European Cybersecurity Month was first held in October 2012. What began as a pilot project across several EU countries has grown into one of the most important annual reminders that digital security is not only a technical discipline but also a human and organizational one. The campaigns of the last two years make this clearer than ever: cybersecurity now touches every part of modern business life.

The initiative, coordinated by the European Commission and ENISA, runs throughout October. Its goal is simple but ambitious: strengthen awareness, improve resilience, and highlight the human factor behind cyber incidents. In recent years, the focus has shifted from purely technical threats to the broader question of how organizations communicate, train people, and coordinate across borders. Many attacks succeed not because the code is lacking, but because people misunderstand instructions or react under pressure.

Cybersecurity as a Communication Challenge

Cybersecurity is often framed as an IT responsibility, yet recent campaigns emphasize that it is also a communication task. Henna Virkkunen, Executive Vice‑President for Technological Sovereignty, Security and Democracy, noted in 2025 that cybersecurity is “a critical condition for all sectors of society and a shared responsibility.” Even the best systems fail when people don’t understand how to use them correctly.

The kind of ‘industrial espionage’ we have all watched in Hollywood movies is no longer relevant in comparison with the social engineering threats we face today. Phishing remains the most common entry point for cyberattacks. Over 90% of cyberattacks begin with phishing, making it the leading method used by attackers to breach networks and steal data (CISA). Every day, 3.4 billion phishing emails circulate globally. Anyone who has ever looked at a suspicious message and hesitated knows how quickly doubt can creep in.

The financial damage goes far beyond immediate losses. Breach containment, legal costs, regulatory fines, reputational harm, and operational downtime all add up. Among all the many threats in cyberspace, Business Email Compromise (BEC) is one of the most financially devastating outcomes of phishing. It doesn’t rely on malware or technical exploits. It relies on impersonation, urgency, and trust — all conveyed through language. Persuasive emails, convincing messages, fake login pages, or QR codes that appear legitimate can trick even the most experienced employees. When someone misinterprets a message or overlooks a subtle warning sign, attackers gain access. In that sense, language itself becomes a potential security risk

The International Dimension: Cybersecurity Across Borders

For internationally active companies, cybersecurity is not just a technical and human challenge but also a global coordination task. When companies prepare translations for EU markets, they often think only of the Big Four – French, Italian, German and Spanish. Yet the EU has 24 official languages, each with its own nuances.

The EU’s own European External Action Service participates in dialogues with Gulf Cooperation Countries, Ukraine and Indo‑Pacific partners to strengthen shared resilience and responsible behavior in cyberspace across all EU and other languages.

Global companies face similar issues. Teams in different countries work with different languages, cultural expectations and regulatory environments. A security guideline written in one country may be interpreted differently in another. A warning message that seems perfectly clear to a German engineer may be quite unclear to a colleague in Kyiv or Madrid. Misunderstandings create vulnerabilities.

This is particularly relevant for industries with complex international supply chains:

  • Automotive: Modern vehicles work with software updates, cloud services and connected components. A poorly translated security instruction can affect the entire chain.
  • Healthcare: Hospitals and medical device manufacturers operate under and must follow strict regulations. The personal information of users, as well as the proper function and operation of devices are on the line if communication is not dependable.
  • Industrial production: Factories increasingly depend on digital control systems. Cyber incidents can disrupt operations, and imprecise instructions can delay response.
  • E‑Commerce and IT/software: Online platforms rely on coordinated incident response. If teams misunderstand alerts or procedures, attackers gain time and advantage, potentially creating damage that can bankrupt companies.

The Global Cybersecurity and Innovation Summit in Hamburg (December 9th and 10th this year) places its focus on the human factor, behavioral change and the effectiveness of awareness programs. The message is clear: cybersecurity is not just about technology. It is also about how people across different locations understand and act on information.

Language as a Security Factor

The question “Can language itself become a security risk?” is increasingly relevant. The answer is yes. Not because language is inherently dangerous, but because unclear or inconsistent communication opens the door for attackers.

Here some examples to clarify the point:

  • If a security policy uses vague wording, some employees – especially in multinational teams – could misunderstand, resulting in behaviour that could potentially cost millions.
  • When security instructions are translated without technical accuracy or cultural clarity, mistakes are bound to happen.
  • Security alerts must be clear, concise and unambiguous. If employees don’t fully understand an alert – due to language barriers or unclear phrasing – they might disregard it altogether or respond incorrectly.
  • Training materials must be accessible to all employees, regardless of their language background. If the wording is too complex or culturally misaligned, critical information might not be understood or implemented correctly.
  • Attackers have become very adept in using AI to create messages that look and feel like internal communications. If employees are not trained to recognize subtle differences, they could disclose proprietary, information, release payments, or unintentionally disrupt operations.

These examples show how consistent, and uncomplicated instructions and explanations – in the user’s language – become an important line of defense.

Current Developments Shaping Cybersecurity in 2026

The 2026 ENISA Threat Landscape highlights how dependencies between digital systems exacerbate the threat. Organizations manage complex networks of suppliers, cloud services and connected devices. This complexity increases the need for clear communication across all levels and touchpoints.

Several developments stand out:

Single Reporting Platform (SRP)

Launched on September 11 2026, SRP simplifies how organizations report cyber incidents. In order to use it correctly, employees must understand the reporting procedures clearly, regardless of location. Ironically, the platform is only available in English, but further languages will be added in due course.

Cyber Europe 2026

ENISA has been organizing the biennial ‘Cyber Europe’ series since 2010. Cyber Europe is a series of large-scale, cross-border cyber crisis management exercises. They feature complex realistic scenarios inspired by real events and threats. ENISA develops these exercises in collaboration with European cybersecurity experts to simulate large-scale cybersecurity incidents that could grow into full-blown cyber crises. The aim here is to analyze incidents and test the participants’ ability to handle complex situations

Human factor and behavioral change

Panels in 2026 explored how behavioral change, gamification and AI‑supported training can improve cybersecurity awareness. Traditional training methods have often been perceived as boring or unnecessary, forcing employers to change their thinking and training methods. Younger generations in particular have shorter attention spans, and are more likely to respond to gamification.

Cyber diplomacy and global cooperation

The EU’s diplomatic initiatives in 2025 and 2026 show that cybersecurity is now part of international relations. Global companies must align their internal communication with international standards and expectations. ‘The Externalisation of the EU’s Cybersecurity Regime: The Cybersecurity Toolbox’ by Yuliya Miadzvetskaya and Ramses A. Wessel is a very interesting read, detailing how the EU is increasingly viewing cyberattacks as an external problem, issuing ever more restrictive measures in response to cyber-attacks.

Bottom Line

For companies operating across borders, Cybersecurity Month is a reminder that cybersecurity requires clarity and consistency in communication, training and messaging. It is more than code and expensive software. Cybersecurity starts with the people handling sensitive information. Making sure that employees fully understand instructions, and why certain behaviors are crucial to the security of their company is the first step to success. Such procedures can therefore not be handled ‘in country’. A global cybersecurity strategy is needed that includes cultural nuances, accurate translation, and unambiguous language as well as the kind of structure that keeps people engaged and willing to learn.



Sources

 

autor_eurotext_100Author: Eurotext Editorial Team

We explain how internationalization works, provide tips for your translation projects and outline some of the technology and processes used. We also report on current e-commerce developments and cover a range of language-related topics.