Skip to content
The ColumnEssay· No. 1341

ESSAY: Ukraine's Cyber War Enters the European Age — the Cybersecurity Reserve

In June 2026, Ukraine crossed a decisive threshold in the digital war that Russia has imposed on it for more than four years: the Ukrainian parliament ratified an agreement giving Kyiv access to the European Union Cybersecurity Reserve. This mechanism, managed by ENISA — the European Union Agency for Cybersecurity — and established under the European Cyber Solidarity Act, now a

Premium reading
MadMax
Key takeaways
  1. In June 2026, Ukraine crossed a decisive threshold in the digital war that Russia has imposed on it for more than four years: the Ukrainian parliament ratified an agreement giving Kyiv access to the European Union Cybersecurity Reserve. This mechanism, managed by ENISA — the European Union Agency for Cybersecurity — and established under the European Cyber Solidarity Act, now a
  2. ESSAY: Ukraine's Cyber War Enters the European Age — the Cybersecurity Reserve
  3. Introduction: when digital warfare demands digital alliances
Transparency

Facts, quotes, and cited links remain in the body. Interpretations are framed as analysis or opinion according to the format.

ESSAY: Ukraine's Cyber War Enters the European Age — the Cybersecurity Reserve

Introduction: when digital warfare demands digital alliances

Unprecedented access to the European cyber arsenal

In June 2026, Ukraine crossed a decisive threshold in the digital war that Russia has imposed on it for more than four years: the Ukrainian parliament ratified an agreement giving Kyiv access to the European Union Cybersecurity Reserve. This mechanism, managed by ENISA — the European Union Agency for Cybersecurity — and established under the European Cyber Solidarity Act, now allows Ukraine to request the intervention of EU-certified private experts in the event of a major cyberattack against its critical infrastructure.

This is not a declaration of principle or a symbolic memorandum. It is an operational mechanism: if a large cyberattack strikes Ukrainian government networks, the electrical grid, or hospitals, Kyiv can now trigger emergency European assistance, benefit from support in containing and neutralizing the attack, assess threats, and restore systems as quickly as possible. According to Militarnyi, the EU has completed all required legal procedures, and the mechanism is officially in force.

The Cybersecurity Reserve: anatomy of a novel mechanism

The Cyber Solidarity Act as legal framework

The European Cyber Solidarity Act — adopted by the EU to strengthen collective incident response capabilities — is the legal framework within which the Cybersecurity Reserve sits. This legislative text provides for the creation of a network of Security Operations Centers (SOCs) across Europe, the establishment of a reserve of trusted private providers, and mechanisms for information sharing and mutual assistance between member states.

Integrating Ukraine into this arrangement represents an extension of the European cyber solidarity perimeter beyond EU borders. It recognizes that the Russian cyber threat does not respect geographic or political boundaries — and that defending Ukraine digitally contributes directly to the security of the entire European digital space.

What access to the Reserve changes in concrete terms

Before this agreement, Ukraine had to manage its cyber crises with its own resources — often limited, often saturated — or seek ad hoc bilateral assistance from partners such as the United States, the United Kingdom, or the Baltic states. From now on, a formal and pre-activated mechanism grants access to a pool of private cybersecurity providers certified by ENISA.

The practical difference is considerable. Searching for cyber experts in an emergency during an active attack is like looking for firefighters during the fire. Having a pre-activated Reserve mechanism, with already-vetted providers and established response protocols, means having firefighters on site before the flames begin. For Ukraine, which has endured continuous cyberattacks for years, this time difference can mean the difference between containing an attack and suffering a national catastrophe.

Russian cyberattacks: a war running parallel to the trenches

The documented scale of Russian digital aggression

The cyberwar that Russia is waging against Ukraine is the longest and most intense ever documented in the history of modern conflicts. According to available data, Ukrainian intelligence services (SSU) and the American Federal Bureau of Investigation (FBI) exposed in June 2026 a Russian cyber-espionage campaign targeting email accounts of government officials, military personnel, politicians, and activists in Ukraine, Europe, and the United States.

This campaign is sophisticated in its methods: sending SMS messages impersonating official support services, tricking users into revealing their passwords, and often targeting victims in the early hours of the morning when vigilance is reduced. Dozens of government officials in Romania, Greece, Bulgaria, and Serbia were also targeted — a concrete illustration of the transnational reach of this Russian digital war.

The Jaguar Land Rover precedent: when cyberwar hits the economy

In August 2025, an attack attributed by British and American investigators to Russian hackers struck automaker Jaguar Land Rover. The result: five weeks of complete production shutdown in plants across England, Brazil, China, India, and Slovakia, a cost of $350 million to the company and $2.5 billion to the British economy according to United24 Media — making it the most expensive cyberattack in UK history.

This case illustrates a reality that British Defense Secretary Dan Jarvis stated bluntly: hostile countries have understood that "the most effective way to attack is not through direct military confrontation, but by silently hollowing out the economy from within." Russian cyberwarfare is not only a war against Ukrainian military networks — it is a war against the economic fabric of all the democracies supporting Kyiv.

Ukrainian Cyber Forces legislation: a delicate legislative undertaking

A bill pending since October 2025

Paradoxically, at the very moment Ukraine was gaining access to the European Reserve, its own legislative framework for cyber operations remained unfinished. The bill establishing Cyber Forces as a separate branch of the armed forces had been approved in a first reading in October 2025, then revised in March 2026 to include provisions for active cyber defense, incentives for successful operations, and the creation of a civilian resistance component.

But in June 2026, a second reading had still not taken place, despite parliamentary officials declaring the text "finalized." This legislative paralysis has practical consequences: Ukrainian cyber units are already operating — conducting cyber intelligence and military cyber operations — but doing so without formal legal status, in a legal grey zone that complicates command, budgets, and accountability.

The problem of inter-institutional competition

Member of Parliament Oleksandr Fediienko identified a structural problem in the Ukrainian approach to cyberwarfare: Ukrainian institutions sometimes compete in cyberspace rather than working together against the enemy. The intelligence services (SSU), the armed forces, and the Ministry of Digital Transformation sometimes operate parallel cyber capabilities with mandates and priorities that can overlap or conflict.

Creating unified command under the direct authority of the Commander in Chief of the Armed Forces — which the Cyber Forces bill provides for — is precisely the structural reform that would eliminate these duplications and internal friction. While waiting for the law's passage, access to the European Cybersecurity Reserve at least provides an external emergency resource that partially offsets internal organizational weaknesses.

NotPetya and the legacy of Ukrainian cyberwarfare

Ukraine as a global testing ground

The history of Russian cyberwarfare against Ukraine predates the large-scale invasion of 2022 by years. The attacks on the Ukrainian electrical grid in 2015 and 2016 were the first cyberattacks to physically cut electricity to civilian populations. The NotPetya attack of 2017 — initially deployed against Ukrainian companies via accounting software — spread worldwide and caused more than $10 billion in global damages.

This legacy is crucial for understanding why access to the European Reserve matters: Ukraine is not a naive or helpless state in the face of the Russian cyber threat. It has developed significant defensive expertise over a decade, often acquired under fire. But that expertise, however real, is no longer sufficient against the scale of Russian attacks in 2025–2026, which combine sophisticated espionage operations, unique ransomware, and large-scale digital disinformation campaigns.

The multiplication of attacks since 2022

Since the start of the full-scale invasion in February 2022, Russian cyberattacks against Ukraine have taken on a new dimension: they are coordinated with ground and air military operations, targeting Ukrainian command and communication systems before major offensives, or civilian infrastructure in parallel with bombardments. Attacks on Ukrainian government networks, energy operators, and transportation systems have become nearly daily.

In April 2026, Reuters revealed that Russian hackers had compromised more than 170 email accounts belonging to Ukrainian prosecutors and investigators responsible for combating corruption and identifying Russian agents — a targeted intelligence operation of surgical precision aimed at the most sensitive institutions of the Ukrainian state. It is against that backdrop of continuous and sophisticated attacks that access to the European Reserve must be evaluated.

ENISA and the architecture of European cyber defense

The European Cybersecurity Agency as a pivot

ENISA — the European Union Agency for Cybersecurity — is the central institution managing the Cybersecurity Reserve at the EU level. Established in 2004 and with a mandate substantially strengthened by the Cybersecurity Act of 2019 and the more recent Cyber Solidarity Act, ENISA now plays a role for cybersecurity comparable to what NATO plays for conventional defense: it provides a common framework, shared standards, and mechanisms for collective solidarity.

Integrating Ukraine into this system represents a qualitative leap in the cyber relationship between Brussels and Kyiv. It is no longer merely ad hoc assistance or occasional bilateral support — it is integration into the European institutional architecture of cybersecurity, with the rights and obligations that entails in terms of information sharing and operational cooperation.

Certified private providers: the backbone of the Reserve

The Cybersecurity Reserve relies on a network of private cybersecurity providers certified by ENISA — specialist firms capable of responding in emergencies in areas including incident response, forensic analysis, remediation, and restoring compromised systems. These providers are pre-selected, vetted, and prepared to intervene according to pre-established protocols within tight timeframes.

For Ukraine, accessing this network means being able to mobilize within hours — not weeks — dozens of experienced specialists who have already worked on the most sophisticated threats documented in Europe. It is a significant cyber force multiplier — all the more so because large-scale Russian cyberattacks are rarely simple events: they combine multiple vectors, customized malware, and zero-day exploits that require precisely this kind of specialized expertise available at short notice.

Russia in cyberspace: a hostile power to be contained

APT28, Fancy Bear, and the gallery of Russian groups

Western intelligence services have documented numerous hacker groups linked to Russian services. The best known is APT28 — also known as Fancy Bear — linked to the GRU, Russian military intelligence. This group has been accused of hacking the American Democratic National Committee ahead of the 2016 elections, running campaigns against NATO targets, and exploiting standard Internet routers to steal passwords and sensitive data from allied countries providing military support to Ukraine.

The British National Cyber Security Centre had issued specific warnings about APT28 well before the Jaguar Land Rover attack — and yet that attack happened. This painful finding illustrates a fundamental challenge of defensive cybersecurity: perfect prevention is impossible against adversaries with state resources, time, and strategic motivation. The response must therefore combine prevention with rapid response capability — which is precisely what the European Reserve specifically provides.

The digital supply chain as an attack vector

The NotPetya attack of 2017 exploited a vulnerability in a widely used Ukrainian accounting software package — M.E.Doc — to spread massively. This so-called software supply chain attack technique is one of the most formidable because it strikes not the final target but its software suppliers or partners, who are often less well protected.

In 2025–2026, this tactic became more sophisticated: Russian services now target legitimate software updates, enterprise collaboration platforms, and cloud service providers used by Ukrainian institutions or their partners. Responding to this type of attack requires precisely the combination of specialized private expertise and coordinated inter-state response that the European Cybersecurity Reserve enables.

The strategic stakes of Euro-Ukrainian cyber integration

A signal of European integration beyond declarations

Ukraine's access to the European Cybersecurity Reserve is a concrete act of integration that precedes formal EU membership — a model that could be reproduced in other domains. It sends a strong diplomatic signal: Brussels treats Ukraine as a full security partner, not as an accession candidate waiting in the wings.

This signal has geopolitical implications beyond cybersecurity: it reinforces Ukraine's legitimacy as a European state integrated into collective security structures, and creates a precedent for other operational partnerships with non-member states. Moldova, Georgia, or other states potentially targeted by Russian cyber operations could benefit from similar agreements.

The question of data and digital sovereignty

Integration into the European Reserve nevertheless raises complex questions about Ukrainian digital sovereignty. When European private providers intervene in Ukrainian computer systems — even with Ukrainian consent and under Ukrainian supervision — this creates flows of sensitive data and access to critical systems that require rigorous governance frameworks.

ENISA and the Ukrainian government have established protocols to frame these interventions, but the question of confidentiality for Ukrainian government data shared with foreign private providers deserves continuous attention. That is not a reason to refuse access to the Reserve — the operational benefits far outweigh the risks — but it is a dimension that the architects of this agreement have had to, and will need to keep managing carefully.

The implications for critical infrastructure defense

Power grids, hospitals, transport: priority targets

The European Cybersecurity Reserve specifically covers attacks against government networks, websites, power grids, and "other critical infrastructure." For Ukraine, these three categories correspond exactly to the preferred attack vectors of Russian services: attacks on the Ukrainian power grid in winter 2022–2023, in 2024, and in 2025–2026 deprived millions of civilians of heating and electricity.

Having access to emergency cyber assistance for these infrastructures is not merely a national security issue — it is a direct humanitarian one. An uncontained attack on the Ukrainian power grid in winter can mean deaths from hypothermia among the most vulnerable populations. The European Reserve therefore indirectly contributes to protecting civilian life in Ukraine — an argument that deserves to be made well beyond technical cybersecurity circles.

Civil-military coordination in cyber defense

One of the innovations in the pending Ukrainian Cyber Forces bill is the creation of a civilian cyber resistance component. This provision acknowledges that cyber defense cannot be a purely military affair: civilian infrastructure is a priority target, and its defense requires close coordination between civilian operators and the armed forces.

Access to the European Reserve fits this logic: it creates a bridge between European cybersecurity capabilities — primarily developed in the private sector — and Ukraine's cyber defense needs, which are both military and civilian. It is a hybrid architecture matching the hybrid reality of modern cyberwarfare, where the distinction between military and civilian targets is deliberately blurred by the aggressor.

Toward a broader cyber defense agreement

Beyond the Reserve: toward systemic integration

Access to the Cybersecurity Reserve is an important step but not a destination. For the Euro-Ukrainian cyber collaboration to reach its full potential, several complementary developments are needed: the adoption of the Ukrainian Cyber Forces legislation, Ukraine's full integration into the European network of Security Operations Centers (SOCs), and the development of real-time threat intelligence sharing protocols between Ukraine and its partners.

These developments fit within a broader frame: the process of Ukraine's accession to the EU, which involves the progressive transposition of the full body of European law into Ukrainian legislation — including the directives on the cybersecurity of network and information systems (NIS2). Every step toward legislative harmonization is a step toward more robust collective defense.

The Ukrainian model as inspiration for NATO

The Ukrainian cyber experience has become a reference in Western defense circles. NATO's Cooperative Cyber Defence Centre of Excellence in Tallinn has incorporated lessons drawn from the Ukraine war into its operational doctrines. Emergency cyber procedures developed by Ukraine under Russian fire — rapid triage, isolation of compromised systems, maintenance of degraded operating capabilities — are being studied by armies that have never faced a state-level cyberattack of this scale.

In that sense, Ukraine's access to the European Reserve is not only a benefit for Kyiv: it is an investment in transferring cyber knowledge to Europe. European experts who intervene in Ukraine under this mechanism will learn as much as they teach — and will return home with practical experience of cyberwarfare that no theoretical exercise can replicate.

The limits of cyber defense: what the Reserve cannot do

A reactive response, not total prevention

Useful as it is, the Cybersecurity Reserve mechanism is fundamentally an incident response tool — it intervenes after an attack has begun, not before. Preventing cyberattacks remains the responsibility of Ukrainian cybersecurity teams, internet service providers, and critical infrastructure operators who must keep their systems updated, reduce attack surfaces, and apply proper security practices.

No emergency assistance mechanism can compensate for fundamentally vulnerable systems or deficient security practices. The European Reserve is a safety net — but a net does not replace solid rails and an attentive conductor. Ukraine will need to continue investing massively in training its own cyber experts, upgrading its digital infrastructure, and building a security culture within its institutions.

The question of funding Ukrainian cybersecurity

Upgrading Ukrainian cyber capabilities requires considerable financial investment — for training experts, acquiring modern security software and equipment, and building functional security operations centers. These investments must be partially funded by Western partners, on equal footing with weapons deliveries and direct budgetary support.

The EU's cyber support program for Ukraine includes capacity-building components, but their scale remains insufficient relative to needs. If access to the Reserve is a major step forward, investing in Ukraine's indigenous capabilities remains the most important long-term task — the one that will allow Ukraine to defend its cyberspace autonomously and sustainably, whether in wartime or peace.

What this means for the future of digital security in Europe

Ukraine as a model for vulnerable states

The agreement between Ukraine and the EU on the Cybersecurity Reserve creates a precedent that could be extended to other states exposed to Russian cyber operations. The Baltic states — Estonia, Latvia, Lithuania — have already developed robust cyber capabilities within NATO and the EU. Poland, Finland, and Sweden have also invested massively in their cyber defense.

For more vulnerable states — Moldova, Georgia, and in time other countries in the European eastern neighborhood — the Ukrainian agreement could serve as a model. A wider network of states integrated into the European Reserve would create a collective cyber defense perimeter that would significantly reduce opportunities for Russian attacks with regional impact.

The digital arms race and its ethical implications

The Russian-Ukrainian cyberwar also has a dimension that must be named: it is fueling a digital arms race whose ethical and legal consequences are still poorly defined. The offensive cyber capabilities developed in this conflict — on both sides — are weapons that can have devastating effects on civilian populations when they target essential infrastructure.

International humanitarian law is adapting slowly to this reality. The principles of proportionality and distinction between military and civilian targets must apply to cyber operations — but their practical application in a conflict as intense as the Russian-Ukrainian war remains unclear and contested. The European Reserve is a defensive and humanitarian response — it is not an offensive weapon. That distinction must be maintained clearly.

The offensive dimension of the Cyber Reserve — between defense and retaliation

Cyber defense or cyber offense — the blurred line Ukraine navigates

The Ukrainian Cyber Reserve is officially presented as a defensive tool — protecting critical infrastructure, detecting intrusions, responding to incidents. But in the context of war, the boundary between defense and offense in cyberspace is particularly permeable. Units maintaining the resilience of Ukrainian computer systems could, with the same tools and skills, conduct offensive operations against Russian infrastructure.

Security reports document Ukrainian cyber operations against Russian targets — disruptions of transportation infrastructure, infiltrations of military communication systems, compromise of Russian government databases. These operations, attributed to groups like IT Army of Ukraine or to actors linked to Ukrainian intelligence services, demonstrate that Ukrainian cyber capability is not purely defensive. The Cyber Reserve, with its 115 profiles of Russian malware and its accumulated expertise, is a potential platform for operations in both directions.

The legal and strategic implications of offensive cyber operations

Offensive cyber operations in wartime raise complex legal questions that international law has not yet fully resolved. When a cyberattack disrupts civilian infrastructure — even in an aggressor country — can it be justified by the same principles that authorize military strikes against dual-use installations? The Tallinn Manual, developed by international cyber law experts, attempts to answer these questions — but its conclusions remain contested.

For Ukraine, the practical answer is proportionality: targeting Russian military infrastructure in cyberspace the same way it targets them with drones and missiles. This doctrine is defensible. And the Cyber Reserve, with its expertise on OT (Operational Technology) systems — the industrial control systems used in power plants, pipelines, and transportation infrastructure — possesses exactly the capabilities needed for such operations.

The future of cooperation: toward a Euro-Ukrainian cyber shield

The next steps of Ukraine-ENISA cyber integration

The agreement on the Ukrainian Cyber Reserve with ENISA is a starting point, not a finish line. The logical next steps of this integration include broader access to threat intelligence from ENISA and its national partners, joint exercises simulating major cyberattacks, and potentially a bilateral cyber defense agreement that goes beyond the ENISA framework to include mutual response commitments in the event of a major attack.

In the perspective of Ukraine's accession to the EU, building this cyber cooperation infrastructure is as important as legislative harmonization or judicial reforms. An EU member state that is not integrated into European cyber defense systems is a vulnerability for the entire Union. Building that integration now, during the war, while Ukraine is developing its expertise at an exceptional pace, is far more effective than waiting for formal accession.

The Ukrainian model as a template for other vulnerable countries

What Ukraine is building — a civilian Cyber Reserve integrated into a national cyber defense architecture, connected to European intelligence-sharing systems, with a documented library of adversary attack methods — could serve as a model for other countries facing persistent state-level cyber threats. The Baltic states, exposed to the same Russian actors, have already developed advanced cyber defense capabilities. Moldova, Georgia, other post-Soviet states targeted by the same Russian techniques could benefit from an adaptation of the Ukrainian model.

ENISA has a natural role to play in this dissemination — by standardizing methods, facilitating expertise sharing, and creating a European network of cyber resilience of which the Ukrainian experience is the centerpiece. A Europe that learns from this war, that transforms hard-won lessons into lasting institutional capabilities — that is the Europe that will be able to resist future hostile state cyber actors.

Conclusion: a cyber agreement for a total cyberwar

A milestone in Euro-Ukrainian security integration

Ukraine's access to the European Cybersecurity Reserve marks a significant moment in the history of the collective Western response to the Russian cyber threat. It is not spectacular like the announcement of a tank or missile delivery, but it is potentially just as important: a digital defense infrastructure that can make the difference between a contained cyberattack and a national infrastructure catastrophe.

Europe took too long to understand that the Russian cyberwar against Ukraine was its war too. With this agreement, it is beginning to act accordingly. Much remains to be done — the Ukrainian Cyber Forces law still needs to be adopted, investments reinforced, protocols refined — but the direction is right. And in a war where every week counts, a right direction is already a great deal.

The cyber war does not end with the physical war

We must prepare for an uncomfortable reality: the Russian cyberwar against Ukraine and its partners will not stop with an eventual ceasefire on the ground. Russian offensive cyber capabilities are a permanent infrastructure, not a tactical response to a limited conflict. Even in "peacetime," Russia will continue to use its cyber capabilities against states that have sanctioned it, supported Ukraine, and documented its war crimes.

The European Cybersecurity Reserve, the integration of Ukraine into the EU's cyber architecture, and the final adoption of the Ukrainian Cyber Forces are therefore investments in the long-term security of the European digital space — regardless of how military operations on the ground evolve. It is in that durable perspective that their importance must be evaluated.

By Maxime Marquette, columnist

Columnist's transparency note

My sources and their scope

This essay rests on open sources published in June 2026: the Militarnyi article documenting Ukrainian access to the European Reserve, the SSU-FBI report on the Russian cyber-espionage campaign, the United24 Media investigation into the attack on Jaguar Land Rover, and sources documenting the European Cyber Solidarity Act. I have no technical background in cybersecurity — my analysis is that of a generalist striving to contextualize technical developments within a broader geopolitical frame.

Some assertions regarding attack attributions — notably regarding Jaguar Land Rover — rest on journalistic investigations (New York Times) rather than formal criminal convictions. Attributions in cyberwarfare are complex and contested. I present them as documented and plausible, not as absolute certainties.

My limits and biases

My analysis favors Euro-Ukrainian cyber integration, consistent with my pro-Ukrainian editorial position. I acknowledge that the digital sovereignty questions raised by this agreement would merit deeper analysis by specialists in international law and digital governance. I am a columnist, not a jurist — and cybersecurity is a domain where the boundary between political analysis and technical expertise is easily crossed.

I also acknowledge that the Ukrainian offensive cyberwar — whose scale is documented but whose details are largely classified — is not addressed in this essay. That choice is deliberate: the subject of the piece is cyber defense, not offense. But intellectual honesty requires noting that Ukraine is not a purely passive actor in cyberspace — that is a reality that must be mentioned.

Sources

Primary sources

Secondary sources

Get the geopolitics analyses

Conflicts, powers, alliances: the MadMax thread without the noise.

Cite this article

Maxime Marquette (2026). ESSAY: Ukraine's Cyber War Enters the European Age — the Cybersecurity Reserve. MadMax. https://mad-max.co/en/article/essai-la-cyberguerre-ukrainienne-entre-dans-l-age-europeen-la-reserve-de-cyberse

How does this piece make you feel?
MM
Maxime Marquette
Independent columnist

Maxime Marquette writes most of the analyses and columns published on MadMax — geopolitics, technology, and current events, no filler.

The Newsletter

Enjoyed this piece? Get the next one.

One chronicle a week, straight to your inbox. No noise.

Comments

0 / 2000

Be the first to weigh in.

This article was generated with AI assistance, under human supervision.

Essay4359 words5 min read