Summary
The core message of the provided session excerpt is that Europe’s cybersecurity autonomy cannot be treated as a purely abstract sovereignty debate: it is tied to concrete market structure, investment flows, buyer behaviour, and the ability of European startups to reach customers early enough to grow. Moderator Martijn Jonk framed the problem with a stark number: in 2025, investors put $18 billion into young cybersecurity companies worldwide, and 70% went to companies headquartered in the United States. He then asked the audience whether their most important security products, such as EDR, SIEM, or firewall technology, came from European companies; only about five hands went up. This set up the panel’s central question: why American companies supply so much of Europe’s security stack, and what companies, governments, and investors can do about it.
The first exchanges established why the issue matters. Rogier Fischer, CEO of Hadrian, said his company’s recent €40 million raise was not because of, or despite, the European funding climate, but because it had built a strong product and saw a way to deploy capital for faster growth. Economist Marieke Blom argued that economists normally welcome international specialization and trade when it delivers value for money, but that the calculation changes when a purchased technology can become a choke point. Bram Kaashoek explained that private equity sellers must consider price, but also strategic fit, business continuity, and reputation. Jean-Noel de Galzain described the Dutch cyber sector from Paris as dynamic, disciplined in budget management, and aligned with France around a renewed European ambition for digital industry, AI, agentic technologies, and cyber resilience.
The discussion then moved into the barriers holding back European cybersecurity champions. Leah Postma said the Netherlands is on track toward the Cabinet Cybersecurity Technology Agenda goal of a competitive cybersecurity market and internationally leading position by 2035, while acknowledging that much remains to be done and that the action agenda exists to bring focus, investment, and ecosystem coordination. Fischer highlighted a cultural gap: in the United States, Fortune 500 CISOs often engage directly with startups and sit on boards, making early feedback and design partnerships easier to secure. In the Netherlands five years earlier, by contrast, startups were often not seen as relevant to security strategy discussions, though he said this has improved in the last two years.
Jean-Noel de Galzain added that Europe needs a stronger culture of risk and trust. For critical infrastructure, factories, defence, healthcare, and other essential sectors, he argued that buyers need solutions that combine performance with sovereignty and trust. The supplied transcript ends during this discussion, at 21:41, while the full session duration is 54:07; later panel content, audience questions, and conclusions are therefore not available in the provided text.
Key Topics
5 key topics from Martijn Jonk, Marieke Blom, Bram Kaashoek, Rogier Fischer and 2 more speakers at ONE Conference. Thicker branches were mentioned more often in the talk.
Key Takeaways
- Engage CISOs early to secure market feedback and design partners.
- Assess cybersecurity suppliers for strategic dependency, not only price.
- Build European cyber products around performance, sovereignty, and trust.
- Coordinate government investment agendas with startups, investors, and buyers.
- Treat critical-sector cybersecurity procurement as a resilience decision.
“everything changes if you fear that what you're buying could become a choke point at any moment in time.”
Up Next
MNext in agenda
Police Hack and Pass-the-Cookie: No Crumbs, Full Access



Also on cybersecurity
Catch up to keep up: how to connect cybersecurity, AI, and the economy to rebuild our basis?


Also on cybersecurity
