High-Risk ICT Vendors and Critical Infrastructure: European Approaches

Visualization of artificial intelligence in big data, internet, icloud storage, data protection, hand holding mobile phone

Image credit: Yurii Maslak / Alamy


This paper compares the strategies used by Germany, Spain and the UK to manage risks from high-risk ICT vendors in critical national infrastructure.

Overview

This paper provides a critical analysis of how Germany, Spain and the UK manage the risks posed by high-risk ICT vendors in European critical infrastructure, offering essential insights for defence and security professionals seeking to understand and shape policy in this evolving domain.

Drawing on extensive research and interviews with key stakeholders, the paper highlights the divergent national strategies, the challenges of harmonising European policy and the persistent tension between economic interests and national security. It underscores the urgent need for a coherent, effective European approach to ICT supply chain security as geopolitical competition intensifies.

Key Recommendations

  • Develop a common European framework: Establish clear, sector-sensitive criteria for identifying and managing high-risk ICT vendors, balancing flexibility with consistency across member states.
  • Strengthen state capacity: Invest in dedicated national institutions to assess vendor risk, advise procurement authorities and monitor implementation.
  • Prioritise economic and strategic alignment: Ensure that economic considerations do not undermine security objectives by supporting the development of competitive European alternatives and aligning industrial strategy with security policy.
  • Enhance supply chain visibility: Improve the ability of governments and operators to map and manage dependencies at all levels of the ICT supply chain, reducing visibility gaps that hinder effective risk management.
  • Clarify messaging and policy scope: Distinguish between risks posed by different foreign vendors and ensure that high-risk vendor policies complement, rather than substitute for, broader cyber security and resilience measures.

This paper is essential reading for policymakers, industry leaders and security professionals navigating the complex intersection of technology, security and economic policy in Europe.

Register or log in to continue reading

Account creation is quick, free and gives access to all RUSI research and more

  • FREE account
  • One-time set-up
  • Easy to manage

WRITTEN BY

Jamie MacColl

Senior Research Fellow

Cyber and Tech

View profile

Dr Pia Hüsch

Research Fellow

Cyber and Tech

View profile

Natasha Buckley

RUSI Associate Fellow, Cyber and Tech

View profile

Sophie Williams-Dunning

Research Analyst

Cyber and Tech

View profile



Explore our related content