EU Struggles to Respond Effectively to Major Cyber Incidents, Auditors Say | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


The European Union can not respond effectively to major cybersecurity incidents because of insufficient information sharing, the European Court of Auditors said in a report published on Monday.

George-Marius Hyzler, the auditor responsible for the report, said timely and actionable information was essential during serious cybersecurity incidents. Without it, he said, the effectiveness of EU cooperation networks and response mechanisms was significantly reduced.

The Luxembourg-based institution said cyber incidents could disrupt public services, businesses, critical infrastructure, and the functioning of the EU single market. The EU has therefore increased its spending on cybersecurity, while its 2025 cybersecurity plan largely clarified the roles and responsibilities of the bodies involved in responding to major cyber crises.

However, the auditors say formal arrangements governing cooperation between the EU’s two main cybersecurity networks have still not been established. This makes coordination between the CSIRT network, which brings together national incident response teams, and EU-CyCLONe, which supports the management of large-scale cyber crises, more difficult.

The auditors also found that some member states had not yet fully implemented updated EU cybersecurity rules. At the same time, national security legislation can restrict which information can be shared.

These factors can make it harder for EU networks to identify threats early and coordinate an effective response, the report said.

The Court of Auditors also identified overlapping responsibilities among some EU bodies involved in monitoring cybersecurity threats.

It found shortcomings in security checks carried out on recipients of EU funding. Such checks are intended, among other things, to prevent non-EU countries from gaining influence over funded projects or accessing sensitive security information.

According to the auditors, however, the European Cybersecurity Competence Centre does not verify beneficiary assessments concerning the ownership and control structures of third parties receiving EU funding.

The Court of Auditors recommended improving information sharing, reducing duplicated work among EU institutions, putting the European cybersecurity alert system into operation and strengthening security checks on beneficiaries of EU funding.


Related articles:

At a time when public debate is increasingly polarized and superficial, Hungarian Conservative remains committed to depth, intellectual honesty, and independent conservative thought.

Producing high-quality journalism requires resources. Your contribution helps us expand our coverage, reach new audiences, and keep our content accessible.

Please consider supporting our mission.

Donate Now



——————————————————-


Click Here For The Original Source.