EU cybersecurity system hampered by delays and weak information sharing
Getting 27 countries to work together remains a challenge.

Image by Cybernews.
- The European Court of Auditors says EU cyber incident cooperation is only partly effective.
- Delays in applying NIS2 rules have limited a consistent EU-wide response to cyberattacks.
- Auditors say EU countries and agencies do not share enough information about cybersecurity incidents.
- The European Commission says trust matters and EU rules do not require all information sharing.
In recent years, the EU has made significant progress in building a coordinated system for detecting and responding to cyberattacks. However, coordination between EU member states and European cybersecurity agencies remains difficult.
The European Court of Auditors (ECA) examined how EU member states and European cybersecurity authorities cooperate when dealing with cybersecurity incidents. Its main conclusion: cooperation isn’t as effective as intended.
According to the EU’s external auditor, Europe has a decent regulatory framework when it comes to dealing with major cybersecurity incidents.
The issue is that this framework is only partially effective for 2 reasons.
First, there have been delays in implementing cybersecurity measures across EU member states, including the NIS2 Directive, which prevented the cybersecurity framework from reaching its full potential.
The NIS2 Directive was designed to create a higher and more consistent level of cybersecurity across the EU. However, there’s no uniform cybersecurity response due to delays and differences among EU member states in implementing the rules.
Secondly, the ECA found that sharing relevant information about cybersecurity incidents between national and EU-level bodies remains insufficient.
“Geographical borders do not prevent cybersecurity incidents and cyberattacks from occurring and spreading. Information sharing between member states on, for example, the tactics and techniques used by threat actors, and on digital signs that a network or information system has been breached, can contribute significantly to increased cybersecurity,” the auditors state in their report.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
In a nutshell, the ECA recommends that member states and EU cybersecurity organizations work faster and more consistently by improving information sharing between countries.
The European Commission agrees with the ECA’s findings, but at the same time recalls that “cooperation in cybersecurity depends on confidence and trust, and there is no obligation under applicable EU rules for information sharing between EU entities and member states.”
“The Commission takes due note of all the findings of the report and will carefully consider them going forward,” the EU’s executive branch concludes.