Brussels – The world is changing rapidly and the European Union, which is pursuing an enlargement process that has gained new momentum, must recognise that threats do not stop at its current borders. This is particularly true in the field of cybersecurity, where the EU’s closest partners need to be integrated as soon as possible, not least to help protect the Union itself.
“Cybersecurity incidents are transnational and this means that, if we do want to keep the European Union safe, we also need to keep our partners safe,” warn Bojana Zorić, Policy Analyst for the Western Balkans and the Eastern Neighbourhood at the European Union Institute for Security Studies (EUISS), and her colleague Clotilde Bômont, Senior Policy Analyst for Cyber and Digital Technologies, in an interview with The New Union Post.
Drawing from their policy brief on integrating enlargement partners into EU digital and cybersecurity efforts, the two analysts explain why the European Commission has started to work more intensively on this field with candidate and potential candidate countries, including within the framework of the EU accession process. “If we stay as we are, but with the rise of cyber threats, this would be problematic.”
Given the “very high pace and intense environment” and the implications of traditional and hybrid warfare, this domain has become increasingly important “in a decade marked by a sharp rise in cybersecurity incidents” both across EU member states and among enlargement partners – from Ukraine and Moldova to the Western Balkans, also in those countries that are “not as advanced on the EU path,” Zorić notes.
All the cybersecurity risks
From a policy perspective, “we are already quite advanced” with the progressive adoption of EU cybersecurity frameworks and instruments – for example, the 5G Toolbox and the NIS-2 Directive – but in practice, “information sharing is the main problem,” Bômont explains. The reason is very simple, and this is also the case among current Member States and companies: “Mentioning that you have a vulnerability can expose you and make you a target.”
However, this approach is what fundamentally obstructs efforts to improve cybersecurity. “It is the weakest link that creates the vulnerability, and information sharing also improves awareness of the threat landscape,” the EUISS Senior Policy Analyst for Cyber and Digital Technologies stresses, highlighting the need to “work better and improve” both cooperation and “a broader sense” of the digital space in Europe that goes beyond EU borders.
In this sense, her colleague Zorić makes it clear that “there is a disbalance” between the uptake of key EU instruments for digital and cybersecurity and the operational need to work more closely with candidate countries. “We have seen that gradual integration is actually taking years,” with compliance differing even among EU member states – “it is the same with the enlargement partners.”
Moreover, “a new realm of complexities may arise if enlargement partners are not aligned with the key EU instruments,” the EUISS Policy Analyst for the Western Balkans and the Eastern Neighbourhood continues. For this reason, while gradual integration is currently ongoing, the European Commission has sought to incorporate these countries more closely and provide them with greater support.

Among the main obstacles, several countries are experiencing institutional constraints that are hindering political decision-making. “Institutional fragmentation, very complex governance, a lack of absorption capacity, and a lack of personnel to work in the cybersecurity sector” are among the unresolved problems cited by Zorić.
It is true that the EU can support candidate countries in addressing these challenges. Yet, some of these key obstacles remain within the realm of the partners’ national responsibility. This is why it becomes “increasingly complex to integrate them more closely from the outset,” she warns.
Bômont starts from here to analyse another crucial political element. “Policymakers do not necessarily have the technical skills and understanding” of technological and cybersecurity issues, which makes them “more hesitant to engage politically and put more resources into countering the risks.”
Industrial challenges regarding capabilities represent another critical element, as both in the EU and among enlargement partners “there are heavy dependencies” on foreign providers and cybersecurity solutions. While the EU is trying to limit the use of US and Chinese providers, concerns arise when, for example, a frontrunner in the EU accession process like Albania introduces an AI minister based on US-developed OpenAI technology.
As Bômont explains, “when you do not have the resources and the means” to develop in-house capabilities, “you go with the more efficient, cheapest, and more compliant and interoperable models” – not necessarily European ones.
Measuring success with EU enlargement partners
Looking at the short-term future – by 2030, optimistically – success in including enlargement partners within the EU’s cybersecurity perimeter can be measured through different parameters. As Zorić stresses, “a huge effort” should be made to try to work “more intensively” on different instruments made available and adapted to the specific needs of Ukraine, Moldova and the Western Balkans.
After concluding contribution agreements to strengthen cybersecurity resilience, work should be further strengthened on capacity building, addressing the complexity of the cybersecurity landscape, raising awareness, and tackling incidents. Although gradual integration is slow and it takes time to transpose EU regulations and directives into the national legislation of third countries, bringing them closer can undoubtedly represent a success.

However, whether that is enough “is questionable,” Zorić continues, warning that operational resilience in practice “may not be working as well as hoped, because there are still gaps that cannot be addressed.” Sometimes, this can also depend on the fact that enlargement partners cannot become members of some EU networks before they become full EU members – “and this is where actual information sharing and joint work takes place.”
The Union has become aware that, if it wants to protect its own cybersecurity space, it also needs to protect that of its non-EU European partners. Yet, if these enlargement partners are still outside the European Union by 2030, “some of these problems will still be there,” she warns.
On the contrary, if the EU succeeds in supporting the digital transformation of enlargement partners by 2030, “this would improve transparency in public services and increase cybersecurity of governmental systems overall,” her colleague Bômont notes.
In this sense, there is also the element of social resilience to consider. As the EUISS Senior Policy Analyst explains, “you need training in cybersecurity for advanced skills, but you also need to improve the population’s basic digital hygiene and threat awareness.”
In terms of industrial resilience, by extending frameworks and political mechanisms to enlargement partners, “we also extend our market here.” This would be of interest to both EU and non-EU European companies. In cybersecurity – and more generally in digital technologies – “the problem is scale and helping European companies to gain market shares,” Bômont concludes. Through a bigger and more integrated European market, “we will be able to create stronger alternatives to foreign models, solutions, and providers.”






























