Cybersecurity: Europe’s real weakness is information sharing
The European Court of Auditors is scrutinising the EU’s cyber-attack response system: few reports, insufficient data sharing and a European alert system that remains inactive. Ten years without a major, formally declared crisis
Is Europe ready to defend itself against significant, large-scale cyber-attacks? The European Court of Auditors’ key finding on this matter can be summarised as follows: the problem with European cybersecurity is not merely anticipating an attack. It is being able to recognise, in good time, that the attack has occurred. In other words, to understand quickly when a breach ceases to be a national issue and becomes a crisis involving several countries, we need timely alerts, shared information and common procedures. And it is precisely here, according to the European Court of Auditors, that the EU system continues to show its weaknesses.
The European Court of Auditors, led by Court President George-Marius Hyzler, examined between 2022 and 2025 how the EU identifies and manages the most serious cyber-security incidents: those that are ‘significant’, i.e. those capable of causing major disruption or damage, and ‘large-scale’ incidents, which affect several Member States and require a coordinated response. The auditors also carried out checks in Italia. The conclusion is that the European cooperation framework has grown, but remains only partially effective. The main point of concern is the exchange of information between Member States and EU bodies.
Over the years, Europe has built a complex system: a network of national CSIRTs, EU-CyCLONe for crisis management, ENISA, a pool of specialists and a European alert system. The Digital Europe programme is providing €1.4 billion for cybersecurity over the period 2021–2027. But the fuel that powers this machine is data. And often, that data does not circulate.
The most obvious case dates back to September 2025. A ransomware attack on Collins Aerospace’s systems caused disruption at Heathrow, Brussels, Berlin-Brandenburg and Dublin, forcing the airports to revert to manual procedures. Yet, according to the Court, no Member State formally classified the event as a significant or large-scale cross-border incident. There was no European-level escalation.
This is not an isolated case. In 2025, Member States submitted just 14 reports of significant cross-border incidents, originating from seven countries. There had been two in 2024, none in 2023 and three in 2022. And since the European mechanism was established, no incident has ever been formally classified as ‘large-scale’: not WannaCry, not NotPetya, nor the cyber blackout linked to CrowdStrike in 2024.


