European cyber resilience starts with trusted identity: Q&A with ECSO’s Cristian Tracci

Yubico recently joined the European Cyber Security Organisation (ECSO), Europe’s largest cross-sector cybersecurity community. As AI fuels an unprecedented 200% surge in automated phishing and social engineering attacks across Europe, Yubico and ECSO are establishing a phishing-resistant digital identity baseline to defend European enterprises, public authorities, and critical infrastructure against a rapidly evolving threat landscape. 

This strategic partnership took center stage at the ECSO CISO Meetup in Berlin. During my talk, I highlighted how Yubico is expanding its mission, evolving from the pioneer of phishing-resistant logins (where YubiKeys have proven zero confirmed account takeovers) into a global security leader protecting the digital identity lifecycle and ensuring trust in the age of AI and quantum threats.

Legacy multi-factor authentication (MFA) no longer works against modern cyberattacks, which are now powered by AI. Complying with regulatory frameworks like NIS2, DORA, and eIDAS 2.0 requires more than legal awareness and box-checking. It demands foresight, adaptability, and, most importantly, strong technical execution and risk management to maintain operational resilience

To explore how collaboration between the public and enterprise sector is shaping the future of European cybersecurity, we connected with Cristian Tracci, strategy officer at ECSO. In the Q&A below, Cristian shares his unique perspective on achieving cybersecurity compliance overcoming operational roadblocks, and why securing the human in the loop is the key to European digital sovereignty.

The ECSO brings together a community of cybersecurity leaders. What are your requirements for someone to join your organization?

The European Cyber Security Organisation (ECSO) is Europe’s largest cross-sector cybersecurity community, bringing together industry, SMEs and startups, research centres, universities, investors, end-users, public authorities, and other key stakeholders across Europe. Established in 2016 as the European Commission’s contractual partner for the Public-Private Partnership on Cybersecurity (2016-2020), ECSO works to strengthen Europe’s cybersecurity ecosystem by fostering collaboration, supporting innovation, contributing to policy discussions, and creating business and partnership opportunities.

Through its trusted network, working groups, and strategic initiatives, ECSO enables members to exchange knowledge, build partnerships, gain market and policy insights, increase their visibility, and contribute to strengthening Europe’s cybersecurity competitiveness, resilience, and digital sovereignty. Membership is open to legal entities established in countries eligible for EU cybersecurity programmes that are willing to actively engage in and contribute to the European cybersecurity community.

Learn more about ECSO and its Community and Strategic Vision: ECSO’s Strategic Vision: European cybersecurity 2030 – ECSO.

Digital sovereignty has become a strategic priority across Europe. Yubico is uniquely positioned as a global innovator with deep European roots. How does that combination of global scale and trusted European operations help support Europe’s vision for a more resilient and sovereign digital infrastructure?

Yubico’s story, being one of the most successful and innovative companies in cybersecurity in the world, should serve as a great example. A global cybersecurity innovator with a proud  European heritage, including headquarters and manufacturing in Sweden, shows that Europe continues to contribute world-class technologies while retaining control over key assets and the value chain. 

Europe’s technological sovereignty should not be understood as isolation from global markets, though. From ECSO’s perspective, this is exactly in line with the priorities set out in ECSO’s Strategic Vision: strengthening Europe’s strategic digital autonomy, reinforcing the competitiveness of the European cybersecurity industry, securing supply chains, and building a more resilient European stronghold. We want strong European companies capable of competing on the global market. 

The momentum around the European Digital Identity (EUDI) wallet framework is growing quickly. From a policy and security standpoint, how do you see the role of hardware-backed passkeys within Europe’s upcoming digital identity standards?

Hardware-backed passkeys can play an important role for the European Digital Identity (EUDI) wallet framework, providing the phishing-resistant authentication needed to satisfy eIDAS 2.0’s strict “High” Level of Assurance, which makes their role increasingly critical to Europe’s upcoming identity standards. Anchoring cryptographic keys inside physical hardware can ensure that private key material remains non-exportable and isolated from any potential malicious software, considering the severity and growth of identity-threats. 

Looking ahead, the conversation might centre around which of these hardware options strikes the best balance between security, costs, and compliance requirements.

What do you see as the biggest roadblocks European businesses face when trying to phase out legacy MFA, and how can Yubico and ECSO work together to help organizations transition to passkeys?

Replacing technologies at scale in a corporate environment requires much more than a technical decision or management support. It requires budget, careful planning and execution to avoid disruptions, and delivering a frictionless user experience at scale. This is even more challenging for SMEs with limited resources. 

One of Yubico’s strengths is its focus on making security easy for users, and the company continues to invest in enabling organizations to adopt modern passwordless workflows using the strongest form of passkey protection. We need to focus more on making security easy and seamless, for both the organization and for the user.

Looking ahead, how will joint initiatives between organizations like ECSO and security leaders like Yubico help us stay ahead of fast-evolving, identity-focused threats? 

European champions such as Yubico and public-private federations such as ECSO play an important role because the challenges mentioned above are ecosystem-level challenges. They require coordination among all stakeholders, including technology providers, policymakers, public institutions, researchers, and end users. 

Industry leaders such as Yubico bring concrete operational experience, while ECSO can help translate that experience into insights and guidance for users and policymakers, maximising its impact. This kind of cooperation is essential if Europe wants to build a stronger, more competitive, and more autonomous cybersecurity ecosystem.

Talk to our team

Share this article: