CYBERSEC 2025
On June 11–12, the 20th edition of the Cybersec conference took place in Krakow, Poland. With sessions in both Polish and English, the event brought together an impressive mix of cybersecurity professionals, public officials, military representatives, and industry analysts. But what stood out this year was a strong sense of shared purpose: building a resilient, secure, and innovative digital Europe.
While familiar topics such as identity and access management (IAM), critical infrastructure protection, business use cases for digital wallets, and threat intelligence were discussed in depth, the conference also emphasized broader strategic goals. In particular, several sessions explored the role of cybersecurity in supporting European digital autonomy, cooperation, and integration.
Layers of Control, or Lack Thereof
One of the most compelling presentations was given by Professor Paul Timmers. It centered on a slide titled "Who Controls the Digital Stack?" which provided a layered breakdown of digital technologies ranging from physical resources to advanced AI. The stack includes:
- Data & Artificial Intelligence
- Software
- Cloud Infrastructure
- Internet of Things (IoT) & Devices
- Networks
- Chips
- Raw Materials, Energy, and Water
For each layer, the key countries and companies currently in control were laid out. The results were telling. The United States leads in AI, software, and cloud. China holds significant ground in AI, network technology, raw materials, renewable energy, and IoT. Europe, in contrast, plays a limited role.
Two key points stood out:
- Over 80% of Europe’s digital technologies are imported.
- 70% of AI language models originate in the US, 20% from China, and 5% coming from Europe.
This level of dependency introduces systemic risks. Not just for innovation but for operational resilience and long-term economic competitiveness. Without viable alternatives, Europe remains in a position of reliance across nearly every digital layer.
These concerns were echoed at EIC 2025 in Berlin last month, where digital sovereignty, cloud control, and vendor lock-in were recurring themes across sessions and side conversations.
My colleague Mike Small has written extensively on the topic: Sovereign Cloud Geopolitical Risks, Microsoft’s Cloud Sovereignty Promises: Progress or Patchwork?, and AWS’s EU Sovereign Cloud: A Step Toward European Autonomy or a Strategic Compromise?
EuroStack: A Strategic Response
Among the many proposals discussed at Cybersec, the EuroStack initiative stood out as a thoughtful and technically grounded vision for Europe’s digital future. Rather than aiming to reinvent the wheel or rebuild the entire technology stack from scratch, EuroStack presents a modular and collaborative framework designed to reinforce European capabilities where they matter most.
The initiative calls for the creation of a common digital stack, one that enables the development and deployment of impactful services, supports the growth of AI, and encourages the formation of federated data spaces. At the same time, it emphasizes leadership in emerging technologies and seeks to unlock innovation through strategic procurement and investment, without adding bureaucratic overhead.
What makes EuroStack particularly compelling is its refusal to fall into familiar traps. It’s not about isolation or techno-nationalism. Nor is it a call to duplicate every layer of the digital stack in-house. Instead, EuroStack is deliberately positioned as a distributed and cooperative effort—flexible, targeted, and realistic. Already, the initiative is drawing support from a growing constellation of European companies, public institutions, and research centers.
With a proposed €300 billion investment over the next decade, EuroStack aims to build a sovereign, values-driven digital ecosystem that empowers European innovation, strengthens strategic autonomy, and ensures long-term economic, social, and environmental resilience.
A Gathering of Builders
A major challenge for EuroStack is the EU’s internal fragmentation—different countries face different economic realities, digital capabilities, and political priorities. Funding gaps and uneven infrastructure make coordinated progress difficult. Without strong alignment and sustained investment, the initiative risks becoming a fragmented patchwork rather than a cohesive strategy. The challenge is no longer about resources, it’s about coordination, focus, and execution.
Throughout the event, vendors from Poland, Germany, Slovakia, the Czech Republic, and other European countries showcased their innovations. From IAM platforms and secure communications to post-quantum encryption and industrial cybersecurity, the diversity of expertise on display underscored Europe’s hidden strengths.
What Europe may currently lack in digital dominance, it more than makes up for in capability, creativity, and collaboration. Cybersec 2025 made that visible.