EU Council adopts Hybrid Threats Regulation, mandating incident reporting for critical infrastructure operators within 24 hours
On 11 July the Council of the European Union formally adopted the Hybrid Threats Regulation. The landmark measure extends mandatory incident reporting beyond the digital domain covered by NIS2 to physical sabotage, supply chain interference and coordinated disinformation aimed at critical infrastructure. Operators in energy, transport, water, healthcare and financial infrastructure must now notify their national competent authority within 24 hours of detecting a hybrid incident. That is defined broadly as any coordinated action using physical, digital or informational means to disrupt service delivery. Member states have 18 months to transpose the Regulation into national law. In practice, organisations will need legal and technical help to classify incidents correctly, write compliant notifications under time pressure and keep an audit trail that shows a proportionate response. Organisations active in several member states will also face notification requirements in more than one jurisdiction.
Our advisory team helps you set up incident classification and 24-hour notification procedures that meet the new Regulation.
Europol Operation SHIELD dismantles luxury hotel TSCM eavesdropping network operating across six EU capitals
Europol announced on 13 July that Operation SHIELD, a 14-month joint investigation by Austria, Belgium, France, Germany, Italy and the Netherlands, has dismantled a sophisticated commercial eavesdropping network. The network had planted listening devices in boardrooms, suites and conference rooms at high-end hotels in Brussels, Vienna, Paris, Berlin, Rome and Amsterdam. Nineteen people were arrested in six countries. The network is believed to have worked for commercial intelligence clients, including at least two foreign state-affiliated entities. It used custom hardware hidden in standard room fittings such as power sockets, smoke detectors and picture frames, sending encrypted audio over the hotel Wi-Fi. The case began when a routine TSCM sweep by a security team accompanying a senior EU official found an anomalous device in a Brussels hotel. It confirms what specialist teams have long assessed: luxury hotels used for sensitive meetings are a prime target for technical eavesdropping. Sweep the room before any sensitive discussion in a hotel.
Before sensitive discussions, we carry out TSCM sweeps of hotel meeting rooms, suites and conference spaces.
ENISA publishes updated threat landscape for the maritime sector, flagging port cyberattack surge
On 11 July the European Union Agency for Cybersecurity (ENISA) published its updated maritime cyber threat report. It records a 67% year-on-year rise in cyberattacks on European port operators and maritime logistics companies in the first half of 2026. The main cause is ransomware groups exploiting unpatched operational technology in port management systems, alongside more state-sponsored reconnaissance aimed at vessel tracking and cargo manifest systems. The Netherlands, home to the Port of Rotterdam, Europe's largest, is named as a high-priority target because of its critical role in EU supply chain resilience. The report recommends mandatory OT security assessments for port operators, separation of IT and OT networks, and incident response exercises that simulate vessel diversion and cargo misrouting. If your business depends on maritime supply chains, plan for what disruption at a major hub port would do to you.
Our cyber security team assesses OT vulnerabilities and supports incident response for port, logistics and maritime operators.