CERIS workshop on Strategic Autonomy for Critical Entities 

 

       ABOUT

The entire European society depends on the critical infrastructure for provision of essential services. Thus, its resilience is invariably one of the European Union’s security priorities. Operators regularly face challenges ranging from intentional attacks, technological accidents, natural disasters and stress from climate change, but as the hybrid attacks incidents are the fastest growing concern, the technological sovereignty and strategic autonomy of our critical infrastructure and entities have become the political necessity.

The European Union has increasingly emphasised the need to strengthen its capacity to act, decide, innovate, produce and protect without creating excessive dependencies on external actors. The 2023 European Economic Security Strategy translated this ambition into a risk-management framework focused on de-risking rather than decoupling. It identifies vulnerabilities stemming from strategic dependencies, technology leakage, economic coercion, foreign interference and/or critical supply-chain vulnerabilities.

Achieving strategic autonomy in this domain goes beyond technology alone. It requires a broader set of capabilities, policies and governance frameworks, including preparedness, mitigation, business continuity planning, cross-border and cross-sector coordination, collaboration and information sharing, data governance, interoperability and Schengen wide crisis response mechanisms. At the same time, strengthening Europe's capacity to develop, deploy and scale home-grown technologies can help ensure that critical systems remain secure, trusted, certified against European regulations and aligned with European values, standards and interests, as these will be embedded at their very core.

Equally important, strategic autonomy should not only protect Europe’s critical assets and essential services, but also serve as a catalyst for innovation, productivity and competitiveness by strengthening the resilience, technological capacity and strategic flexibility of the interconnected systems that underpin the European economy. In an era of cascading and hybrid threats, strategic autonomy stems not from the self-sufficiency of individual critical entities, but from the collective resilience and adaptive capacity of the interconnected systems that sustain Europe’s essential functions.

At the same time, strategic autonomy should be understood not as a path to isolation, but as the capacity to engage in trusted and interoperable networks of cooperation, supported by appropriate information-sharing and governance frameworks. These should enable joint risk assessment, preparedness, response and mitigation, while avoiding critical dependencies that could undermine resilience, security or sovereign decision-making. This principle is particularly important in areas requiring strong cross-border coordination, such as critical infrastructure resilience, disaster prevention, preparedness and response, and civil protection.

This workshop will explore what strategic autonomy means from various perspectives (social, market/supply chain, technological, legal/policy, etc.) in the context of cyber-physical critical entities resilience. Together we will examine the main dependency mechanisms affecting critical entities and infrastructure; technologies, products and services that may create strategic vulnerabilities; approaches to assessing and monitoring strategic dependencies; possible common assessment frameworks and indicators; policy implications, governance challenges and existing gaps in the overall European resilience architecture.