The European Union’s (EU) leading audit body has recently raised alarms regarding substantial “shortcomings” that are obstructing the region’s ability to effectively identify and respond to significant cyber incidents. According to a new report released by the EU Court of Auditors, the bloc’s substantial budget of €1.4 billion (approximately $1.6 billion) allocated for cybersecurity initiatives has made some headway. Nonetheless, the auditors highlight a critical flaw—namely, the insufficient exchange of information among key entities.
The report emphasizes that poorly defined roles and responsibilities are hindering cooperation between country-level Computer Security Incident Response Teams (CSIRTs) and the European Cyber Crisis Liaison Organization Network (EU-CyCLONe). This lack of clarity impedes efficient collaboration in addressing cyber threats and ultimately dilutes the overall effectiveness of the EU’s cybersecurity strategies.
Additionally, the audit sheds light on the slow transposition of the NIS2 directive into national law, indicating that the lag has a detrimental impact on the collective readiness and effectiveness of EU member states to combat cyber threats. Furthermore, national security regulations often restrict what information can be shared, adding another layer of complexity to an already convoluted network of cybersecurity operations.
The auditors criticize the duplication of efforts between the European Commission’s cyber-situation center—established in 2022 and supported by external providers—and the existing work carried out by the EU security agency, ENISA. The redundancy not only leads to inefficiencies but also complicates the EU’s approach to real-time threat monitoring and situational awareness.
Delays in the implementation of the European Cybersecurity Alert System are also a point of concern. Specifically, two operational hubs, ATHENA and ENSOC, have yet to commence functions due to ongoing procurement delays. The auditors noted that essential cooperation agreements, a common classification system, and necessary technical standards needed for the smooth operation of this system were still missing, pointing to a fundamental breakdown in planning and execution.
Another significant finding from the audit is the lack of vetting processes for organizations receiving EU cybersecurity funding. At the time of the investigation, these organizations were not being sufficiently scrutinized, leaving them exposed to potential intrusion or influence from non-EU states. This oversight raises alarms regarding the risk of sensitive security information being inadvertently shared with entities outside the EU.
Jacob Krell, a senior director specializing in secure AI solutions and cybersecurity at Suzu Labs, has urged the EU to learn from the best practices employed by the Cybersecurity and Infrastructure Security Agency (CISA) in the United States. He pointed out that CISA’s Automated Indicator Sharing initiative facilitates real-time exchanges of machine-readable indicators and defensive measures. Furthermore, he highlighted the value of the Joint Cyber Defense Collaborative, which fosters rapid exchanges and the creation of playbooks among government entities, industries, and international partners. Krell believes that the EU urgently requires similar frameworks connected to its existing institutions, emphasizing the need for shared rules governing confidence, urgency, and proactive action in cybersecurity.
The timely relevance of this situation is underscored by a separate report from ENISA, published on September 22, which warned that deepening dependencies within the supply chain are broadening the attack surface across the region. According to the ENISA Threat Landscape 2026 report, low-impact DDoS attacks comprised 51% of recorded incidents in the previous year, a number largely driven by geopolitical tensions. Nonetheless, ransomware continues to pose the highest impact short-term threat to various sectors.
In the report, ENISA noted that among the small fraction of intrusion-related incidents for which a vector could be identified—5%—a troubling 60% stemmed from exploited vulnerabilities. The findings highlight an urgent need for improvements in cybersecurity measures across the board.
Public administration emerged as the most affected sector, suffering 32% of incidents, followed by business services at 9%, transport at 8%, manufacturing at 7%, and finance/banking at 6%. The report encapsulates comprehensive analysis drawn from a total of 8,257 incidents recorded during the 2025 calendar year.
These findings reflect a pressing need for the EU to enhance its collaborative frameworks, clarify roles and responsibilities, and streamline processes to bolster cybersecurity resilience.
