Ireland was among the countries considered by the European Court of Auditors.
A new report published by the European Court of Auditors (ECA) has found that information sharing, or rather the lack thereof, among EU member states, is creating gaps in cybersecurity for the region.
Among the countries investigated for the purpose of research were Ireland, Greece and Italy.
The ECA’s research found that cybersecurity incidents have the potential to disrupt public services, businesses, critical infrastructure and the EU’s internal market. Largely, the responsibility for responding to cyber incidents is placed on member states, but the wider EU community plays a critical role.
The ECA in a statement said, “This is the case particularly when such incidents cause major disruption, significant financial losses, or substantial harm to people or organisations (significant cybersecurity incidents), or when they affect several member states and go beyond the capacity of a single country to respond effectively, (large-scale cybersecurity incidents).”
According to the report, the EU has been increasingly investing in stronger cybersecurity via the 2021-2027 EU budget and the Digital Europe Programme, which has provided funding of €1.4bn, the main source of cybersecurity funding.
Despite this however, the ECA auditors are of the opinion that there is a clear ‘Achilles heel’ element, in that the system is too dependent on an insufficient exchange of information.
The ECA said, “The Cyber Blueprint, which was adopted in 2025, largely clarifies roles and responsibilities by setting out how the EU should manage major cybersecurity crises. However, the way the two EU cyber networks work together has still not been formally defined.
“This hampers the cooperation of the CSIRTs network, which brings together national teams dealing with cyber incidents and EU-CyCLONe, an EU network for cyber crisis cooperation.”
Additionally, some EU countries are still in the process of updating their cybersecurity policies in a landscape where national security rules are limiting the level of information that can be shared. The ECA claims this is resulting in an environment in which EU networks may struggle to detect threats early on, or coordinate an effective response.
This is further exacerbated by an overlap in EU bodies responsible for monitoring cybersecurity threats.
Commenting on the findings, George-Marius Hyzler, the ECA member in charge of the audit, said, “The EU has made progress in building a cybersecurity cooperation framework, but it is not yet working as effectively as it should.
“When a serious cyber incident occurs, timely and actionable information is essential. Without it, networks and mechanisms lose much of their added value.”
Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.
You must be logged in to post a comment Login