the usual safeguards on the market. Proponents of digital sovereignty therefore tend to stress the legal jurisdiction under which the tech operates. This bears the risk of hijacking the debate and getting carried away on an ideological wave to the detriment of the European innovation ecosystem. Without maintaining reasonable openness, home-grown technologies will struggle to thrive.

Political weaponization of tech is not the only concern. The CrowdStrike outage in 2024 affected several large businesses, including those in the important aviation sector. IT systems can fail and be vulnerable to attacks. Certainly, there seems to be a steady flow of vulnerabilities that can be exploited, including zero-days. This is where the EU’s enhanced focus on ICT supply chain security comes into foreground complementing the initiatives specifically aimed at tech sovereignty. The proposed framework for identifying high-risk vendors in ICT supply chains under the revised Cybersecurity Act aims to provide a comprehensive methodology merging political, legal and technical considerations for excluding high-risk suppliers. This approach aims to increase European control and jurisdiction over critical supply chains, as well as potentially create space for the growth of European alternatives replacing excluded vendors.

In response to growing demands for national tech sovereignty and protection of local competitiveness in various regions around the world, several US tech firms have begun offering “sovereign” solutions tailored to foreign jurisdictions. While these initiatives, such as those in Europe, are intended to address concerns over data governance and operational autonomy, some analysts note that such models may still rely heavily on US-based infrastructure, legal frameworks, and corporate oversight. Critics, including many Members of the European Parliament, call this “tech sovereignty washing”. Similar questions hang over certain domestic providers that market their services as sovereign solutions, yet continue to depend on US origin technology at the core of their platforms, creating uncertainty about the extent to which these offerings can genuinely deliver independent control. 

While criticism is currently focused on the US (and China), we should also recognize that relationships between nations can shift over time. Membership in the same grouping, whether the EU, ASEAN, the African Union, or others, does not guarantee that one member might not use technological leverage against another during a dispute. Political leadership and policy priorities can change rapidly, and with them, the dynamics of trust and cooperation. Some may point to legal frameworks or contracts as reassurance, but arguably these matter little when nation states decide to use their own legal sway over their companies and those that want to operate in their market. The challenge for policymakers is to translate supportive words and sentiment on securing greater tech sovereignty and digital independence into meaningful action.

Trusted cyber defenses made in Europe 

In cybersecurity, there are credible alternatives available – ESET is one strong example, though certainly not the only one. Many European firms are working hard to compete globally. Ultimately, organizations need to understand and reduce their exposure risks, adopting trusted solutions that are tailored to each case and that ensure strong compliance with strict data protection frameworks, such as the GDPR. 

Across the EU, there is also a growing discussion about adapting public procurement processes and public funding schemes to favor such alternatives. Increasing the awarding of public contracts (rather than grants) could be an effective way to stimulate business growth while reducing costs for taxpayers. Switching providers should also be made easier through greater and built-in interoperability, mitigating “technical lock-ins” and easing switching costs. The European Cybersecurity Organisation (ECSO) has advocated for a dedicated industrial strategy for cybersecurity, given its strategic importance. We await the details of the European Commission’s “Tech Sovereignty Package” due at the end of May, as well as the potential revision of public procurement rules under the Public Procurement Act to see tangible, realistic and hopefully practical measures aimed at nurturing and scaling European alternatives. 

Primarily, it is critical to strike the right balance between fluid political and objective technical considerations when setting out criteria defining a “made in Europe” solutions. Sovereignty should not be reduced to the geographical origin of a provider. Greater weight should be placed on objective indicators of how a solution delivers operational autonomy and legal insulation from non-EU jurisdictions. Finally, given the complexity of the challenge and the vastness of the gap that the EU aims to close, it is also necessary to be realistic about timelines and certain specific types of technologies where achieving sovereignty is unlikely for Europe in a short or even medium term. In such cases, a reasonable share of EU-made components in the final product should be a sufficient step towards incrementally increasing domestic capacity. This could be coupled with the assessment of critical functions of a product which should be based (or at least majority of them) on EU-made technology.

The private sector also has a vital role to play by considering technological sovereignty, geopolitical risk and supply chain vulnerabilities within its procurement decisions. If the private sector also aligns itself to the cause, the take-up of alternatives and stimulus would be widely felt. One risk, however, is that support becomes concentrated on just one or two national/regional firms – a mistake that could undermine the sector. Healthy competition drives lower prices, greater innovation, and reduces strategic vulnerability should any single company fail or encounter difficulties. 

The geopolitical landscape has shifted significantly. A complete decoupling from US technology is neither realistic nor necessary, but the changing environment does require nations and companies to reassess their relationships and dependencies. Risks that were barely considered only a few years ago must now be recognized, understood, mainstreamed and actively mitigated.