The EU built an early-warning system to catch the next major cyberattack before it spreads. Roughly 20 months later, auditors have found it still is not fully switched on.
Brussels has allocated €1.4 billion to defending Europe from cyberattacks. Its own auditors found that when that funding is passed on to third parties, nobody independently checks whether it could be reaching organisations exposed to influence from hostile states.
The warning comes from a report published on Monday by the European Court of Auditors (ECA), which examined how well the EU detects and responds to major cybersecurity incidents between 2022 and 2025.
Grant beneficiaries are responsible for assessing the ownership and control of any third parties receiving EU cybersecurity funding. But the European Cybersecurity Competence Centre, the body overseeing these grants, does not verify those assessments itself, the auditors found.
As a result, sensitive infrastructure, operational data and security-critical technologies could be exposed to security risks.
The funding falls under the Digital Europe Programme, the EU's main channel for cybersecurity spending as part of its 2021-2027 budget.
An alarm system still lagging
The audit also found that the EU's early-warning network for major cyberattacks is not yet operational.
Two hubs meant to anchor the European Cybersecurity Alert System, known as ATHENA and ENSOC, still lack the tools to detect threats and share information after repeated procurement delays.
The cooperation agreements, common classification system and technical standards needed to get the alert system running were also still missing, auditors said.
"The EU has made progress in building a cybersecurity cooperation framework, but it is not yet working as effectively as it should," said George-Marius Hyzler, the ECA member in charge of the audit.
"When a serious cyber incident occurs, timely and actionable information is essential. Without it, networks and mechanisms lose much of their added value."
Information-sharing as the 'Achilles heel'
Auditors identified poor information-sharing as the central weakness in the EU's cyber defences, describing it as the "Achilles heel of the entire system".
The scale of the problem was laid bare last September, when a ransomware attack on Collins Aerospace, a major aviation technology provider, forced airports including London Heathrow, Brussels, Berlin Brandenburg and Dublin to revert to manual operations, causing widespread delays and cancellations.
Under the EU's own rules, an incident of that scale should have qualified as significant or large-scale, triggering formal notification. None of the affected states reported it as either.
It is not an isolated lapse. No member state has classified a single cybersecurity incident as "large-scale" since 2016 — not even WannaCry, NotPetya, or the global IT outage triggered by a faulty CrowdStrike update in 2024.
As a result, the EU's crisis-escalation procedure for major cyberattacks has never once been fully activated.
Member states formally notified just 14 cross-border incidents in 2025, submitted by only seven countries or a fraction of the 322 incidents affecting two or more member states that ENISA had separately identified the year before.
Gaps in the system
The Cyber Blueprint, adopted in 2025, largely clarifies roles and responsibilities during major cybersecurity crises.
However, how the EU's two main cyber networks work together has still not been formally defined, the report found. That has hampered cooperation between the CSIRTs network, which brings together national incident-response teams, and EU-CyCLONe, the bloc's crisis cooperation network.
All but two member states missed the deadline to transpose the EU's updated cybersecurity rules, including the NIS 2 Directive.
Together, auditors said, these gaps mean EU networks may struggle to detect threats early and mount an effective joint response.
Overlapping mandates
The report also flagged duplication between EU bodies tasked with monitoring cyber threats.
The European Commission's cyber situation centre, set up in 2022 and largely supported by external providers, was found to be doing work that overlaps with the European Union Agency for Cybersecurity (ENISA), which already monitors threats and builds situational awareness across the bloc.
The auditors' recommendations include improving information-sharing between EU networks, clarifying how bodies with overlapping mandates should work together, integrating the alert system into the wider cybersecurity landscape through clear cooperation agreements and interoperability standards, and strengthening security checks on funding recipients.
Responsibility for responding to cybersecurity incidents lies mainly with individual member states, but the EU also plays an important role when incidents cause major disruption, significant financial losses or affect several countries at once, beyond what any single state can handle alone.
The alert system was established under the EU Cyber Solidarity Act in February 2025 to act as a unified network for real-time monitoring, early threat detection and cross-border intelligence-sharing on large-scale cyberattacks against Europe.
Earlier this year, the European Commission proposed a new cybersecurity package to revise the Cybersecurity Act, including a strict, risk-based supply chain security framework to prevent high-risk third countries from accessing critical EU infrastructure.
The package also proposes drastically increasing ENISA's budget and revising existing EU and national laws to streamline the administration and implementation of Union-wide cybersecurity rules.
As of this September, under the Cyber Resilience Act, hardware and software manufacturers must report any exploited vulnerability or severe security incident within 24 hours to national CSIRTs and ENISA's Single Reporting Platform, with fines reaching up to €15 million or 2.5% of global turnover for serious breaches.