By&nbspAndrea Giuricin is adj. professor in Transport Economics and Logistic at University Milano Bicocca in Italy

Published on

The opinions expressed in this article are those of the author and do not represent in any way the editorial position of Euronews.

When a train enters a tunnel at high speed, passengers do not think about the signalling equipment, communications networks and control systems guiding it. They simply trust that someone, somewhere, has made sure those systems are safe. That assumption is precisely what makes it dangerous when it turns out to be wrong.

ADVERTISEMENT


ADVERTISEMENT

As a transport economist, I have spent much of my career studying the infrastructure that allows people and goods to move. One lesson applies far beyond transport: a network is only as strong as the critical systems beneath it.

The invisible infrastructure

Europe’s digital infrastructure is no different. Every time a hospital retrieves a patient record, a port processes a shipment, a factory coordinates production or a railway operator manages traffic, an invisible digital chain is at work. Connectivity networks, data centres, cloud services and software now underpin almost every essential activity in our societies.

If these systems are compromised, the consequences do not remain digital. Trains can stop. Payments can fail. Public services can become inaccessible. Businesses can lose sensitive information. When the Swedish government confirmed earlier this year that a cyberattack on a heating plant had been carried out by a pro-Russian group with links to Russian intelligence, and when a coordinated assault on Poland’s power grid in December last year damaged critical control systems, the message was unambiguous: digital threats already reach our physical world.

The End of Innocence

For decades, European policy rested on a reasonable assumption: greater economic interdependence would produce prosperity and stability. Europe benefited enormously from open markets and global trade. We should not discard those achievements. But the geopolitical environment has changed.

Russia’s war against Ukraine taught Europe the hard way that strategic dependencies can be exploited. China’s trajectory is less blatant, but demands equal attention: its companies operate under laws that require cooperation with state intelligence services on demand, with no right of refusal and no independent judicial check. Chinese state-backed groups have conducted documented campaigns against European foreign ministries, cloud infrastructure and critical systems, in operations that appear designed to plant access capabilities for future use.

The lesson is not that international trade is dangerous. It is that not every dependency is commercially neutral.

Not all suppliers are equal

A supplier of office furniture and a supplier controlling essential components in a mobile network do not create the same risk. In sensitive digital systems, a supplier’s ownership, legal environment, governance and exposure to government pressure matter. So does its ability to access data remotely, provide software updates or influence equipment after installation.

Europe must stop pretending these factors are irrelevant to procurement. Trust in a supplier is not a matter of branding or diplomatic preference. It is more and more a security requirement.

Three tests for Europe

The revision of the EU Cybersecurity Act, tabled by the European Commission early this year, is the right vehicle for addressing digital supply-chain security. It is now up to the European Parliament and the Council to take it further. Three principles should guide their legislative work.

First, Europe needs coherence. Cyber threats do not stop at national borders inside the EU, yet the decision to build European telecom networks with high-risk suppliers from China, still is a decision every member state can make for itself. This weakens security and damages the Single Market. A vulnerability accepted in one Member State can have consequences for others.

Second, the framework must be proportionate. This means European digital networks should have the strongest safeguards where failure would cause the greatest harm. Core connectivity infrastructure deserves particularly rigorous protection because every other critical sector depends on it. With an understatement: it is better not to run our hospitals and nuclear powerplants on networks from suppliers we cannot trust for the full 100 percent.

Third, Europe must act with speed. A framework that takes years to become operational will be outpaced by technology and events. It is not Europe’s strong suit, but companies need legal certainty to invest and replace equipment. Governments need enforceable deadlines.

Security is not protectionism

Europe should remain open to investment and global cooperation, but only with trusted partners. US and Chinese firms are not strategically equivalent: American companies are legally separate from government and can challenge state decisions, while Chinese firms could be compelled to serve party-state objectives without independent judicial protection.

Europe should manage its reliance on US technology, not confuse it with dependence on high-risk Chinese vendors. This distinction matters because Europe cannot isolate itself from every trading partner at once. The goal is not to abandon openness, but to make it secure.

In transport, safety standards do not stop trains from crossing borders; they ensure they can do so safely. Europe’s digital economy should run on the same principle: open tracks, common safeguards and only trusted operators in the control room.

A secure single market is needed to have the size to be attractive to the investments, but at the same time maintaining the security to have a long-term development of the market.

Andrea Giuricin is Adjunct Professor of Transport Economics at the University of Milano Bicocca and CEO of TRA Consulting. He advises the World Bank and the United Nations.

Share.
Leave A Reply

Exit mobile version