The European Union’s efforts to strengthen cybersecurity across its member states are being hindered by insufficient information sharing, according to a report released Monday by the European Court of Auditors. Despite increased investment and enhanced cooperation, the 27-nation bloc faces challenges in effectively coordinating responses to cyber threats.
The EU has allocated $1.61 billion in its current budget for cybersecurity initiatives aimed at protecting critical infrastructure and digital services. However, the auditors found that these resources have not translated into optimal outcomes due to gaps in communication between member states.
The report highlighted a ransomware attack in September 2025 that targeted a technology provider serving the aviation sector. This breach caused significant disruptions at major airports in London, Brussels, Berlin, Dublin, and other key European hubs. Despite the widespread impact, none of the affected countries informed the EU cybersecurity agency or shared details of the incident with fellow member states.
This lack of notification undermines collective efforts to respond rapidly and mitigate the effects of cyberattacks, the report stated. It also hampers the EU’s ability to analyze threats comprehensively and coordinate preventative measures going forward.
The European Court of Auditors called for improvements in the mechanisms for information exchange among member states and more proactive engagement with EU cybersecurity bodies. Strengthening transparency and communication is viewed as essential to enhancing the bloc’s overall resilience against increasingly sophisticated cyber threats.
