








News |
By Asma Adhimi
More than 5,000 cybersecurity professionals, policymakers and industry stakeholders took part in Cyber Europe 2026, a large-scale exercise designed to test Europe’s ability to respond to cyberattacks targeting critical transport infrastructure.
Organised by the EU Agency for Cybersecurity (ENISA), the two-day exercise on 10-11 June focused on rail and maritime networks, simulating a series of escalating cyber incidents that disrupted operations across interconnected European transport systems.
The exercise comes as transport infrastructure faces increasing cyber risks amid rising geopolitical tensions and growing digitalisation. For eeNews Europe readers, the event provides a useful insight into how Europe is preparing to protect critical systems that underpin supply chains, logistics, mobility and essential public services.
According to ENISA, the transport sector has ranked among the five most targeted industries for cyberattacks over the last two years. Both rail and maritime operators face similar challenges as they integrate legacy operational technology (OT) with modern digital systems while maintaining strict safety and reliability requirements.
The sector’s dependence on complex supply chains and third-party providers further increases its exposure to cyber threats. At the same time, the growing importance of transport infrastructure in military logistics has elevated its strategic significance.
ENISA’s NIS360 report found that both the rail and maritime sectors remain in a risk zone, with cybersecurity maturity levels below average despite their critical role in Europe’s economy and security.
To deliver this year’s exercise, ENISA collaborated with more than 100 cybersecurity experts from national cybersecurity agencies, EU institutions and private-sector organisations across Europe.
“Transport is essential to our economy and daily lives, but it is also a target for cyber threats. When ports or railways are hit, effects can reach far beyond transport, disrupting trade, military mobility and crisis response. As hybrid threats blur the line between civilian and military infrastructure, preparedness is not optional. Cyber threats cross borders in seconds. Europe must be able to act just as fast, together with its closest partners,” said Henna Virkkunen, Executive Vice-President for Tech Sovereignty, Security, and Democracy.
The exercise scenario centred on a coordinated cyberattack against critical rail and maritime infrastructure across Europe.
Attackers compromised port logistics and navigation systems, halting cargo operations and creating maritime safety risks, including near-collision incidents. At the same time, railway networks suffered direct interference that caused cross-border train services to stop, delaying thousands of passengers and freight shipments.
To increase the pressure on participants, the scenario also included a ransomware attack targeting transport authorities and ticketing systems. The attack disrupted administrative operations and passenger services while exposing sensitive passenger and emergency-response data. The stolen information was then used to fuel disinformation campaigns on social media.
Participants were required to analyse technical incidents while coordinating responses across technical, operational and political levels, sharing information rapidly with the appropriate stakeholders.
“Cyber dependencies across Europe’s critical infrastructure is our operational reality. Our interconnected systems that drive our economies and societies also expose us to common threats, thus cybersecurity is a shared responsibility. Cyber Europe is where we work together to build our preparedness and response to be ready when crisis hits,” said ENISA Executive Director Juhan Lepassaar.
A key objective of Cyber Europe 2026 was to test the EU’s revised Cyber Blueprint for crisis management, adopted in June 2025 to strengthen coordination during large-scale cybersecurity incidents.
For the first time, the exercise also tested the EU Cybersecurity Reserve, a mechanism established under the EU Cyber Solidarity Act and operated by ENISA. The reserve provides incident-response support from trusted managed security service providers when member states require additional assistance during a cyber crisis.
ENISA will now carry out a detailed evaluation of the exercise. The findings will be incorporated into after-action reports designed to identify weaknesses, capture lessons learned and strengthen Europe’s preparedness for future cyber incidents affecting critical infrastructure.
If you enjoyed this article, you will like the following ones: don't miss them by subscribing to :
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。