Report exposes EU vulnerabilities in responding to major cyberattacks | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


A report from the European Court of Auditors, published on September 21, 2026, warns that the lack of information exchange and delays in certain projects reduce the effectiveness of community protection.

The audit, which analyzes actions carried out between 2022 and 2025, identifies issues that may hinder the response to incidents capable of paralyzing public services, compromising critical infrastructures, or causing significant economic losses.

The study includes visits by auditors to Ireland, Greece, and Italy.

Lack of information weakens the European response

The main problem identified is the insufficient circulation of information among the agencies responsible for managing threats.

Although cooperation structures exist, the necessary data to anticipate attacks and make decisions do not always reach their recipients in time.

“The EU has made progress in establishing a cooperation framework for cybersecurity, but it has not yet reached its full potential,” says George-Marius Hyzler, a member of the European Court of Auditors responsible for the audit.

The report especially examines the coordination between the network of national computer security incident response teams, known as CSIRT, and EU-CyCLONe, created to facilitate the management of major cyber crises.

Despite the fact that the 2025 Cybersecurity Master Plan contributed to delineating the responsibilities of the different actors, formal agreements regulating collaboration between both networks are still lacking.

Adding to this situation is that some member states continue to adapt their legal systems to the NIS 2 Directive. Additionally, certain national security-related restrictions limit the information that can be shared with other countries.

A European alert system that is still not operational

One of the most relevant findings concerns the European Cybersecurity Alert System. At the time of the audit, this infrastructure, designed to improve early threat detection, had not yet started to operate.

The two centers analyzed, ATHENA and ENSOC, remained inoperative due to delays in procurement procedures. Cooperation agreements, common incident classification, and necessary technical specifications had also not been completed.

The Court also questions the distribution of functions among certain European agencies.

The cyber situation center created by the European Commission in 2022 relies considerably on external providers, whose activities partially overlap with ENISA’s threat monitoring capabilities.

This duplication can generate inefficiencies and highlights the need to better delineate institutional responsibilities.

Deficiencies in controls of funded projects

The audit also points to potential risks related to organizations receiving community funding to develop cybersecurity projects.

The European Cybersecurity Competence Center does not verify the ownership and control assessments conducted by grant beneficiaries when providing financial support to third parties.

This situation could facilitate the exposure of sensitive infrastructures, operational information, or strategic technologies to foreign influences.

Auditors call for more rigorous controls, effective institutional coordination, and the implementation of the pending alert system. They also consider it essential to improve information transmission so that countries can act jointly in response to incidents that exceed their national capabilities.

A report from the European Court of Auditors, published on September 21, 2026, warns that the lack of information exchange and delays in certain projects reduce the effectiveness of community protection.

The audit, which analyzes actions carried out between 2022 and 2025, identifies issues that may hinder the response to incidents capable of paralyzing public services, compromising critical infrastructures, or causing significant economic losses.

The study includes visits by auditors to Ireland, Greece, and Italy.

Lack of information weakens the European response

The main problem identified is the insufficient circulation of information among the agencies responsible for managing threats.

Although cooperation structures exist, the necessary data to anticipate attacks and make decisions do not always reach their recipients in time.

“The EU has made progress in establishing a cooperation framework for cybersecurity, but it has not yet reached its full potential,” says George-Marius Hyzler, a member of the European Court of Auditors responsible for the audit.

The report especially examines the coordination between the network of national computer security incident response teams, known as CSIRT, and EU-CyCLONe, created to facilitate the management of major cyber crises.

Despite the fact that the 2025 Cybersecurity Master Plan contributed to delineating the responsibilities of the different actors, formal agreements regulating collaboration between both networks are still lacking.

Adding to this situation is that some member states continue to adapt their legal systems to the NIS 2 Directive. Additionally, certain national security-related restrictions limit the information that can be shared with other countries.

A European alert system that is still not operational

One of the most relevant findings concerns the European Cybersecurity Alert System. At the time of the audit, this infrastructure, designed to improve early threat detection, had not yet started to operate.

The two centers analyzed, ATHENA and ENSOC, remained inoperative due to delays in procurement procedures. Cooperation agreements, common incident classification, and necessary technical specifications had also not been completed.

The Court also questions the distribution of functions among certain European agencies.

The cyber situation center created by the European Commission in 2022 relies considerably on external providers, whose activities partially overlap with ENISA’s threat monitoring capabilities.

This duplication can generate inefficiencies and highlights the need to better delineate institutional responsibilities.

Deficiencies in controls of funded projects

The audit also points to potential risks related to organizations receiving community funding to develop cybersecurity projects.

The European Cybersecurity Competence Center does not verify the ownership and control assessments conducted by grant beneficiaries when providing financial support to third parties.

This situation could facilitate the exposure of sensitive infrastructures, operational information, or strategic technologies to foreign influences.

Auditors call for more rigorous controls, effective institutional coordination, and the implementation of the pending alert system. They also consider it essential to improve information transmission so that countries can act jointly in response to incidents that exceed their national capabilities.


——————————————————-


Click Here For The Original Source.