Skip to Content

European Economic and Social Committee

Hearing - March 3, 2026


Context: Hearing to gather experts perspectives ahead of the initiation of the EU's reform of its cybersecurity laws.


Summary

  1. European spyware scandals (Pegasus in Spain, Poland, Hungary) show that state use of hacking tools can undermine democracy, journalists, lawyers, and political opposition, while creating systemic cybersecurity risks for all citizens.
  2. The growing ransomware risk posed by spyware with hacking tools represents a serious threat to democratic processes, including the integrity and security of elections.
  3. Lessons from WannaCry and NotPetya demonstrate that stockpiling and exploiting vulnerabilities can backfire against states themselves, causing deep societal and economic harm; the EU should therefore adopt harmonised governmental vulnerability management rules similar to, but stronger than, the US approach.
  4. The EU needs common framework requiring Member States to carefully document proportionality and risk assessments before exploiting vulnerabilities, balancing law enforcement objectives against broader cybersecurity, ransomware, and democratic risks.
  5. Transparency and EU-wide harmonisation are essential: experts warn that without harmonised obligations, Member States will avoid stricter safeguards for fear of strategic disadvantage. High level transparency reporting should therefore become a rule-of-law indicator, including disclosure on vulnerability capabilities using frameworks such as CVSS.
  6. ENISA’s mandate should be reinforced to monitor Member States’ compliance with vulnerability management and transparency obligations, enabling the Commission to assess whether offensive cyber capabilities are proportionate, especially in countries with rule-of-law concerns.


Detailed intervention 

  • Thank you for inviting me to speak.
  • I am the Director of Data Rights. Data Rights is European non-profit organisation, focussed on how data protection and cybersecurity impact traditional human rights. Our current focuses are dual use technologies, as well as the enforcement of interoperability.
  • DR is one of the founding members of a coalition of European NGOs supporting spyware victims, primarily journalists, lawyers and MEPs. It is called the PEGA coalition.
    • I will be Talking from the perspective of our work on hacking tools and spyware
  • This intervention focuses on the mandate of ENISA and the more general need for EU level requirements for governmental vulnerability management.

 

I) Context

In the last 6 years Amnesty International and the CitizenLab have repeatedly showed that European states are using potent hacking tools against their citizens. Be it Pegasus launched on the attorney of Catalan Politicians, Spanish open source voting tools researchers, anti-corruption investigative journalists in Poland and Hungary, or even Polish MEP Brejza that used to be in the opposition party while the PIS was in power.

In Poland, Pegasus was used by law enforcement to extract 10 years of his communications. Then his messages were reorganised and merged to create a new narrative, that was sent to public TV channels for a smear campaign.

Poland now found that this use of Pegasus was illegal. We need to make sure this cannot happen again. Cybersecurity rules can help if they evolve.

Let’s take a step back for a second. It is after the NSA’s hacking tools were stolen and launched on the general public through the Wannacry and NotPetya crises, that the US reformed its management of vulnerabilities. For the record, French industrial player Saint Gobain lost 250 million € in sales due to NotPetya halting its production sites (1). Wannacry left hospital patients shut out from operation rooms.

These crises made the US realise that stockpiling and using completely disproportional hacking tools was going against it’s own interests and the safety of its citizens.

Now back to the present: As a Citizen Lab spokesperson pointed out during a LIBE hearing in May 2025 when talking about spyware encompassing hacking tools, “we might be about to see a major ransomware crisis or a general cybersecurity crisis for Europe“.

Indeed, technical costs for the private sector to protect citizens on the cybersecurity risks created by states being sold or exploiting vulnerabilities are high. More generally, hacking tools found in spyware have become a threat to democracy and elections.

 

II) Needs for the EU

In June 2021, the German Constitutional Court delivered an opinion about the use of IT vulnerabilities by law enforcement. It stressed that the ransomware risk on the population needs careful balancing, given that most fundamental rights are impacted by IT nowadays. Therefore, to exploit vulnerabilities authorities must document balanced assessments of risks.

The European Union must take the same path as the US and create harmonised requirements for states to ethically manage vulnerabilities, in order to ensure that democratic resilience is no longer thrown under the bus of short term political gains.

To be clear - All specialists we spoke with stress that rules must be harmonised EU-wide, otherwise each state will feel they are bending the knee compared to others. Most importantly, rules must be EU-wide so that transparency requirements become an additional rule of law indicator. This would support EU citizens in countries that have temporarily turned their back against democratic rules.

Indeed, we see an important parallel on spyware cases. Right now, EU countries with the most egregious spyware scandals tend to be countries with poor rule of law. As a result, the EU needs to create rules that adapt to the ups and downs of democracies. Which is why rules will need to require high level transparency reporting and some information on capabilities, on the back of the Common Vulnerability Scoring System (CVSS).

 

III) Pitfalls

In fact, the EU can do better than the US. Reports from the US on how it is upholding its vulnerability management framework are clear - authorities are not upholding their public reporting requirements. Yet, these requirements are fundamental to ensure transparency and trust.

The EU has a strong card to play here, thanks to ENISA. ENISA should be mandated to monitor future transparency requirements for Member States. This would enable it to monitor transparency and the adequacy of the potency of vulnerabilities used, vis-à-vis the rule of law level of the country. For instance, a country with low rule of law records should not be allowed to use vulnerabilities beyond a certain CVSS threshold, as it might be using vulnerabilities for political reasons rather than strict law enforcement purposes.

By way of conclusion, To put it simply - ENISA should see its mandate reinforced to prepare for its future monitoring of states’ vulnerability management. So that it can become a tool in the tool box of the European Commission, when taking measures on rule of law failings.

 

Thank you very much.

 

===

(1) L’impact financier de l’attaque au ransomware menée en juin contre les entreprises au niveau mondial vient d’être très concrètement chiffré par l’industriel français Saint-Gobain sur son exercice 2017. Il approche 250 millions d’euros sur ses ventes et 80 millions d’euros sur son résultat d’exploitation.” See Gros M., “Saint-Gobain évalue à 250 M€ les dégâts liés à l’attaque NotPetya” Le Monde Informatique (01 August 2017). Available at https://www.lemondeinformatique.fr/actualites/lire-saint-gobain-evalue-a-250-meteuro-les-degats-lies-a-l-attaque-notpetya-68955.html