Chinese devices threaten Western infrastructure security: CEPA report
Synopsis
Key Takeaways
A new report from the Center for European Policy Analysis (CEPA) has warned that Chinese-made connected devices — ranging from port cranes to electric buses — pose growing and largely unchecked security risks to Western infrastructure, and that allied nations urgently need a common methodology to assess and contain those risks. The findings, released on 17 September 2026, place the spotlight on hardware and software already embedded in critical systems across Europe and North America.
Key Vulnerabilities Identified
The CEPA report singles out ZPMC cranes supplied by China to American ports as a specific concern, noting that the machines contained cellular modems capable of bypassing firewalls, harvesting cargo data, and potentially disrupting port operations. In a separate case, Yutong buses sold to Oslo were found to carry connected battery and power controls that could, reportedly, allow the manufacturer to remotely render the vehicles inoperable.
Beyond hardware, the report flags software risks. Chinese-supplied applications such as Hikvision's Hik-Connect reportedly transmit phone and SIM card identifiers to servers located in China, raising concerns about persistent surveillance and data aggregation at scale.
The Grid Threat and Energy Infrastructure
One of the report's more striking warnings concerns the energy sector. According to CEPA, even an ordinary household purchase — such as a Chinese-built affordable solar inverter — could compound into a structural threat if the manufacturer retains the ability to push malicious software updates to thousands of such devices simultaneously. The International Energy Agency (IEA) has separately warned about the risk of grid blackouts from such updates, noting that actors with connected capacity could spread disruption across borders faster than grid operators can respond.
Connected vehicles, cameras, and microphones add another dimension to the threat. The report argues that granular location data collected across a large fleet could, when aggregated, reveal sensitive infrastructure layouts or military movements — intelligence that would otherwise require significant covert effort to obtain.
What CEPA Recommends: Digital Strategic Exposure
To address these risks without triggering a counterproductive technology decoupling, CEPA proposes a framework it calls Digital Strategic Exposure (DSE). Under this methodology, governments would assess risk across four dimensions: devices, cloud services, subcontractors, and jurisdictions. The goal is to limit what the report terms 'dangerous digital leverage.'
'Under DSE, Europe would gain a legally defensible way of making decisions to exclude Chinese products where risks cannot be contained, without unnecessarily excluding American technology. Partners could compare their reasoning without sharing confidential evidence,' the report stated.
Notably, CEPA also urges allied countries within the European Union to avoid 'counterproductive sovereignty requirements' — a caution against unilateral, nationally siloed responses that could fragment the very alliance cohesion needed to counter the threat effectively.
Broader Context and Strategic Stakes
This comes amid an intensifying global debate over Chinese technology in critical infrastructure. The United States has moved to restrict ZPMC crane software access, and several EU member states are reviewing Chinese components in their telecommunications, energy, and transport networks. Critics of outright bans, however, argue that blanket exclusions risk trade retaliation and leave gaps that no immediate alternative can fill.
The CEPA report attempts to chart a middle path: a shared, evidence-based risk framework that allied democracies can apply consistently. Whether Europe and its transatlantic partners move swiftly enough to adopt DSE — or something comparable — before further Chinese-connected devices are embedded in critical systems will be a defining policy question in the months ahead.