Skip to main content
CybersecurityIncident Response

EU Cybersecurity Efforts Hindered by Information-Sharing Gaps

A dimly lit government briefing room with a laptop and papers on a large wooden table.

"The insufficient exchange of information."

The EU Court of Auditors' diagnosis

The EU Court of Auditors has concluded that the bloc’s cybersecurity effort, despite a budget of €1.4bn, is hampered by critical shortcomings — most notably failures of information-sharing that weaken detection and response to large-scale cyber incidents. In a new report, the auditors said the funding "is doing some good," but identified an Achilles heel in how data and alerts move across the system.

European Cyber Crisis Liaison Organisation Network (EU‑CyCLONe) and national CSIRTs

The auditors flagged a lack of formally defined roles as a specific barrier to cooperation between country-level computer security incident response teams (CSIRTs) and the European Cyber Crisis Liaison Organisation Network (EU‑CyCLONe). The report also linked the slow transposition of the NIS2 directive into national law and national security laws that limit what information can be shared to the overall shortfall in cross-border coordination.

Duplication: the Commission's cyber‑situation centre and ENISA

The audit found overlap between the European Commission’s cyber‑situation centre — established in 2022 and supported by external providers — and the work performed by the EU cybersecurity agency ENISA in monitoring threats and building situational awareness. The auditors described this as duplication of effort, an inefficiency that complicates who watches which sensors and who produces what shared picture for decision-makers.

European Cybersecurity Alert System: ATHENA and ENSOC delays

The report criticized delays in bringing the European Cybersecurity Alert System to life. Two hubs within that system, ATHENA and ENSOC, had not begun operations at the time of the auditors’ inspection because of procurement delays. The audit further noted that necessary cooperation agreements, a common classification system, and the technical standards needed for the alert system to function were still lacking.

ENISA Threat Landscape 2026: incidents, vectors, and sectors

On September 22, ENISA published its Threat Landscape 2026 report, which the auditors’ findings sit alongside. ENISA reported that dependencies in the supply chain are expanding the region’s attack surface. Its analysis of 8,257 incidents in the 2025 calendar year showed low‑impact distributed denial‑of‑service (DDoS) attacks accounted for 51% of recorded incidents, a rise ENISA attributes mainly to geopolitical tensions. Ransomware remained the highest‑impact short‑term threat.

ENISA also examined intrusion-related incidents where a vector was identified — a small subset, 5% of incidents — and found that 60% of those were caused by vulnerability exploitation. The sectors most affected in 2025 were public administration (32%), business services (9%), transport (8%), manufacturing (7%), and finance/banking (6%).

What this means for technologists, policymakers, and affected enterprises

  • Technologists and security teams: expect ambiguity about who receives and acts on shared indicators. The auditors’ finding of insufficient exchange and duplication between the Commission’s centre and ENISA implies that machine-readable, standardized sharing and joint playbooks are not yet institutionalized across the EU architecture.
  • Policymakers and regulators: the slow national transposition of NIS2 and the absence of key cooperation agreements and classification standards are concrete implementation gaps. The auditors also highlighted that national security laws are restricting cross-border information flows, a legal constraint that will need policy attention.
  • Affected enterprises and procurement leads: the audit found that organisations receiving EU cybersecurity funding were not being vetted at the time of inspection, exposing them to "risk of intrusion or influence" by non‑EU states and the potential for sensitive security information to be shared outside the EU. Procurement delays that have stalled ATHENA and ENSOC underscore operational friction in standing up EU‑level capabilities.

Outside voices in the report point to tangible options. Jacob Krell, senior director of secure AI solutions and cybersecurity at Suzu Labs, urged emulation of U.S. models: “CISA’s Automated Indicator Sharing moves machine-readable indicators and defensive measures in real time,” he said, adding that “the Joint Cyber Defense Collaborative adds playbooks and rapid exchanges across government, industry, and international partners. Europe needs those functions tied to its existing institutions, with shared rules for confidence, urgency, and action.”

The auditors leave a clear ledger of unfinished work: statutory transposition, vetting of funded organisations, procurement to activate ATHENA and ENSOC, cooperation agreements, and common classification and technical standards. ENISA’s incident counts and breakdown of vectors and sectors underline that the threat environment is active and shifting, with supply‑chain dependencies and widespread low‑impact DDoS shaping the landscape.

With defined roles, standardized sharing, and vetted partners still pending, the practical question the report hands to EU decision-makers is precise: will the bloc translate its €1.4bn of cybersecurity investment into an operational, trusted, and integrated alert and response fabric that connects national CSIRTs, EU‑level centres, and industry defenders — or will gaps in law, procurement, and governance keep the picture fragmented?

Source: infosecurity-magazine.com — EU Auditors Warn Information‑Sharing Gaps Are Hindering Cyber Incident Response