Active Cyber Protection

ENISA is supporting the EU Member States since 2012 to develop, implement and evaluate their National Cyber Security Strategies (NCSS). Since 2017, all EU Member States have published their own NCSS.

Active Cyber Protection

Active Cyber Protection (ACP): As part of their national cybersecurity strategies, Member States should adopt policies on the promotion of active cyber protection as part of a wider defensive strategy. Based on NIS2 Directive, ACP involves the prevention, detection, monitoring, and mitigation of network security breaches through both internal and external capabilities. ACP includes tools and services such as self-service checks, detection tools, and proactive measures to enhance the ability to share threat intelligence and improve the overall security posture of the country.

Austria flag
Austria
Belgium flag
Belgium
Bulgaria flag
Bulgaria
Croatia flag
Croatia
Cyprus flag
Cyprus
Czech Republic flag
Czech Republic
Denmark flag
Denmark
Estonia flag
Estonia
Finland flag
Finland
France flag
France
Germany flag
Germany
Greece flag
Greece
Hungary flag
Hungary
Iceland flag
Iceland
Ireland flag
Ireland
Italy flag
Italy
Latvia flag
Latvia
Liechtenstein flag
Liechtenstein
Lithuania flag
Lithuania
Luxembourg flag
Luxembourg
Malta flag
Malta
Netherlands flag
Netherlands
Norway flag
Norway
Poland flag
Poland
Portugal flag
Portugal
Romania flag
Romania
Slovakia flag
Slovakia
Slovenia flag
Slovenia
Spain flag
Spain
Sweden flag
Sweden
Switzerland flag
Switzerland
Croatia flag
Croatia

SK@UT - national system for cyber threat detection and protection: Croatia's flagship active-protection capability and largest national cyberspace-protection project. SK@UT ("cybernetic umbrella") is a national system for detecting cyber threats and protecting cyberspace through a distributed network of sensors and cyber-protection tools deployed in key entities. Built by SOA and ZSIS (with a joint SOA/ZSIS/VSOA expert team), it provides timely detection, early warning and protection against state-sponsored and APT attacks and other threats, catching sophisticated attacks in their earliest stages. It now protects 120+ state bodies, critical-infrastructure operators and legal entities of special interest - mandatory for ministries/government bodies (per NCSC-HR criticality assessment) and open to voluntary participation by socially important entities. 

Sources: https://ncsc.hr/hr/skaut 
https://ncsc.hr/en/skaut 
https://soa.hr/hr/kiberneticka-sigurnost/212 
https://soa.hr/en/cyber-security/212 

National CERT proactive protective measures (CERT.hr): The National CERT's proactive (as opposed to reactive) protection function, complementing SK@UT for the wider .hr community. CERT.hr (within CARNET) delivers proactive measures: security recommendations, monitoring of cybersecurity technologies and the threat landscape, dissemination of threat information and security warnings, vulnerability assessments for CARNET member institutions, issuance of electronic certificates, and security testing of services. It also runs public protective tools such as "CERT iffy" (a web-shop/URL checker) and publishes Ongoing advisories to pre-empt attacks. 

Sources: https://gov.hr/hr/nacionalni-cert/1230 
https://gov.hr/en/national-cert/1230 
https://www.cert.hr/ 
https://www.cert.hr/en/home-page/ 

Denmark flag
Denmark

CSIRT International Cooperation through the Danish Defence Intelligence Service: Denmark’s national CSIRT and Government CERT is placed in the Danish Defence Intelligence Service (DDIS). It provides warnings, threat information, incident handling support and cybersecurity services to government entities and operators of critical infrastructure, strengthening national incident preparedness and response capabilities.

Sources: https://tf-csirt.org/trusted-introducer/directory/teams/cfcs/
https://www.fe-ddis.dk/da/arbejdsomrade-a/Cybertruslen/

New joint 24/7 situation centre: The Danish Government announced the establishment of a 24/7 situation centre linked to NOST, alongside a national cyber operations centre and cyber monitoring network. These measures aim to strengthen detection, coordination, response and crisis management for cyber and hybrid threats.

Sources: https://mssb.dk/nyheder/nyhedsarkiv/2025/december/regeringen-nyt-faelles-247-situationscenter-i-lyset-af-hybridkrig/
https://mssb.dk/media/ywqbp0rh/baggrundsnotat.pdf

Annual Cyber Threat Assessment (Cybertruslen mod Danmark): Denmark publishes an annual national cyber threat assessment describing the cyber threat landscape, threat levels and attack patterns affecting public authorities, businesses and citizens.

Sources: https://samsik.dk/publikation/cybertruslen-mod-danmark/
https://samsik.dk/wp-content/uploads/2025/11/Cybertruslen-mod-Danmark-2025.pdf

Hungary flag
Hungary

GovProbe – distributed government trap/sensor (honeypot) system: Hungary's flagship active-protection capability. GovProbe (the Distributed Governmental Network Security Trap System) is a national honeypot/sensor network deployed across public-administration and critical-infrastructure bodies that emulates real services to lure, detect and analyse attackers, providing a second line of defence, an intrusion-alarm/early-warning function, and threat intelligence (attacker source IPs, new indicators, zero-day discovery and trend analysis). Operated by the Event Detection unit of the National Cyber Security Centre of Hungary (NCSC HU), it aggregates data from ~54 sensors across ~23 locations, generating roughly 680,000 trap attack entries daily. Its data feeds weekly NCSC HU situational reports. Built with EU Internal Security Fund co-funding (BBA projects, 2016 and 2019).

Sources: https://nki.gov.hu/szolgaltatasok/tartalom/honeypot/
https://nki.gov.hu/wp-content/uploads/2023/10/GovProbe.pdf

National Cyber Security Centre of Hungary (NCSC HU) proactive protection service

The national CSIRT's suite of proactive/active-defence services complementing GovProbe. The National Cyber Security Centre of Hungary (NCSC HU)operates an Early Warning System and an Automated Vulnerability Detection service that continuously scan for and flag weaknesses in constituents' systems, publishes a public Cyber Threatmap and continuous threat advisories/alerts, and (under the Cybersecurity Act) can order the temporary inaccessibility (takedown) of phishing/malicious websites to protect users. These pre-emptively neutralise threats before they cause harm.

Sources: https://nki.gov.hu/szolgaltatasok/tartalom/ews-rendelet/
https://nki.gov.hu/szolgaltatasok/tartalom/asr/
https://cyberthreatmap.nki.gov.hu/
https://net.jogtar.hu/jogszabaly?docid=a2000214.kor
https://nki.gov.hu/wp-content/uploads/2022/10/Szolgaltatasi-szabalyzat-EWS.pdf

Netherlands flag
Netherlands

National Detection Network in NCSC: The National Detection Network combines shared threat intelligence with the monitoring capabilities of participating organisations. By distributing indicators and coordinating findings, it helps participants identify malicious activity and act before the threat causes wider harm. 

Source: https://www.ncsc.nl/over-ons/versterkt-ncsc 

NCSC-NL advisories and pre-emptive mitigation: NCSC-NL publishes advisories on significant vulnerabilities and threats together with recommended actions. Organisations can use the guidance to patch systems, strengthen configurations and apply other safeguards before exploitation occurs. The main value here is timing: organisations receive concrete mitigations before a vulnerability becomes an incident. 

Source: https://advisories.ncsc.nl/ 

Defence Cyber Command military cyber operations: The Defence Cyber Command develops military capabilities to detect, analyse and counter cyber threats affecting defence operations and networks. Its mandate would include proactive measures authorised for military purposes, rather than only recovery after an incident. Military cyber activity remains clearly separated from the civilian advisory and response role of NCSC-NL. 

Source: https://www.defensie.nl/organisatie/defensie-cyber-commando 

Anti-Phishing Shield: It is a public-private initiative that helps protect internet users from phishing and fraudulent websites. Specifically, the service uses regularly updated threat intelligence to identify malicious domains and enables participating internet service providers to block access to those sites for customers who choose to opt in. 

Source: https://www.ncsc.nl/nieuws/ruim-twee-miljoen-bezoeken-aan-kwaadaardige-websites-voorkomen-in-pilot