EU cyber defences hobbled by poor information sharing, auditors warn
EU auditors say weak information sharing among member states is undermining the bloc's cyber defences, despite rising investment.
Efforts to counter cyberattacks across the European Union are being held back by member states' reluctance to share information about incidents, the European Court of Auditors has said.
The bloc is spending more on cybersecurity — €1.4 billion ($1.61 billion) in its current budget — and cooperation has improved, according to the court, which assesses how effectively EU money is used. Even so, the auditors concluded that the system is not performing as well as it should.
Poor information sharing was described in the report as the "Achilles heel of the entire system". It noted that timely, actionable information is essential when a serious cyber incident occurs, and that without it, networks and mechanisms lose much of their value.
The auditors cited a ransomware attack in September 2025 on a technology provider serving the aviation industry, which disrupted airports in London, Brussels, Berlin, Dublin and other hubs. None of the affected states notified the EU cybersecurity agency or other members about the incident.
National security legislation in individual countries was also found to obstruct the sharing of information about incidents that cross borders. The court pointed out that no EU state has reported a "large-scale" cybersecurity incident since 2016, even though the label officially applies to any attack affecting at least two member states.
In July, the European Commission referred France, Ireland, the Netherlands and Spain to the EU Court of Justice for failing to align their national laws with EU measures on sharing cybersecurity information.