EU Cyber Defence Undermined by Poor Information Sharing, Auditors Find
The EU Court of Auditors has found that despite a €1.4 billion cybersecurity budget, the union's ability to respond to large-scale cyber incidents is being undermined by poor information exchange. The report points to a lack of clearly defined roles between national incident response teams and the EU Cyber Crisis Liaison Network, slow adoption of the NIS2 directive into national law, and national security rules that restrict what can be shared across borders.
The auditors also identified duplicated efforts between the European Commission's cyber-situation centre and the EU's cybersecurity agency, Enisa, as both work on threat monitoring. Delays to the European Cybersecurity Alert System were also flagged, with two planned hubs still not operational due to procurement issues, and key agreements, classification systems and technical standards still missing. Separately, the audit raised concerns that organisations receiving EU cybersecurity funding were not being properly vetted, creating a risk of foreign interference or exposure of sensitive information.
Industry experts suggest the EU could learn from models like the US CISA's Automated Indicator Sharing programme, which shares threat data in real time, paired with structured playbooks for coordinated action. The findings come alongside a separate Enisa report warning that supply chain dependencies are expanding Europe's overall cyber attack surface.