Summary
- European auditors found that member-state information sharing remains a weakness in the EU response to significant cyber incidents.
- The review examined EU action between 2022 and 2025 as roughly €1.4 billion is committed to cybersecurity in the current budget period.
- Existing networks, agencies, and emergency mechanisms cannot provide a common operational picture when national authorities withhold or delay incident information.
Europe has spent years building shared structures for detecting and responding to cyber attacks, but a new audit has found that those mechanisms remain constrained by fragmented responsibilities and weak information flows between national authorities.
The European Court of Auditors examined how the EU detects and responds to significant and large-scale cybersecurity incidents, covering activity between 2022 and 2025. Its findings arrive after roughly €1.4 billion was committed to cybersecurity through the current EU budget and as the number of institutions and networks involved in cross-border response has continued to grow.
The central weakness is not the absence of another European body or legislative framework. Instead, auditors found that the system cannot work as intended when member states fail to provide timely, actionable information about incidents, while overlapping structures can complicate the path from a national attack to a coordinated European response.
That problem becomes acute during incidents affecting infrastructure or suppliers used across several countries, where attackers and software dependencies move more easily across borders than government reporting channels. A cyber incident may begin inside a private company but quickly disrupt aviation, healthcare, finance, public administration, or other services spread across multiple jurisdictions.
Shared infrastructure depends on shared information
The auditors highlighted a ransomware attack on an aviation technology provider in September 2025 that disrupted airports in London, Brussels, Berlin, Dublin, and elsewhere. Despite its cross-border impact, reporting on the audit indicates that none of the affected EU countries notified the European Union Agency for Cybersecurity or other member states through the relevant European mechanisms.
The episode exposes the difference between having a coordination architecture and feeding it with useful information. Europe now has the CSIRTs Network for national incident-response teams, EU-CyCLONe for large-scale cyber crises, ENISA, the Cybersecurity Alert System, and the Cybersecurity Emergency Mechanism, alongside national agencies and sector-specific authorities.
Those layers were built for different purposes and at different stages of European cyber policy, but each relies on information arriving quickly enough to establish a shared view of an attack. National authorities may also face legal, intelligence, security, or commercial restrictions when incidents touch sensitive infrastructure.
The Cyber Solidarity Act is intended to strengthen common detection and response, including through national and cross-border cyber hubs and a Cybersecurity Reserve capable of providing specialist support. Yet even substantial central capacity has limited value if national authorities hold back the underlying evidence needed to recognise that an incident is spreading across several countries.
Private-sector reporting is moving faster
The audit arrives as European regulation is tightening incident-reporting obligations on technology suppliers. The Cyber Resilience Act has begun introducing rapid notification requirements for manufacturers dealing with actively exploited vulnerabilities and severe incidents, while NIS2 expands obligations on organisations operating essential and important services.
Techopia recently examined the start of operational Cyber Resilience Act reporting, which places manufacturers on short notification clocks and routes reports through ENISA’s infrastructure. The contrast is difficult to ignore: technology companies are being required to provide information through increasingly standardised systems while the public coordination layer still faces persistent friction around national disclosure.
The Commission has acknowledged related weaknesses in its own work on the future of ENISA, including fragmentation in European situational awareness and pressure on an agency whose responsibilities have expanded as new cyber legislation has accumulated.
Implementation is therefore becoming the harder part of the policy problem. The EU already has rules, networks, agencies, and emergency mechanisms intended to connect national response systems, while the auditors argue that the information-sharing obligations within those structures need to work more consistently.
Organisations operating critical or cross-border services have a direct interest in whether that coordination functions. A supplier compromise can affect customers in several countries simultaneously, yet the quality of the response depends partly on how quickly national agencies establish that apparently separate incidents share the same cause, infrastructure, vulnerability, or component.
Europe’s cyber framework has become considerably denser since the original NIS Directive, and more capacity is still being added. The auditors’ findings suggest that its effectiveness will increasingly depend on whether the organisations inside that framework exchange enough information to behave like a common response system when an attack crosses a border.












