Cyber security

Cybersecurity: Europe’s real weakness is information sharing

The European Court of Auditors is scrutinising the EU’s cyber-attack response system: few reports, insufficient data sharing and a European alert system that remains inactive. Ten years without a major, formally declared crisis

Protezione della riservatezza dei dati dell'Unione europea (Alamy Stock Photo)

3' min read

Translated by AI
Versione italiana

3' min read

Translated by AI
Versione italiana

Is Europe ready to defend itself against significant, large-scale cyber-attacks? The European Court of Auditors’ key finding on this matter can be summarised as follows: the problem with European cybersecurity is not merely anticipating an attack. It is being able to recognise, in good time, that the attack has occurred. In other words, to understand quickly when a breach ceases to be a national issue and becomes a crisis involving several countries, we need timely alerts, shared information and common procedures. And it is precisely here, according to the European Court of Auditors, that the EU system continues to show its weaknesses.

The European Court of Auditors, led by Court President George-Marius Hyzler, examined between 2022 and 2025 how the EU identifies and manages the most serious cyber-security incidents: those that are ‘significant’, i.e. those capable of causing major disruption or damage, and ‘large-scale’ incidents, which affect several Member States and require a coordinated response. The auditors also carried out checks in Italia. The conclusion is that the European cooperation framework has grown, but remains only partially effective. The main point of concern is the exchange of information between Member States and EU bodies.

Loading...

Over the years, Europe has built a complex system: a network of national CSIRTs, EU-CyCLONe for crisis management, ENISA, a pool of specialists and a European alert system. The Digital Europe programme is providing €1.4 billion for cybersecurity over the period 2021–2027. But the fuel that powers this machine is data. And often, that data does not circulate.

The most obvious case dates back to September 2025. A ransomware attack on Collins Aerospace’s systems caused disruption at Heathrow, Brussels, Berlin-Brandenburg and Dublin, forcing the airports to revert to manual procedures. Yet, according to the Court, no Member State formally classified the event as a significant or large-scale cross-border incident. There was no European-level escalation.

This is not an isolated case. In 2025, Member States submitted just 14 reports of significant cross-border incidents, originating from seven countries. There had been two in 2024, none in 2023 and three in 2022. And since the European mechanism was established, no incident has ever been formally classified as ‘large-scale’: not WannaCry, not NotPetya, nor the cyber blackout linked to CrowdStrike in 2024.

Part of the problem is regulatory. NIS2, which significantly expands the number of organisations subject to security and notification requirements, was due to be transposed by October 2024. Delays have slowed down the roll-out of the system. Furthermore, in some countries, national security regulations restrict the information that can be shared across borders.

The European early-warning system was also not yet operational at the time of the audit. The two initiatives examined, ATHENA and ENSOC – the latter involving Italian participation – were held back by delays in procurement. There was also a lack of cooperation agreements, a common classification of incidents and shared technical standards.

The Court also highlights overlaps between the Commission’s IT Situation Centre and ENISA in the monitoring of threats. It also raises another issue regarding funding: in cases where beneficiaries distribute funds to third parties, the ECCC does not directly verify assessments of ownership and control, which could pose risks to sensitive data and infrastructure.

“When a serious cyber incident occurs, timely and actionable information is essential,” notes Hyzler. Without it, networks and procedures lose much of their value.

This is perhaps the most important finding in the report. For years, European cybersecurity has been portrayed as a matter of technology and defences. The Court shifts the focus: a country may have sensors, specialists and operations centres. But if one country detects something and the others are unaware of it, the problem is no longer a technological one. It is an information issue.

Copyright reserved ©
Loading...
  • Luca Tremolada

    Luca TremoladaGiornalista

    Luogo: Milano via Monte Rosa 91

    Lingue parlate: Inglese, Francese

    Argomenti: Tecnologia, scienza, finanza, startup, dati

    Premi: Premio Gabriele Lanfredini sull’informazione; Premio giornalistico State Street, categoria "Innovation"; DStars 2019, categoria journalism

Loading...

Brand connect

Loading...

Newsletter

Notizie e approfondimenti sugli avvenimenti politici, economici e finanziari.

Iscriviti