“All challenges that SMEs face when dealing with cybersecurity are somehow related to budget constraints”

NGI Ambassador Aljosa Pasic is involved in a new EU initiative to foster a pan-European cybersecurity startup community

marta.albujar 7 de marzo de 2022
“All challenges that SMEs face when dealing with cybersecurity are somehow related to budget constraints”

It is well known that one of the main objectives of the NGI programme is to improve trust when using digital media and tools, in an era in which personal data and security are sometimes being compromised online.


As it was discussed on this NGI Talk, cybersecurity is now a key point to protect citizens from potential attacks and to make them aware of the importance of safeguarding people’s integrity, also in online environments. In NGI, we fund projects that specifically shield people's online security, as this initiative of the innovator "Neuropil".

To talk further about the role of cybersecurity for small businesses and startups, the NGI Ambassador Aljosa Pasic has invited the NGI Community members to join the webinar EU cybersecurity start-ups today and tomorrow. In it, Pasic will moderate the panel ECCC and start-ups: challenges and road ahead, for those startups interested in the initiative, which, in collaboration with EU institutions, will provide information, support and matchmaking services.

On this occasion, the NGI Community team has interviewed the NGI Ambassador to know more about this interaction between startups and cybersecurity. Have a glimpse of his views on the topic!

What is the Pan-European Cybersecurity Start-Up Community and what are its objectives?

To explain what this community is, I need to mention wider context, namely the European Union Regulation (EU) 2021/887 of the European Parliament and of the Council, establishing the European Cybersecurity Industrial, Technology and Research Competence Centre (ECCC) and the Network of National Coordination Centres (NCCs). Regulation also envisages the Pan-European Cybersecurity Community (CC), composed of many different stakeholders from industry, research, government etc. At the moment this community is composed of the European Cyber Security Organisation (ECSO) and four very big pilot projects, one of them being CONCORDIA.

One of the ECCC/NCC and CC tasks that has been envisaged is a support for cybersecurity startups, although it is not defined which kind of support it should be, or what kind of services should be provided by which level: European, national or local. More information can also be found here.

In CONCORDIA, we established Pan-European Cybersecurity Start-Up Community [...] in order to pilot some services, such as the identification of relevant events or sources of finance, or access to market support. It is an informal community, with no specific requirements to be part of it, and no specific obligations. You can see it as a mailing list and forum for discussion. However, the most important issue here is to consult relevant stakeholders: who should do what, when and how, when it comes to the future support services for European cybersecurity startups.

How does the European Cybersecurity Competence Network and Centre develop cybersecurity capacities for/with startups?

The European Centre, which will be located in Bucharest, already has an active website, but is not fully operational yet. Something similar holds for most NCC nodes (see for example German node NCC-DE). The Digital Europe programme will launch calls targeting establishment and operations of different parts of this infrastructure, and we expect that these calls will include support for startups as well.

What are the challenges that startups and SMEs face when trying to minimise the risk on their digital activities?

Number one is the budget constraint, while number two, three etc. are all somehow linked to this number one (e.g. lack of expertise). Cyber threats are increasing in number, complexity and sophistication. Small organisations often cannot deal with them on their own, so they frequently rely on managed security service providers or use cloud based security solutions, which raises a different kind of challenge, such as trust in the digital supply chain.

How can Next Generation Internet solutions help shield startups and SMEs from cyberattacks?

I already mentioned one example of links between security and trust, but there are many others, e.g. cyber intelligence data sharing. Among areas that NGI is addressing are distributed trust models, but also assurances and many others. Startups and SMEs need feasible, but also affordable solutions where they do not give up too much control over their valuable assets.