EU Auditors Warn Information-Sharing Gaps Hinder Cyber Response
Share
The EU Court of Auditors has warned that critical gaps in information sharing are undermining the European Union’s capacity to detect and respond to large-scale cyber incidents.
While the bloc maintains a €1.4bn ($1.6bn) cybersecurity budget, the audit identified an “Achilles heel” in the form of insufficient information exchange between member states and central authorities.
Structural and Regulatory Hurdles
The auditors noted that a lack of formally defined roles is hindering cooperation between national Computer Security Incident Response Teams (CSIRTs) and the European Cyber Crisis Liaison Organisation Network (EU-CyCLONe). This friction is compounded by the slow transposition of the Network and Information Security Directive (NIS2) into national laws across the union.
Furthermore, the report highlighted that existing national security laws often restrict the types of information that can be shared across borders. There is also a perceived duplication of effort between the European Commission’s cyber-situation centre, established in 2022, and the work performed by the European Union Agency for Cybersecurity (ENISA).
Operational Delays and Security Risks
The audit also identified significant delays within the European Cybersecurity Alert System. Two key hubs, ATHENA and ENSOC, have failed to begin operations due to ongoing procurement delays. The auditors stated that the system currently lacks the necessary cooperation agreements, common classification systems, and technical standards required for effective functioning.
A separate concern involves the security of organisations receiving EU cybersecurity funding. The auditors warned that these entities are not currently being vetted, creating a risk of intrusion or influence by non-EU states. Such a lapse could potentially lead to sensitive security intelligence being accessed by foreign authorities.
Industry experts have suggested that the EU could benefit from models used by the United States, such as the Cybersecurity and Infrastructure Security Agency (CISA) approach to automated indicator sharing and rapid defensive exchanges across government and industry partners.
Expanding Threat Landscape
The findings coincide with a report from ENISA, which warned that expanding supply chain dependencies are increasing the region’s attack surface. According to the ENISA Threat Landscape 2026 report, while low-impact Distributed Denial of Service (DDoS) attacks accounted for 51% of recorded incidents in 2025, ransomware remains the highest-impact short-term threat.
The report, which analysed 8,257 incidents from the 2025 calendar year, found that 60% of identified intrusion-related attacks resulted from vulnerability exploitation. Public administration was identified as the most targeted sector, accounting for 32% of incidents, followed by business services at 9% and transport at 8%.




Leave a Reply