Atlantic Council proposes Three Seas cybersecurity hub
A policy report calls for a regional cybersecurity center to protect Three Seas Initiative critical infrastructure and cloud investments across Central and Eastern Europe.
This Atlantic Council report is a policy paper, not an incident report. It argues that the Three Seas Initiative—a twelve-nation infrastructure and digitization effort spanning Central and Eastern Europe from the Baltic to the Adriatic and Black Seas—faces growing cyber risk as members expand energy, transport, and digital interconnectivity projects and adopt cloud services from providers like Microsoft, Google, and Amazon. The authors note the region's history of state-sponsored cyber espionage and reconnaissance targeting Baltic energy networks since 2015, attributed in prior reporting to suspected Russia-backed actors, and frame this as justification for enhanced regional defense.
The paper's core recommendation is the creation of a Three Seas Cybersecurity Center, a public-private hub modeled loosely on the Hague Security Delta, to provide operational security support, threat information sharing, international coordination, workforce development, and standardization of incident response and certification practices across member states. It proposes a phased rollout beginning with operational security, followed by incident response protocols, and finally long-term security planning and standardization.
No specific malware, threat actors with confirmed campaigns, exploited vulnerabilities, or technical indicators are described; the single cited historical incident (Baltic energy network targeting) is referenced only generally via a 2017 Reuters article. This is best characterized as strategic/policy content relevant to critical infrastructure resilience planning rather than an active threat disclosure.
Mentioned in this report
Source reporting: https://www.atlanticcouncil.org/in-depth-research-reports/report/collective-cybersecurity-for-the-three-seas
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free