Zero Day Room
Live
Defence

EU Auditors Cite Information-Sharing Gaps in Cyber Response

The EU Court of Auditors warns that insufficient information exchange and undefined roles are hindering the bloc's ability to detect and respond to major

The EU Court of Auditors warns that insufficient information exchange and undefined roles are hindering the bloc's...

The European Union's €1.4 billion ($1.6 billion) cybersecurity budget is being undermined by poor information sharing, according to the bloc's top audit institution. The EU Court of Auditors identified this as a critical weakness in a new report, stating it hinders detection and response to large-scale cyber incidents.

Formally defined roles are lacking, hampering cooperation between national Computer Security Incident Response Teams (CSIRTs) and the European Cyber Crisis Liaison Organisation Network (EU-CyCLONe). The auditors also noted that national security laws restrict what information can be shared. Furthermore, the slow adoption of the updated NIS2 directive into national law is having a negative impact.

Duplication and Delays

The report found duplication of effort between the European Commission's cyber-situation centre and the EU security agency Enisa. Both entities monitor threats and build situational awareness. The audit also criticized delays to the European Cybersecurity Alert System.

Two hubs for the system, named ATHENA and ENSOC, have not begun operations due to procurement delays. The necessary cooperation agreements, a common classification system, and technical standards were also missing at the time of the audit.

Funding and Foreign Influence Risks

A separate but related risk concerns EU cybersecurity funding. The auditors warned that, at their time of inspection, organizations receiving this funding were not being vetted. This leaves them exposed to a "risk of intrusion or influence" by non-EU states. It could potentially lead to sensitive security information being shared with non-EU authorities.

Jacob Krell, senior director of secure AI solutions and cybersecurity at Suzu Labs, suggested the EU look to the US for a model. "CISA’s Automated Indicator Sharing moves machine-readable indicators and defensive measures in real time," he explained. He added that Europe needs similar functions tied to its existing institutions.

ENISA Report Highlights Threat Landscape

The auditors' warning coincides with a new ENISA threat report published on September 22. The ENISA Threat Landscape 2026 report states that dependencies in the supply chain are expanding the region's attack surface. It is based on an analysis of 8,257 incidents in the 2025 calendar year.

For the small number of intrusion-related incidents where a vector was identified (5%), ENISA said 60% stemmed from vulnerability exploitation. The report also provided a breakdown of the most impacted sectors from recorded incidents.

SectorPercentage of Incidents
Public Administration32%
Business Services9%
Transport8%
Manufacturing7%
Finance / Banking6%

Low-impact DDoS attacks accounted for 51% of recorded incidents last year, driven mainly by geopolitical tensions. However, ENISA assessed that ransomware remained the highest impact short-term threat.

Related coverage

More from Defence