NATO Allies Pledge 1.5% Of GDP To Boost Cybersecurity & Protect Critical Infrastructure

On 25 June 2025, NATO leaders, gathered at the annual summit in The Hague, agreed to a landmark defence spending target of 5% of GDP by 2035, with 1.5% earmarked specifically for cybersecurity and critical national infrastructure protection.

This decision, driven by mounting geopolitical tensions and the growing sophistication of cyber threats, marks a significant shift in how the alliance defines defence expenditure.

The move responds to persistent calls from US President Donald Trump for European allies to shoulder more of the collective security burden, while addressing urgent vulnerabilities in digital and physical infrastructure.

Responding To Contested Cyberspace

The 1.5% allocation, detailed in NATO’s new spending framework, will fund cybersecurity, border and coastal security, and infrastructure upgrades such as roads and bridges capable of supporting military convoys. A Bloomberg report from May 2025 noted that NATO proposed including these expenditures to meet the alliance’s ambitious 5% GDP target, with 3.5% allocated to “hard defence” like troops and weapons.

The decision reflects the alliance’s recognition of cyberspace as a contested domain, with daily malicious cyber events ranging from low-level attacks to sophisticated campaigns targeting critical systems.

Russia’s ongoing war in Ukraine and China’s hybrid cyber operations have underscored the need for robust defences, as highlighted in NATO’s 2024 cyber defence policy update.

Economic & Strategic Implications

The commitment to 1.5% of GDP for infrastructure and cybersecurity is poised to transform the global cybersecurity market. A data visualisation from Ainvest projects that NATO-related spending could drive 40% of the sector’s growth, with annual cybersecurity expenditures potentially surpassing $500 billion by 2032.

This surge will benefit firms specialising in threat detection, encryption, and infrastructure protection, such as Palo Alto Networks and CrowdStrike. However, the financial strain is significant. European allies and Canada, who increased defence spending from 1.43% of GDP in 2014 to 2.02% in 2024, face challenges in meeting the new target, particularly southern members like Spain, which secured flexibility to spend only 2.1% on core defence.

Challenges & Dissent

Spain’s reluctance to fully commit to the 5% target, as reported by Reuters, highlights tensions within the alliance. Prime Minister Pedro Sánchez argued that 2.1% of GDP suffices to meet NATO’s capability targets, a stance that drew criticism from US officials and NATO Secretary-General Mark Rutte, who insisted Spain must align with the 3.5% core defence goal. Despite these challenges, countries like Norway and Poland are already on track to meet or exceed the 5% target, driven by proximity to Russia and heightened security concerns.

A Step Toward Resilience

The pledge, set for review in 2029, requires allies to submit annual plans to ensure incremental progress. As NATO Secretary-General Mark Rutte warned, Russia could pose a military threat to the alliance within five years, making investments in cybersecurity and infrastructure critical.

In expert comment, Jamie Moles, Senior Technical Manager at ExtraHop said. "NATO’s allocation to protect critical infrastructure and bolster cyber resilience signals the notable link between cybersecurity and national security on the world stage. However, the real impact will come from how these funds are deployed...

With state-sponsored cyber attacks increasing in frequency and sophistication, investing in network visibility that detects threats before a major incident occurs is more essential than ever. Equally important is building resilience, not just preventing attacks, but minimizing complexity to ensure critical systems can recover quickly without disruption." Moles concluded.

This commitment signals NATO’s resolve to adapt to 21st-century threats, balancing traditional defence with digital resilience to safeguard the Euro-Atlantic area.

Bloomberg  |   Politico   |    Euronews   |  @CGTN  |   CNBC   |   NATO  

Image: Marek Studzinski

You Might Also Read:

The UK’s Defence Shift & The Urgency Of Sovereign Digital Infrastructure:


If you like this website and use the comprehensive 8,00-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

« Healthcare Under (Cyber) Attack: What You Need to Know

CyberSecurity Jobsite
Check Point

Directory of Suppliers

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

Directory of Cyber Security Suppliers

Directory of Cyber Security Suppliers

Our Supplier Directory lists 8,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

Aptive Consulting

Aptive Consulting

Aptive is a cyber security consultancy providing Penetration Testing and Vulnerability Assessment services.

e-Governance Academy (eGA)

e-Governance Academy (eGA)

eGA is a think tank and consultancy founded for the transfer of knowledge and best practice in e-governance, e-democracy and national cyber security.

Verint Systems

Verint Systems

Verint is a leader in CX automation. The world’s most iconic brands rely on our open platform and team of AI-powered bots to create tangible AI business outcomes, now.

Redshift Consulting

Redshift Consulting

Redshift is an information management and information security consulting company offering a full range of services from infrastructure design to security assessments and network monitoring.

State e-Government Agency (SEGA) - Bulgaria

State e-Government Agency (SEGA) - Bulgaria

The State e-Government Agency (SEGA) is responsible for matters relating to electronic governance in Bulgaria.

National Accreditation Agency of Ukraine (NAAU)

National Accreditation Agency of Ukraine (NAAU)

NAAU is the national accreditation body for Ukraine. The directory of members provides details of organisations offering certification services for ISO 27001.

Plug and Play Tech Center

Plug and Play Tech Center

Plug and Play is the ultimate innovation platform, bringing together the best startups and the world’s largest corporations.

CyberSN

CyberSN

CyberSN is your essential partner in cybersecurity workforce risk management offering solutions that empower leaders to diversify, acquire, retain, and develop their cybersecurity teams.

MyDocSafe

MyDocSafe

MyDocSafe is an all-in-one document security and e-sign software.

LBMC

LBMC

LBMC is a professional services solutions provider in accounting and finance, human resources, technology, risk and information security, and wealth advisory services.

Allot

Allot

Allot are a global provider of leading innovative network intelligence and security solutions for Service Providers and Enterprises worldwide.

Box

Box

Box is the Cloud Content Management company that empowers enterprises to revolutionize how they work by securely connecting their people, information and applications.

Triskele Labs

Triskele Labs

Triskele Labs deliver services including Penetration Testing, Compliance and Risk Management through to 24*7*365 Security Operations and outsourced Cybersecurity Managers.

Incode

Incode

Incode is the leading provider of world-class identity solutions that is reinventing the way humans authenticate and verify their identities online.

Black Alps

Black Alps

Black Alp's mission is to promote cybersecurity through the organization of dedicated events.

Platview Technologies

Platview Technologies

Platview Technologies is an innovative and agile cybersecurity company with the goal of safe-guarding businesses with our world-class, industry-leading services and technology solutions.