Cybersecurity

EU Cybersecurity Weakened by Data-Sharing Gaps

A new European audit says gaps in information sharing and fragmented cybersecurity systems are limiting the bloc’s ability to respond effectively to major cyber incidents.

EU Cybersecurity Gaps
Summary

The European Court of Auditors says the European Union’s cybersecurity response remains less effective than intended because member states do not consistently share timely information about cyber incidents. The audit also identified fragmented responsibilities, overlapping systems and delays in developing some EU-wide tools.

Europe has spent billions of euros building a common cybersecurity framework, but a new audit suggests that one of its biggest weaknesses is not necessarily a lack of technology.

It is the difficulty of getting countries to share important information quickly when cyberattacks cross national borders.

The European Court of Auditors said on September 21 that the EU’s efforts to detect and respond to major cyber incidents remain only partly effective, with information-sharing gaps limiting the value of cooperation between member states.

Europe Is Spending More on Cybersecurity

The 27-member European Union has allocated about €1.4 billion to cybersecurity under its current 2021–2027 budget, while European institutions have also expanded cooperation between national cybersecurity authorities.

The investment reflects the growing importance of cybersecurity to Europe's economy. A serious attack can disrupt businesses, public services, transport networks, healthcare systems and other critical infrastructure.

But according to the auditors, spending and cooperation mechanisms do not automatically produce an effective collective response if governments do not exchange information when incidents occur.

Information Sharing Is the Main Weakness

The auditors described poor information sharing as a central weakness in the EU's cybersecurity system.

When a major cyberattack occurs, information about what happened, how the attackers entered a system and which organisations were affected can help other countries protect themselves before the same techniques are used elsewhere.

Delays or incomplete reporting can therefore turn a national cyber incident into a wider European vulnerability.

Cyberattacks do not stop at national borders, but cybersecurity information often does.

The Aviation Ransomware Example

The auditors highlighted a ransomware attack against a technology provider serving the aviation industry in September 2025.

The incident disrupted operations at airports including London, Brussels, Berlin and Dublin, demonstrating how a cyberattack against one technology provider can have consequences across several countries.

According to the audit, none of the affected states notified the EU cybersecurity agency or other member states about the incident. The example illustrates the problem the auditors identified: an attack can have cross-border consequences while the information needed for a coordinated response remains fragmented.

National Security Rules Can Complicate Cooperation

One challenge identified by the auditors is the interaction between national security legislation and European information-sharing requirements.

Governments may have restrictions on what information can be disclosed outside national authorities, particularly when an incident involves sensitive security matters.

The result can be a difficult balance between protecting sensitive information and providing other countries with enough technical details to defend their own networks.

A Problem With How Major Incidents Are Reported

The audit also found a striking gap in the reporting of large-scale cyber incidents.

No EU member state has reported a cyber incident officially classified as “large-scale” since 2016, even though the definition covers an incident affecting at least two member states.

The auditors said this raises questions about whether the EU is receiving a complete picture of major cyber threats affecting the bloc.

Europe Also Faces Fragmented Systems

Information sharing is not the only concern. The audit identified overlapping responsibilities among different European cybersecurity bodies and delays affecting some common tools.

One example is the European Cybersecurity Alert System, which the auditors said was not yet operational. Such systems are intended to improve the ability of countries to detect threats and coordinate responses.

The auditors also raised concerns about how some EU cybersecurity funding recipients are checked, adding another layer to the broader problem of coordination.

Pressure to Strengthen EU Cyber Defences

The findings come as European governments face increasingly sophisticated ransomware attacks, cyber espionage and threats against critical infrastructure.

In July, the European Commission referred France, Ireland, the Netherlands and Spain to the EU Court of Justice over failures to fully incorporate European cybersecurity information-sharing requirements into national law.

The legal action highlights the difficulty of creating a genuinely unified cybersecurity system across countries that retain significant national responsibilities for security and intelligence.

Why the Data Matters

Cybersecurity information can have enormous practical value. Indicators of compromise, malware samples, attack methods and details about targeted infrastructure can help organisations identify threats before they spread.

For a region as economically interconnected as Europe, the ability to share such information quickly can be especially important. A technology provider, bank, hospital, airport or energy company in one country may provide services to organisations in several others.

That means a weakness in one national system can potentially become a problem for organisations far beyond its borders.

Final Thought

Europe can invest in more cybersecurity technology, but the effectiveness of those defences ultimately depends on whether countries can share the right information quickly enough to act together.

Daily Touch Insights
Technology, cybersecurity and the forces reshaping the digital world.