A year ago, a ransomware attack forced airports in Brussels, Berlin, and Dublin to switch to manual check-in. None of the affected EU countries formally warned the others. Despite €1.4bn in EU funding, auditors say the bloc still struggles to spot and handle major cyberattacks.
The attack hit Collins Aerospace, a major technology provider for the aviation industry. It caused widespread flight delays and cancellations. Yet no member state treated the incident as significant. None of them formally alerted the European Union Agency for Cybersecurity (ENISA) or other EU countries. For the European Court of Auditors (ECA), the case sums up a much wider problem. In a new special report, the auditors conclude that EU measures suffer from “shortcomings when it comes to detecting and responding to significant and large-scale cybersecurity incidents”.
The EU has set aside €1.4bn for cybersecurity under the Digital Europe Programme for 2021–2027. Yet the auditors judge the system it supports only partially effective. Its main weakness lies in information sharing. Member states often keep data on attacks to themselves. At the same time, several EU bodies do overlapping work. The auditors call for a better flow of information and for “better coordination to avoid duplication of work among the various bodies involved”.
Many players, little sharing
Quick action is hard when so many players are involved. The European Commission launched its own cyber situation centre in 2022. ENISA monitors threats and tracks the overall situation. A network of national computer security incident response teams (CSIRTs) deals with incidents at the technical level. The European Cyber Crisis Liaison Organisation Network (EU-CyCLONe) links the national authorities in charge of cyber crises.
The Commission’s centre relies heavily on external contractors. According to the auditors, their work partly duplicates what ENISA already does. The contract, worth nearly €18m, runs out in December 2026. At the time of the audit, the Commission had no plan for what comes next.
National rules add to the problem. Only two member states met the October 2024 deadline to bring the NIS 2 Directive, the EU’s updated cybersecurity rulebook, into national law. Until countries do so, organisations covered by the new rules have no legal duty to report incidents. National security laws also limit what governments can share.
The numbers show the gap. In 2025, just seven member states reported a total of 14 significant cross-border incidents. ENISA’s 2024 threat report, by contrast, counted 322 incidents targeting at least two member states. As a result, the auditors note that “EU networks may struggle to detect threats early and coordinate an effective response”.
Holes in the safety net
Security checks raise another concern. EU rules can restrict cybersecurity funding to entities owned and controlled within the EU. The aim is to keep non-EU states away from sensitive projects. Some grant recipients, however, pass part of the money on to other organisations. In those cases, the recipients vet the new partners themselves. The European Cybersecurity Competence Centre (ECCC), which manages the funds, does not verify their checks. “As a result, sensitive infrastructure, operational data, and security-critical technologies could be exposed to security risks,” the auditors add.
The EU’s planned early-warning network is not up and running either. The European Cybersecurity Alert System aims to link national and cross-border cyber hubs that spot threats and share data. At the time of the audit, 13 member states had joined two such hubs, ATHENA and ENSOC.
Both hubs started work in January 2024. Yet they still lack the tools to detect threats. Procurement began in mid-2024, but 18 months later no contract was in place. The auditors describe the hubs as “operationally on hold”.
Bigger threats, new rules
The threats keep growing. ENISA rates the cyber threat level in the EU as substantial and names ransomware as the most critical danger. Public administration is the most frequent target. Europe also faces Russian-sponsored cyberattacks and disinformation campaigns. At the same time, Brussels worries about reliance on technology from high-risk suppliers, a debate that often centres on China. In January, the Commission proposed a revision of the EU Cybersecurity Act, dubbed CSA2. Among other things, it would restrict the use of technology from such suppliers. The proposal still needs the approval of the European Parliament and the Council of the EU.
When a serious cyber incident occurs, timely and actionable information is essential. Without it, networks and mechanisms lose much of their added value. — George-Marius Hyzler, Member of the European Court of Auditors
The audit covered the years 2022 to 2025 and included visits to Ireland, Greece, and Italy. George-Marius Hyzler, the ECA member in charge, summed up its central lesson. “When a serious cyber incident occurs, timely and actionable information is essential. Without it, networks and mechanisms lose much of their added value,” Mr Hyzler said. The auditors set deadlines between 2026 and 2028 for their five recommendations.
The Commission has already responded. A spokesperson promised to “carefully consider its recommendations”. The aim, the spokesperson added, is “to further strengthen the Union’s detection, situational awareness and response capabilities to cyber threats and incidents”. The spokesperson also pointed to the revision of the Cybersecurity Act. It “puts forward proposals to strengthen ENISA’s capabilities to support Member States on situational awareness and incident response”.