The EU spent billions on a cyberattack shield — nobody checked if it worked

The EU spent billions on a cyberattack shield — nobody checked if it worked

Brussels has allocated €1.4 billion to defending Europe from cyberattacks. According to its own auditors, nobody is properly checking whether that money could be reaching organisations exposed to influence from hostile states. ADVERTISEMENT ADVERTISEMENT The warning comes from a report published on Monday by the European Court of Auditors (ECA), which examined how well the EU detects and responds to major cybersecurity incidents between 2022 and 2025. Grant beneficiaries are responsible for assessing the ownership and control of any third parties receiving EU cybersecurity funding. But the European Cybersecurity Competence Centre, the body overseeing these grants, does not verify those assessments itself, the auditors found. As a result, sensitive infrastructure, operational data and security-critical technologies could be exposed to security risks. The funding falls under the Digital Europe Programme, the EU's main channel for cybersecurity spending as part of its 2021-2027 budget. An alarm system still switched off The audit also found that the EU's early-warning network for major cyberattacks is not yet operational. Two hubs meant to anchor the European Cybersecurity Alert System, known as ATHENA and ENSOC, had not started work due to procurement delays. The cooperation agreements, common classification system and technical standards needed to get the alert system running were also still missing, auditors said. "The EU has made progress in building a cybersecurity cooperation framework, but it is not yet working as effectively as it should," said George-Marius Hyzler, the ECA member in charge of the audit. "When a serious cyber incident occurs, timely and actionable information is essential. Without it, networks and mechanisms lose much of their added value." Information-sharing as the 'Achilles heel' Auditors identified poor information-sharing as the central weakness in the EU's cyber defences, describing it as the "Achilles heel of the entire system". The Cyber Blueprint, adopted in 2025, largely clarifies roles and responsibilities during major cybersecurity crises. However, how the EU's two main cyber networks work together has still not been formally defined, the report found. That has hampered cooperation between the CSIRTs network, which brings together national incident-response teams, and EU-CyCLONe, the bloc's crisis cooperation network. Some member states are also still transposing the EU's updated cybersecurity rules, including the NIS 2 Directive, while national security laws in some countries restrict what information can be shared at all. Together, auditors said, these gaps mean EU networks may struggle to detect threats early and mount an effective joint response. Overlapping mandates The report also flagged duplication between EU bodies tasked with monitoring cyber threats. The European Commission's cyber situation centre, set up in 2022 and largely supported by external providers, was found to be doing work that overlaps with the European Union Agency for Cybersecurity (ENISA), which already monitors threats and builds situational awareness across the bloc. The auditors' recommendations include improving information-sharing between EU networks, clarifying how bodies with overlapping mandates should work together, accelerating the rollout of the alert system, and strengthening security checks on funding recipients. Responsibility for responding to cybersecurity incidents lies mainly with individual member states, but the EU also plays an important role when incidents cause major disruption, significant financial losses or affect several countries at once, beyond what any single state can handle alone. The alert system was established under the EU Cyber Solidarity Act in February 2025 to act as a unified network for real-time monitoring, early threat detection and cross-border intelligence-sharing on large-scale cyberattacks against Europe. Earlier this year, the European Commission proposed a new Cybersecurity package to revise the Cybersecurity Act, including a strict, risk-based supply chain security framework to prevent high-risk third countries from accessing critical EU infrastructure. The package also proposes drastically increasing ENISA's budget and revising existing EU and national laws to streamline the administration and implementation of Union-wide cybersecurity rules. As of this September, under the Cyber Resilience Act, hardware and software manufacturers must report any exploited vulnerability or severe security incident within 24 hours to national CSIRTs and ENISA's Single Reporting Platform, with fines reaching up to €15 million or 2.5% of global turnover for serious breaches.

Original Source

Read the full article at Euronews →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.