EU Audit Warns of Critical Cybersecurity Gaps Across the Union

[2m 6s read]

A new report by the European Court of Auditors (ECA) raises significant concerns about the European Union’s ability to detect, assess and respond to major cybersecurity incidents. Despite increased investment and a more structured cooperation framework, the ECA concludes that the EU’s current mechanisms remain operationally insufficient to address large‑scale cyber threats that can disrupt public services, businesses, critical infrastructure and the functioning of the single market.  

Cyber incidents that cause substantial disruption, economic damage or harm to individuals fall under the category of major cybersecurity incidents, while attacks affecting multiple Member States and exceeding national response capabilities are classified as large‑scale incidents. Although Member States retain primary responsibility for handling such events, the EU plays a crucial role when threats escalate beyond national capacity.

Under the 2021–2027 budget, the EU has significantly increased its cybersecurity investment, with the Digital Europe Programme allocating €1.4 billion to strengthen capabilities across the Union. Yet, according to the ECA, the effectiveness of these investments is undermined by structural gaps in information‑sharing, coordination and operational readiness.

George‑Marius Hyzler, the ECA Member responsible for the audit, notes that the system’s “Achilles’ heel” is the lack of timely and actionable information exchange. The EU’s 2025 Cybersecurity Strategy clarifies roles and responsibilities for managing major cyber crises, but cooperation between the two core EU networks — the CSIRT Network, composed of national incident response teams, and EU‑CyCLONe, the EU‑level crisis coordination network — has not yet been formally defined. This gap weakens Europe’s ability to detect threats early and coordinate an effective response.

The situation is further complicated by delays in transposing the updated EU cybersecurity rules, including the NIS2 Directive, into national legislation. In several Member States, national security laws restrict the type and volume of information that can be shared, limiting the operational value of EU‑level cooperation.

The ECA also identifies overlaps in responsibilities among EU bodies tasked with monitoring cyber threats. The European Commission’s Cyber Situational Awareness Centre, established in 2022 and largely supported by external contractors, performs activities that partially overlap with the existing threat‑monitoring capabilities of the EU Agency for Cybersecurity (ENISA). Without clear delineation of tasks, the added value of these structures is diminished.

A particularly concerning finding is that the European Cybersecurity Alert System — a key component of the EU’s crisis‑response architecture — is still not operational. The two nodes examined by the auditors, ATHENA and ENSOC, had not begun functioning due to delays in procurement procedures. Critical elements such as cooperation agreements, a unified classification system and technical standards were also missing, preventing the system from reaching operational readiness.

The audit further highlights weaknesses in the security checks applied to organisations receiving EU cybersecurity funding. These checks are intended to mitigate risks related to foreign state influence or access to sensitive information. However, while grant beneficiaries are responsible for assessing ownership structures and third‑party involvement, the European Cybersecurity Competence Centre does not verify these assessments. As a result, sensitive infrastructure, operational data and security‑critical technologies could be exposed to external risks.

In an era where cyberattacks represent a systemic threat to economic stability, public administration and critical infrastructure, the ECA’s findings serve as a clear warning: Europe has made progress, but its cybersecurity architecture is not yet prepared for a large‑scale crisis. Strengthening information‑sharing, finalising legislative and operational frameworks, and ensuring the full activation of EU‑level mechanisms are now essential steps for safeguarding Europe’s digital resilience.

Χορηγούμενο
AKTINOVOLIA
Χορηγούμενο
Cargo
Προσφορά B Προσφορά C
Προσφορά Α Προσφορά B Προσφορά C
Hide Ads for Premium Members by Subscribing
Hide Ads for Premium Members. Hide Ads for Premium Members by clicking on subscribe button.
Subscribe Now