The European Court of Auditors has found several inefficiencies in the EU's systems designed to detect and respond to cyber threats. In a recent audit covering 2022 to 2025, the court noted that while the EU has made efforts to improve its cybersecurity response, these mechanisms are not yet fully effective. Information sharing between member states remains limited, and the cooperation framework is still being developed. The audit highlights that while the EU has established several initiatives, their implementation and coordination are not yet complete.
The audit focused on five key mechanisms: Réseau des CSIRT, Réseau EU-CyCLONe, the Cyber Situation Centre, the European Cyber Alert System, and the EU Cyber Security Reserve. The CSIRT network, which connects national computer security incident response teams, and Réseau EU-CyCLONe, a network for sharing cyber threat intelligence, have not yet finalized how they will collaborate. They have also not agreed on the criteria for sharing incident information or on a common definition of terms like "significant incident" and "major incident."
Delays in implementing the NIS 2 directive, which requires organizations to report cyber incidents, have also slowed information sharing. Until the directive is fully in place, companies are not legally required to report incidents, and it is difficult to determine if an event has a transboundary impact. The audit highlighted an example involving Collins Aerospace, where the incident was not reported by member states despite its wide-reaching effects. Since 2016, no member state has classified any incident as "major," despite high-profile events such as WannaCry and NotPetya.
National security laws further complicate information sharing, as there has been no EU-level analysis of how these laws affect cybersecurity cooperation. The newly established Cyber Situation Centre, launched in 2023, relies heavily on external service providers, with a contract worth nearly 18 million euros over four years. This effort partly overlaps with the work of ENISA, the EU Agency for Cybersecurity, which already provides similar reports and uses the same data. Additionally, the EU Cyber Security Reserve, with a budget of 36 million euros for 2025-2027, is divided equally among member states, but it cannot be used to assist other countries if a nation does not use its pre-contracted services. The audit suggests the reserve may be more useful for preparation than for actual response efforts.
The European Cyber Alert System is voluntary, and only 13 member states had joined by the time of the audit. Two cross-border clusters, ATHENA and ENSOC, were formed to enhance cybersecurity cooperation, but delays in awarding contracts for tools and services have hindered their operations. The procurement process for ENSOC began in May 2024 and for ATHENA in July 2024, but by the time of the audit, 18 months later, no contracts had been signed. Without the necessary tools, the alert system is not yet functional. The lack of clear roles for cyber clusters compared to national CSIRTs has led to overlapping responsibilities and a lack of standardized terminology, which ENISA has noted as a major obstacle to effective information sharing.
European Cybersecurity Mechanisms Face Operational and Structural Challenges
AI-rewritten from original reportingHow it works
cybersecurityeu-auditinformation-sharingcyber-incidentscsirt



