THE European Union has allocated €1.4 billion to cyber-defence efforts, but auditors say key safeguards and an early-warning system for major attacks remain incomplete. The findings come from a report published on Monday by the European Court of Auditors (ECA), which examined the EU’s ability to detect and respond to significant cybersecurity incidents between 2022 and 2025.
The ECA said that, when funding is passed to third parties, there is no independent check to establish whether it could reach organisations exposed to influence from hostile states. The audit also found that the European Cybersecurity Alert System is not yet operational, around 20 months after its planned development. Its two intended hubs, ATHENA and ENSOC, still lack the tools needed to detect threats and share information, following repeated procurement delays.
Agreements governing cooperation, a common classification system and the technical standards required to run the network were also missing, according to the auditors.