TheCyberExpress

EU Cybersecurity Incidents Expose Gaps In Response


The European Union’s ability to detect and respond to EU cybersecurity incidents faces significant gaps, particularly in information-sharing and coordination between national and EU-level bodies, according to a new report by the European Court of Auditors (ECA). The auditors said the EU has made progress in developing a cybersecurity cooperation framework, but several measures needed to support an effective response to significant and large-scale incidents are still incomplete.

Cybersecurity incidents can disrupt public services, businesses, critical infrastructure and the EU’s internal market. While member states remain primarily responsible for responding to such incidents, the EU has a role when attacks cause major disruption, significant financial losses or substantial harm, or when incidents affect several countries and exceed the response capacity of a single member state.

EU Cybersecurity Incidents Face Information-Sharing Gaps

The ECA identified insufficient information exchange as a major weakness in the EU’s cybersecurity response system. The Cyber Blueprint, adopted in 2025, largely clarifies roles and responsibilities for managing major cybersecurity crises. However, the cooperation between two key EU cyber networks has not yet been formally defined.

The auditors said this affects cooperation between the CSIRTs network, which brings together national teams responsible for handling cyber incidents, and EU-CyCLONe, which supports cooperation during EU-level cyber crises.

Information-sharing is also affected by differences in national security laws and the ongoing implementation of updated EU cybersecurity rules, including the NIS 2 Directive. According to the auditors, these factors can make it harder for EU networks to identify threats early and coordinate an effective response.

“The EU has made progress in building a cybersecurity cooperation framework, but it is not yet working as effectively as it should,” said George-Marius Hyzler, the ECA Member responsible for the audit. “When a serious cyber incident occurs, timely and actionable information is essential. Without it, networks and mechanisms lose much of their added value.”

European Cybersecurity Alert System Still Delayed

The audit also found that the European Cybersecurity Alert System was not operational at the time of the assessment. Two hubs examined by the auditors, ATHENA and ENSOC, had not started operating because of procurement delays.

The system also lacked several elements needed for operation, including cooperation agreements, a common classification system and technical standards.

The findings come as the EU continues to invest in cybersecurity. Under the 2021-2027 EU budget, €1.4 billion has been allocated to cybersecurity through the Digital Europe Programme, the EU’s main source of cybersecurity funding.

Overlap Among EU Cybersecurity Bodies

The ECA also identified overlapping responsibilities among some EU bodies involved in monitoring cybersecurity threats.

The European Commission’s cyber situation centre, established in 2022 and largely supported by external providers, carries out work that the auditors said partly duplicates existing capabilities at the European Union Agency for Cybersecurity (ENISA). These capabilities include monitoring threats and developing cybersecurity situational awareness.

The auditors called for better coordination to reduce duplication and strengthen the overall effectiveness of the EU’s cybersecurity framework.

Funding Checks Raise Security Concerns

The report also highlighted weaknesses in checks on some organisations receiving EU cybersecurity funding.

These checks are intended to reduce risks linked to intrusion or influence by non-EU states and prevent sensitive security information from being shared with non-EU authorities. However, while grant beneficiaries are responsible for assessing the ownership and control of third parties receiving financial support, the European Cybersecurity Competence Centre does not verify those assessments.

The ECA warned that this could expose sensitive infrastructure, operational data and security-critical technologies to security risks.

The audit covered the period from 2022 to 2025 and assessed whether EU actions effectively supported the detection of and response to significant and large-scale cybersecurity incidents. Audit missions were conducted in Ireland, Greece and Italy.



Source link