Infosecurity Magazine iconInfosecurity MagazineSep 23, 2026 ~4 min source read

EU auditors: poor information‑sharing is weakening response to large cyber incidents

A European Court of Auditors report finds coordination gaps, delayed systems and legal limits on sharing are reducing the EU's ability to detect and handle cross‑border cyber crises.

Share this story

Send the public story page.

Useful takeaways from this story.

Insufficient information exchange between national CSIRTs, EU‑CyCLONe and EU bodies is the primary operational shortcoming.

Procurement delays and missing cooperation agreements have stalled key alert hubs (ATHENA and ENSOC) and delayed the European Cybersecurity Alert System.

Duplication exists between the European Commission’s cyber‑situation centre and ENISA’s monitoring work, and vetting gaps expose EU‑funded projects to intrusion or foreign influence.

# What the auditors found

Auditors reviewed the EU's cybersecurity architecture and concluded that while the bloc's €1.4bn cybersecurity budget produces useful activity, the system's Achilles heel is insufficient exchange of information. This shortfall hinders timely detection and coordinated response to large, cross‑border cyber incidents.

# Where communication breaks down

The auditors identify unclear, informal roles and limited formal agreements as the main causes. Country‑level CSIRTs, the European Cyber Crisis Liaison Organisation Network (EU‑CyCLONe), ENISA and the Commission lack clearly defined responsibilities and shared routines for urgent exchanges. National security laws and the slow transposition of NIS2 into member‑state law further restrict what can be shared across borders.

# Systems and procurement delays

Two hubs intended to support the European Cybersecurity Alert System, ATHENA and ENSOC, had not started operations at the time of the audit because of procurement delays. The auditors also found that necessary cooperation agreements, a common classification system and technical standards for the alert system were still missing, limiting the system's readiness.

# Duplication and coverage gaps

The report flags overlap between the European Commission's cyber‑situation centre, created in 2022 and supported by external providers, and ENISA's monitoring and situational‑awareness activities. That duplication could dilute resources and create confusion about who leads monitoring and warning functions.

# Supply‑chain and vetting concerns

Auditors say organisations receiving EU cybersecurity funding were not consistently vetted. This leaves funded projects vulnerable to intrusion or influence by non‑EU states and raises the risk that sensitive security information could be shared outside the EU.

# Complementary ENISA findings

  • Low‑impact DDoS accounted for 51% of recorded incidents, driven largely by geopolitical tensions.
  • Ransomware remained the highest short‑term impact threat.
  • Sectors most affected: public administration (32%), business services (9%), transport (8%), manufacturing (7%), finance/banking (6%).
  • ENISA's dataset covers 8,257 incidents in 2025.

# Views on possible operational models

The report includes industry commentary calling for faster, machine‑readable sharing and playbook‑driven exchanges. One cited view recommends functions similar to CISA's Automated Indicator Sharing and Joint Cyber Defense Collaborative: real‑time indicator exchange and coordinated playbooks that bring government, industry and international partners together under shared rules for urgency and action.

# Practical implications for stakeholders

Policy makers: accelerate NIS2 transposition, define formal roles for CSIRTs and EU‑level bodies, and finalise cooperation agreements and classification standards for the alert system.

Operational teams: prepare for more automated, machine‑readable indicator exchange and align playbooks across national and EU entities.

Funding bodies: introduce vetting processes for recipients of EU cybersecurity funds to reduce risk of foreign intrusion or influence.

Sectors at risk: public administration and business services should prioritise vulnerability management and incident‑response readiness because data show they are frequently targeted and intrusions often exploit known vulnerabilities.

# Bottom line

The EU has invested significant funding and created structures for cybersecurity, but the auditors find that real‑time sharing, formalised responsibilities and operational standards are still missing. Those gaps reduce the EU's ability to detect and coordinate response to large‑scale, cross‑border cyber events, while procurement and vetting weaknesses add additional exposure.

More context around this story.

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app