RIGA - Critical infrastructure is becoming a tool of geopolitical pressure, said Luca Tagliaretti, executive director of the European Cybersecurity Competence Centre, on Thursday at the CyberShield cybersecurity and technology forum.
He noted that, given the current geopolitical situation, it is important to take the developments affecting critical infrastructure seriously. Looking at Ukraine and the data, it is evident that 80 to 85 percent of cyberattacks are directed against civilian infrastructure - the energy sector, transportation, telecommunications, and public services.
The situation in Europe is not quite as dramatic, but a significant number of attacks are also being observed. More often than not, these are directed against government agencies, transportation, digital services, and financial services. According to Tagliaretti, these are fundamental elements of society, which is why they require special attention.
Tagliaretti noted that critical infrastructure is no longer merely a system that ensures the functioning of society, but is also becoming an instrument of geopolitical pressure. Therefore, it is essential to ensure its protection against threats that are no longer merely civilian in nature, but also relate to the defense sector.
He explained that the European Union's first step was to establish a level playing field and a common understanding of cybersecurity. This is ensured by two regulations that establish a common level of security in critical sectors and reinforce the understanding that cybersecurity is no longer merely a technical issue.
According to Tagliaretti, cybersecurity is an issue that must also be addressed at the company board level, by establishing the responsibility of board members and directors for system security. This helps establish a common terminology and policy framework. Furthermore, through the so-called omnibus approach, this framework is extended to various pieces of legislation, ensuring a unified regulatory approach.
The second key piece of legislation is the Cybersecurity Act. Tagliaretti emphasized that, for the first time, this Act extends responsibility not only to companies that must protect their own technology and servers, but also to companies that offer technologies and products on the European market. In his view, this will raise the level of protection and help ensure that protection extends beyond the borders of the European Union.
Speaking about the role of the European Cybersecurity Competence Centre in implementing this legislation, Tagliaretti noted that several funding mechanisms have been established to help the industry prepare for the requirements of the Network and Information Security Directive (NIS2) and the Cybersecurity Act.
One example is the Secure project, which focuses on the Cybersecurity Act. Several member states are participating in it, but companies outside these countries can also apply. Companies can use this opportunity to test their software and adopt best practices from other companies in the sector.
In addition to providing funding, the European Cybersecurity Competence Centre, together with the European Union Agency for Cybersecurity (ENISA), has developed technologies and systems to protect critical infrastructure, particularly in connection with the Cybersecurity Solidarity Act. Tagliaretti emphasized that when assessing risks and threats to various critical infrastructure sites, it is important to recognize that cyberattacks do not stop at borders.
Dmitrijs Nikitins, Chief Technology Officer at Latvian technology company Tet, noted at the forum that cyberattacks are becoming increasingly automated, so defense systems must be able to operate in a similar manner.
He explained that, unlike a human attacker, an artificial intelligence model can operate continuously and, following a failed attempt, use the information gathered to adapt its actions in the future. Nikitins also noted that many criminal organizations are attempting to adapt artificial intelligence models to exploit vulnerabilities.
At the same time, he noted that these tools are not yet fully automated, but development is moving in that direction. As companies increasingly adopt artificial intelligence, the potential attack surface is growing.
Nikitins pointed out that AI agents with extensive access privileges and MCP servers capable of performing various autonomous actions are already being used. If an attacker manages to gain control of such an agent, the consequences could be serious.
He explained that attackers can exploit devices that have not been updated for a long time on the network, automatically scanning the network, checking for various CVE vulnerabilities, finding an attack vector, and gaining initial access. Afterward, artificial intelligence agents can analyze the situation, find other agents with access to internal systems, and pass on the information and access rights they have obtained. As a result, a human may be involved only in the final stage of the attack, while the scale and speed of the attack increase significantly.
Nikitins pointed out that the cyber defense process currently involves many activities - network scanning, vulnerability identification and assessment, task creation, troubleshooting, and applying patches, all of which take time. On the attackers' side, however, these processes can occur continuously and automatically.
Therefore, in his view, the approach to cybersecurity must change, and the level of automation must be increased. Defense must operate continuously while maintaining human oversight.
Nikitins noted that results from 2025 show that the average time required to transfer gained access to another group decreased from eight hours to 22 seconds. This means that once one group gains access, it can be transferred almost immediately to other groups for further action.
He noted that tools are available on the market that can automate the detection, assessment, and remediation of vulnerabilities, but their use requires human oversight.
Based on data from Tet, Nikitins noted that an increase in the number of automated attacks has been observed on the network. This year, the number of automated denial-of-service (DDoS) attacks has increased by 30 percent, and there has also been a rise in the number of carpet bombing and large-scale DDoS attacks. According to him, this underscores the need to invest in cybersecurity and protect both the operator's and the customers' infrastructure.
Email data also shows an increase in the number of spam and malicious emails. Currently, 62 percent of all emails reaching a company's email gateway contain spam, phishing attempts, or malicious code. Similarly, the number of targeted phishing attacks-which are created using artificial intelligence-is on the rise.
Nikitins pointed out that artificial intelligence can sometimes know more about people and their data than even their closest relatives do, so organizations must be prepared for such attacks.
He also mentioned a sixfold increase in emergency patching incidents over the past year and a half. The risk of vulnerabilities being exploited has become so high that it is necessary to stop other work and install patches immediately. Whereas a company previously had only a couple of such incidents, there are now more than a dozen.
As previously reported, the CyberShield cybersecurity and technology forum is taking place in Riga on Thursday. The forum's program focuses on cybersecurity policy and resilience, the impact of artificial intelligence on security, as well as real-world cyberattacks and organizations' ability to respond to them in a timely manner.
2026 © The Baltic Times /Cookies Policy Privacy Policy