Member States, with the support of the European Commission and the EU Agency for Cybersecurity (ENISA), published the first report on the cybersecurity and resilience of the EU’s telecommunications and electricity sectors. The report points to concerns about a number of risks, including risks to supply chain security, the lack of cyber professionals and the risks posed by malicious activities from cyber criminals and state-sponsored threat actors. More specifically, the risk evaluation uncovers major technical and non-technical risks for telecommunications and electricity sectors. Supply chain vulnerabilities, ransomware, data wipers, and zero-day exploits are major pressing concerns. Electricity faces insider threats, while telecoms faces roaming and botnet attacks. Physical risks like cable sabotage are difficult to mitigate. Recommendations include improving resilience through information sharing, vulnerability monitoring, personnel vetting, enhancing cyber situational awareness, strengthening contingency planning and cross-sector collaboration, and addressing supply chain security risks through assessments and an EU framework. Given the critical infrastructure involved and evolving threats, the report urged swift implementation of these resilience measures by Member States, the Commission, and ENISA.