Breaking
SecurityDeveloping Story

EU's Cyber Info-Sharing Falls Short

EU auditors say weak information exchange between national and bloc-level bodies is undermining detection and response to large-scale cyber incidents.

··2 hours ago·6 min read
three european flags flying in front of a building
Photo by Carl Gruner on Unsplash

The European Union's top audit institution has delivered a blunt assessment of how the bloc handles large-scale cyber incidents, pointing to what it calls an Achilles heel in an otherwise useful cybersecurity budget: the insufficient exchange of information between the bodies meant to coordinate a response. The finding, published by the EU Court of Auditors, questions whether the money Europe spends on cyber defense is translating into the kind of coordinated action a major incident would demand.

The report arrives alongside separate analysis from the EU's own cybersecurity agency warning that supply chain dependencies are widening the region's attack surface. Together, the two documents sketch a picture of a union spending real money on cyber resilience while struggling to connect the institutions that are supposed to make that spending count.

A well-funded weak point

The Court of Auditors examined the bloc's €1.4bn ($1.6bn) cybersecurity budget and concluded it is doing some good. But the audit identified a structural flaw: information does not move well between the organizations charged with detecting and responding to incidents. The auditors characterized this as the Achilles heel of the EU's cyber effort.

According to the findings, a lack of formally defined roles is hampering cooperation between country-level CSIRTs — the national computer security incident response teams — and the European Cyber Crisis Liaison Organisation Network, known as EU-CyCLONe. Without clear divisions of responsibility, the mechanisms that should allow these groups to work together in a crisis are not functioning as intended.

The auditors also pointed to the slow transposition of NIS2 into national law as a negative factor, and noted that national security laws restrict what information can be shared. In other words, even where the will to cooperate exists, legal and procedural barriers stand in the way.

Duplicated effort, delayed systems

The audit found duplication of effort between two parts of the EU apparatus: the European Commission's cyber-situation centre, founded in 2022 and supported by external providers, and the threat-monitoring and situational-awareness work carried out by the EU security agency Enisa. Two bodies doing overlapping jobs is a recipe for wasted resources and muddled accountability.

Delays to the European Cybersecurity Alert System drew particular criticism. Two hubs within that system, ATHENA and ENSOC, had still not begun operations at the time of inspection because of procurement delays. The report did not stop at the timing problem, noting that the system was missing the very things it would need to function.

"In addition, the necessary cooperation agreements, a common classification system, and technical standards needed for the system to work were still lacking."

— The EU Court of Auditors, in its report on the bloc's cybersecurity arrangements.

That assessment matters because an alert system without shared standards or a common way of classifying incidents cannot deliver the interoperability it promises. The components exist on paper; the connective tissue does not.

The vetting gap

The audit also raised a concern about who receives EU cybersecurity funding. At the time of inspection, organizations receiving that money were not being vetted, which the auditors said left them exposed to a "risk of intrusion or influence" by non-EU states. The report warned this could potentially lead to sensitive security information being shared with non-EU authorities.

That is a notable finding for a funding program intended to strengthen European defenses. Money flowing to unvetted recipients creates a pathway by which the very information-sharing the auditors want to improve could end up in the wrong hands.

A model from across the Atlantic

One industry voice weighed in on what the EU could do differently, pointing to structures already operating in the United States. Jacob Krell, senior director of secure AI solutions and cybersecurity at Suzu Labs, argued the EU should take a leaf out of CISA's book.

"CISA's Automated Indicator Sharing moves machine-readable indicators and defensive measures in real time," he explained.

"The Joint Cyber Defense Collaborative adds playbooks and rapid exchanges across government, industry, and international partners. Europe needs those functions tied to its existing institutions, with shared rules for confidence, urgency, and action."

Krell's point is less about copying a specific tool than about wiring real-time exchange into the institutions Europe already has. The audit's findings on missing classification systems and standards line up with that diagnosis: the EU has the organizations, but not the shared rules that would let them act in concert.

ENISA's threat picture

The audit landed the same week as a new Enisa report, published on September 22, which warned that dependencies in the supply chain are expanding the region's attack surface. The Enisa Threat Landscape 2026 report drew on analysis of 8257 incidents in the 2025 calendar year.

Among its findings, low-impact DDoS attacks accounted for 51% of recorded incidents last year, driven mainly by geopolitical tensions. Ransomware, however, remained the highest-impact short-term threat — a reminder that frequency and severity do not track together.

For the small number of intrusion-related incidents where a vector was identified — just 5% of them — Enisa said 60% stemmed from vulnerability exploitation. That figure speaks to the persistence of unpatched flaws as an entry point.

Public administration remained the most impacted sector at 32%, followed by business services at 9%, transport at 8%, manufacturing at 7%, and finance and banking at 6%. The dominance of the public sector is notable given that the audit's concerns center on coordination between government-level bodies.

  • €1.4bn ($1.6bn) — the EU's cybersecurity budget examined by the Court of Auditors
  • 51% — share of recorded incidents attributed to low-impact DDoS attacks in 2025
  • 5% — intrusion-related incidents for which a vector was identified
  • 60% — of those identified attacks traced to vulnerability exploitation
  • 32% — public administration's share as the most impacted sector
  • 8257 — incidents analyzed for the Enisa Threat Landscape 2026 report

Why the gaps matter

The auditors' central finding is not that Europe lacks cyber capability or funding. It is that the machinery for sharing what each part of the bloc knows is incomplete. In a large-scale incident, the difference between containment and escalation often comes down to how fast information moves between the organizations that hold pieces of the picture.

For businesses operating across the EU, this has a practical edge. The national CSIRTs and EU-CyCLONe are the bodies that would coordinate a cross-border response, and the audit suggests their cooperation is impaired by undefined roles and restrictive national laws. A company hit by a serious intrusion may find that the channels meant to help it — and to warn others — are slower or narrower than expected. The delayed alert system and its two idle hubs, ATHENA and ENSOC, compound that concern.

The vetting gap adds a second dimension. If organizations receiving EU cybersecurity funding are not screened, there is a risk that support intended to harden European defenses instead creates routes for outside influence. For recipients, the implication is that funding may come with closer scrutiny down the line; for the bloc, it suggests the program's safeguards lag its ambitions.

The combination of an audit describing incomplete coordination and a threat report describing an expanding attack surface suggests the EU's next challenge is less about adding money and more about making the existing structures talk to each other — with the agreements, classifications, and standards the auditors say are still missing. Whether that happens before the next major incident is the open question the report leaves behind.

#eu#cybersecurity#incident response#enisa#nis2#information sharing

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories