Skip to content
MarketsIndicesCommoditiesFXRates
Technology

EU Cyber Defences Only Partially Effective, Auditors Warn

An audit by the European Court of Auditors found EU cybersecurity efforts are only partially effective due to poor data sharing and implementation delays.

EU Cyber Defences Only Partially Effective, Auditors Warn
Ciberataques e burlas digitais aumentam, com prejuízos e novas formas de fraude
Cyberattacks and digital scams increase, with losses and new forms of fraud Photo: Getty Images

European Union cybersecurity measures are only partially effective due to data sharing flaws and execution delays, the European Court of Auditors warned on Monday.

In a report evaluating the bloc's response to cyber threats, external auditors concluded that EU actions only partly facilitate the detection of and response to significant, large-scale incidents. The watchdog stated that scant data sharing, information reporting deficiencies, and considerable execution delays prevent European networks and emergency mechanisms from reaching their full potential.

Although the European Union has gradually developed a cooperation framework among its 27 member states, efforts to complete the architecture remain ongoing. Funded projects face operational problems and delays, while the overall performance monitoring framework suffers from notable deficiencies.

Working methods and network fragmentation

To manage digital emergencies, the Council of the European Union adopted the Cybersecurity Action Plan in 2025. The initiative established the European framework for computer crisis management and largely clarified institutional roles and responsibilities across the bloc.

However, auditors noted that a joint working method has not yet been formalized between two primary cybersecurity bodies. The national Computer Security Incident Response Teams network, created in 2016 to handle technical incidents, lacks a structured operational link with EU-CyCLONe, a network officialized in 2023 to coordinate political and operational responses during major cyber crises.

The European Court of Auditors identified insufficient information sharing across these channels as a critical weakness in the union's defensive system. Auditors found that data exchanges remain scarce, driven by delays in transposing the EU directive on measures for a high common level of cybersecurity across the Union.

Information sharing has also been hindered by difficulties in determining whether an incident carries cross-border impacts, as well as restrictive national security legislation in individual member states that limits data distribution to external partners.

Warning on crisis response and funding control

George-Marius Hyzler, the audit court member responsible for the report, stressed that the established system does not yet function as intended. He noted that during a serious disruption or attack, access to useful and timely information makes all the difference, warning that the system holds little value without it.

To reinforce digital infrastructure, the EU allocated approximately 1.4 billion euros to cybersecurity through the Digital Europe Programme under the current 2021 to 2027 multi-year budget. The funding program supports public administrations, businesses, and research bodies in deploying advanced technology.

Despite the financial commitment, the audit highlighted control weaknesses regarding certain organizations receiving European funds. Specifically, auditors cited inadequate safeguards to reduce the risk of interference from third countries and to prevent sensitive security information from being shared with authorities outside the EU.

Scope of the audit

The comprehensive audit was conducted between 2022 and 2025 to evaluate how effectively EU measures detect and handle large-scale cyber incidents. As part of their investigation, auditors carried out field visits to Ireland, Greece, and Italy to examine national capabilities and cooperation mechanisms on the ground.

Related

Leave a comment

Your email address will not be published. Required fields are marked *