THE EU Court of Auditors has criticised shortcomings in the bloc’s ability to detect and respond to large-scale cyber incidents. Its report said the EU’s €1.4bn cybersecurity budget is delivering benefits, but that insufficient information-sharing remains a major weakness.
Cooperation between national computer security incident response teams and the European Cyber Crisis Liaison Organisation Network (EU-CyCLONe) is being hindered by unclear roles, slow implementation of NIS2 into national law and national security rules that restrict the information authorities can share.
Auditors also identified duplicated work between the European Commission’s cyber-situation centre and the European Union Agency for Cybersecurity (ENISA). The European Cybersecurity Alert System has been delayed by procurement problems, with its ATHENA and ENSOC hubs not yet operational at the time of inspection. Required cooperation agreements, a shared classification system and technical standards were also absent.
In addition, organisations receiving EU cybersecurity funding were not being vetted, creating a risk of intrusion or influence by non-EU states and possible disclosure of sensitive information to non-EU authorities. A cybersecurity executive suggested adopting more automated, machine-readable information-sharing and joint response mechanisms.
The findings followed an ENISA report published on 22 September, based on 8,257 incidents recorded during 2025. It said low-impact DDoS attacks represented 51% of incidents, while ransomware remained the highest-impact short-term threat. Of the 5% of intrusion-related incidents with an identified attack vector, 60% resulted from vulnerability exploitation. Public administration was the most affected sector, accounting for 32% of incidents.