AI & TechBusinessCybersecurityNewswireTechnology

EU Auditors: Info Gaps Hinder Cyber Incident Response

▼ Summary

– The EU Court of Auditors criticized the union’s cybersecurity efforts, citing insufficient information exchange and undefined roles as major hindrances to detecting large-scale cyber incidents.
– The audit highlighted duplication of effort between the European Commission’s cyber-situation centre and ENISA, alongside delays in launching key hubs like ATHENA and ENSOC due to procurement issues.
– Concerns were raised about the lack of vetting for organizations receiving EU cybersecurity funding, which exposes them to potential intrusion or influence by non-EU states.
– Experts recommended that the EU adopt practices similar to CISA’s Automated Indicator Sharing to facilitate real-time, machine-readable defensive measures and rapid exchanges.
– A separate ENISA report identified low-impact DDoS attacks as the most frequent incident type, while ransomware remained the highest impact threat, with public administration being the most affected sector.

Cybersecurity coordination in the European Union is facing significant hurdles, according to a critical new assessment by the EU Court of Auditors. The institution highlighted that while the bloc’s €1.4bn ($1.6bn) cybersecurity budget has yielded some positive results, its overall effectiveness is severely compromised by an “Achilles heel” identified as the “insufficient exchange of information.”

The audit report points to structural and legal barriers that stifle cooperation between national Computer Security Incident Response Teams (CSIRTs) and the European Cyber Crisis Liaison Organisation Network (EU-CyCLONe). A primary issue is the absence of formally defined roles, which creates ambiguity in how these entities interact during crises. Furthermore, the slow transposition of the NIS2 directive into national legislation continues to drag down response capabilities. National security laws also impose restrictions on data sharing, further limiting the flow of critical intelligence across borders.

Operational Duplication and System Delays

Beyond inter-agency friction, the auditors uncovered inefficiencies within the EU’s own institutional framework. There is notable duplication of effort between the European Commission’s cyber-situation centre, established in 2022 with support from external providers, and the threat monitoring activities conducted by the EU agency ENISA. This overlap raises questions about resource allocation and strategic focus.

The report also criticized delays in launching the European Cybersecurity Alert System. Two key hubs, ATHENA and ENSOC, have failed to begin operations due to procurement issues. The auditors noted that essential infrastructure for the system remains incomplete: “In addition, the necessary cooperation agreements, a common classification system, and technical standards needed for the system to work were still lacking.”

Perhaps most concerning was the finding that organizations receiving EU cybersecurity funding were not undergoing vetting processes at the time of inspection. This gap leaves recipients vulnerable to potential intrusion or influence by non-EU states, creating a risk that sensitive security information could be inadvertently shared with foreign authorities.

Expert Recommendations and Threat Landscape

Industry experts argue that Europe must adopt more agile mechanisms for information sharing. Jacob Krell, senior director of secure AI solutions and cybersecurity at Suzu Labs, suggested that the EU should look to the United States’ CISA for guidance. He emphasized the need for automated, real-time data exchange and standardized protocols.

CISA’s Automated Indicator Sharing moves machine-readable indicators and defensive measures in real time,” he explained. “The Joint Cyber Defense Collaborative adds playbooks and rapid exchanges across government, industry, and international partners. Europe needs those functions tied to its existing institutions, with shared rules for confidence, urgency, and action.”

These criticisms coincide with a separate warning from ENISA regarding expanding supply chain vulnerabilities. The ENISA Threat Landscape 2026 report, released on September 22, indicates that dependencies are widening the region’s attack surface. Analysis of 8,257 incidents recorded in the 2025 calendar year revealed that low-impact DDoS attacks constituted 51% of all incidents, largely driven by geopolitical tensions. However, ransomware persisted as the highest impact short-term threat.

For the small fraction of intrusion-related incidents where vectors were identified (5%), 60% stemmed from vulnerability exploitation. In terms of sectoral impact, public administration remained the most targeted area, accounting for 32% of incidents. This was followed by business services (9%), transport (8%), manufacturing (7%), and finance/banking (6%).

(Source: Infosecurity Magazine)

Topics

eu cyber audit findings 98% information sharing gaps 95% operational delays and duplication 92% funding security risks 90% threat landscape analysis 88%
Show More