EU Cyber Shield Remains Non-Operational After €1.4B Investment, Auditors Warn

3 min read
Source: Euronews.com
EU Cyber Shield Remains Non-Operational After €1.4B Investment, Auditors Warn
Photo: Euronews.com
TL;DR

The European Court of Auditors (ECA) found that the EU’s €1.4 billion cybersecurity investment has failed to produce a functional early-warning system. The ATHENA and ENSOC alert hubs remain non-operational due to procurement delays and missing technical standards. Auditors identified poor information-sharing as the system's 'Achilles heel,' noting that no member state has classified an incident as 'large-scale' since 2016, meaning the EU’s crisis-escalation procedure has never been fully activated. The report also highlights overlapping mandates between ENISA and the Commission’s cyber situation centre, and warns that funding recipients are not independently vetted for hostile state influence.

Key points

  • The EU’s early-warning system for major cyberattacks, established under the Cyber Solidarity Act in February 2025, is not yet operational due to procurement delays and missing cooperation agreements.
  • The ECA found that the European Cybersecurity Competence Centre does not independently verify assessments of third-party ownership, potentially exposing sensitive infrastructure to hostile state influence.
  • No EU member state has classified a cybersecurity incident as 'large-scale' since 2016, meaning the EU’s crisis-escalation procedure has never been fully activated, despite major incidents like the 2024 CrowdStrike outage.
  • Auditors identified poor information-sharing as the central weakness, with only 14 cross-border incidents formally notified in 2025 by seven countries, compared to 322 incidents identified by ENISA.
  • The report recommends clarifying roles between overlapping EU bodies, improving information-sharing, and strengthening security checks on funding recipients to prevent high-risk third countries from accessing critical infrastructure.

Background

The EU has been strengthening its cybersecurity framework in recent years, including the adoption of the Cyber Blueprint in 2025 and the Cyber Resilience Act, which requires manufacturers to report severe security incidents within 24 hours. The European Commission recently proposed a new cybersecurity package to revise the Cybersecurity Act, including a risk-based supply chain security framework and increased funding for ENISA. These efforts aim to address gaps in the EU’s ability to detect and respond to major cyberattacks, but the ECA’s findings suggest that significant structural and operational challenges remain.

Why it matters

The EU’s inability to effectively detect and respond to major cyberattacks poses a significant risk to its critical infrastructure and digital economy. The lack of a functional early-warning system and poor information-sharing between member states could lead to widespread disruptions, as seen in the 2025 ransomware attack on Collins Aerospace, which forced major airports to revert to manual operations. Strengthening the EU’s cybersecurity framework is essential to protect against increasingly sophisticated cyber threats and to ensure the resilience of its digital infrastructure.

What to watch

The EU is expected to implement the recommendations from the ECA report, including improving information-sharing between EU networks, clarifying roles between overlapping bodies, and integrating the alert system into the wider cybersecurity landscape. The European Commission’s proposed cybersecurity package, which includes a risk-based supply chain security framework and increased funding for ENISA, is also expected to be a key focus in the coming months. Member states will also need to transpose the updated cybersecurity rules, including the NIS 2 Directive, to ensure effective implementation of the EU’s cybersecurity framework.

Share this article

Want the full story? Read the original reporting

Read on Euronews.com