Auditors find EU cyber‑attack response is weakened by overlapping systems and secretive member states

Auditors find EU cyber‑attack response is weakened by overlapping systems and secretive member states

Europe has spent billions building a common cybersecurity architecture. But a new audit has found that when a major cyber incident strikes, the EU’s response remains hampered by fragmented responsibilities, limited information-sharing and overlapping systems. The European Union allocated €1.4bn to cybersecurity under its 2021-27 budget, with the Digital Europe programme the main source of funding. EU networks are intended to help member states detect and respond to significant and large-scale cyber incidents, but the auditor responsible for the report at the European Court of Auditors (ECA), George-Marius Hyzler, said “the cybersecurity cooperation network is not yet as effective as it should be.” The audit published on Monday (21 September) examined EU action between 2022 and 2025, including missions to Ireland, Greece and Italy. It concluded that shortcomings remain in the way the EU detects and responds to major cyber incidents, calling for better coordination and warning that duplications between the various bodies involved are frequent. For the EU, the stakes are high. Cyber attacks can disrupt public services and businesses, interfere with critical infrastructure and threaten the functioning of the EU’s internal market. EU’s cybersecurity threats come mainly from two sides. "We have a practical problem of hardware — from the Chinese side," senior research officer at the Wilfried Martens Centre for European Studies, Dimitar Lilkov, told EUobserver. On the other side, "we have the problem of Russian-sponsored cyberattacks or disinformation campaigns." While responsibility for responding to incidents remains primarily with national authorities, Brussels has an increasingly important role in coordinating the response. Yet one of the central difficulties is the willingness and legal ability of national governments to share sensitive information. “The obligation to share information exists. It is only a matter of getting it enforced,” said Hyzler. The first step, he said, was to get all member states on board. “It is not a question of having new regulations. The crux of the matter is enforcing the existing regulations,” Hyzler also said. National capitals vs Brussels "Member states have their own established institutions and technical competencies and overall philosophy when it comes to cybersecurity,“ said Lilkov.

Original Source

Read the full article at Euobserver →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.