European states are failing to share information about large-scale cyber security incidents with other members of the European Union (EU) bloc, weakening Europe’s ability to respond to cyber attacks.
The European Union’s auditors warn that barriers to sharing of information, including concerns about national security, are deterring countries in the EU from sharing information about cyber attacks with other member states.
The EU has allocated €1.4bn to cyber security through its Digital Europe programme, but the auditors warn that the measures have only been “partially” successful at allowing member states to improve their detection and response to major cyber security incidents.
The European Court of Auditors found that legal restrictions, concerns about national security, differences in national approaches and delays in the implementation of EU rules, meant information on cyber attacks is not being escalated.
The auditors found that EU member states had not shared information on significant cyber attacks with other EU states, meaning the European Union has been unable to coordinate responses to cyber attacks impacting multiple EU countries.
A ransomware attack in 2025 against Collins Aerospace caused widespread flight delays and cancellations in European airports, including Brussels, Berlin, Dublin and London Heathrow, but EU states did not share information about the attack.
Under the EU’s cyber security law, NIS2, more than 100,000 organisations across Europe are required to report cyber security incidents to their national authorities.
Auditor Frédéric Soblet said this information should be shared with other member states to allow organisations to urgently patch security vulnerabilities and to identify “indicators of compromise” that would show they are under attack.
The report calls for the EU to identify national security restrictions that prevent member states sharing information on cyber security incidents that could negatively impact the cyber resilience of the EU.
European cyber alert
The auditors recommend that Europe prioritises its delayed European cyber alert system to allow member states to share incidents and information on attacks in real-time in a way that respects national security.
“These incident reports should be in real time, processed, analysed and correlated, so that we know that when something is happening the information is shared immediately,” said Soblet.
Currently it can take weeks or months for the European Union Agency for Cybersecurity (Enisa) to receive information from member states about cyber incidents.
Auditor George-Marius Hyzler said the failure of EU member states and institutions to pass on information put a “spoke in the wheels” of cyber security resilience. “The European Commission has to work on the trust that has to be built up … to ensure that information does flow.”
The report also calls for better coordination to avoid duplication of work among EU cyber security bodies.
The auditors found that there was a lack of cooperation between Europe’s network of Computer Security Incident Response Teams (CSIRTs) and EU-Cyclone, an informal network set up to coordinate on cyber crises.
The European cyber security alert system is not yet in operation because of procurement delays, a lack of cooperation agreements, and a lack of agreed common classification systems and technical standards.
The auditors also found weaknesses in the way some organisations in receipt of cyber security funding were checked for eligibility for funding, presenting a risk that sensitive security information could be shared with non-EU authorities.

