EU auditors expose critical flaws in €1.4bn cyber defense network
The European Court of Auditors (ECA) has revealed that the EU’s €1.4 billion cybersecurity investment lacks independent verification, leaving sensitive infrastructure vulnerable to hostile state influence. The audit highlights that the EU’s early-warning system is non-functional due to procurement delays, and that member states fail to share critical incident data, rendering the bloc’s crisis response mechanisms ineffective.
Key points
- The ECA found that the European Cybersecurity Competence Centre does not independently verify third-party ownership of grant recipients, risking exposure to hostile states.
- The EU’s ATHENA and ENSOC alert hubs remain non-operational due to missing technical standards and procurement delays.
- No member state has classified a cyber incident as 'large-scale' since 2016, meaning the EU’s crisis escalation procedure has never been fully activated.
- Only 14 cross-border incidents were formally notified in 2025, despite ENISA identifying 322 incidents affecting multiple member states the previous year.
- The European Commission’s cyber situation centre overlaps with ENISA’s mandate, creating inefficiencies in threat monitoring.
Background
This audit follows the 2025 adoption of the Cyber Blueprint and the Cyber Solidarity Act, which aimed to establish a unified monitoring network. It also occurs amid recent EU proposals to revise the Cybersecurity Act, including stricter supply chain security and increased funding for ENISA, reflecting ongoing efforts to address the very gaps identified in this report.
How outlets are covering it
Euronews emphasizes the security risks of unverified funding and the non-functional state of the alert system. Cybernews highlights the tension between the ECA’s findings and the European Commission’s defense that information sharing relies on trust rather than legal obligation. Silicon Republic focuses on the specific gaps in information sharing among member states like Ireland, Greece, and Italy, noting that national security rules often limit data exchange, exacerbating the 'Achilles heel' of the EU’s cyber defense.
Why it matters
The failure to verify funding recipients and share incident data leaves critical EU infrastructure exposed to state-sponsored cyberattacks. Without a functional early-warning system or consistent cross-border reporting, the EU cannot mount a coordinated response to large-scale threats, undermining its digital sovereignty and economic stability.
What to watch
The ECA recommends clarifying cooperation between EU networks, improving information sharing, and strengthening security checks on funding. The European Commission has acknowledged the findings and will consider them, while ongoing legislative revisions to the Cybersecurity Act may address supply chain vulnerabilities and ENISA’s budget.
- The EU spent billions on a cyberattack shield — nobody checked if it worked Euronews.com
- Poor data sharing undermining EU cyber defences, auditors say Reuters
- EU cybersecurity system slowed by delays, auditors say Cybernews
- Member states not sharing info creates security gaps – auditors siliconrepublic.com
- THE HACK: Auditors slam poor EU cyber response coordination euractiv.com
Want the full story? Read the original reporting
Read on Euronews.com