NewsTradingSentimentEventsCommunityBriefing
World

EU Auditors Cite Slow Cyber Data Sharing

By Geopolitics Desk · · 2 min read
A server rack with blinking status lights in a dimly lit data center room
Illustration: Tradingbird

European Court of Auditors report highlights delays in sharing critical cyber incident data across member states.

Key points

  • EU auditors found that member states fail to share timely cyber incident data, weakening collective defense capabilities.
  • The European Cyber Alert System remains non-operational due to procurement delays and lack of common technical standards.
  • A 2025 ransomware attack on Collins Aerospace highlighted the operational impact of poor information sharing across Europe.

European Union member states are struggling to share timely information about large-scale cyber security incidents, a practice that is weakening the bloc’s collective ability to respond to cross-border threats. According to a new report from the European Court of Auditors, legal restrictions and national security concerns are creating significant barriers to information exchange, preventing a coordinated European response.

The auditors noted that despite the EU allocating €1.4 billion to cyber security through its Digital Europe programme, the measures have only been partially successful in improving detection and response capabilities. In a notable example, a 2025 ransomware attack against Collins Aerospace caused widespread flight delays in major European airports, yet member states failed to share relevant information with one another during the crisis.

Barriers to Information Exchange

The report identifies several factors hindering cooperation, including delays in implementing the NIS2 directive, which requires over 100,000 organizations to report incidents to national authorities. Auditor Frédéric Soblet emphasized that this data should be shared immediately to allow organizations to patch vulnerabilities and identify indicators of compromise. Currently, it can take weeks or months for the European Union Agency for Cybersecurity to receive this information from member states.

Auditor George-Marius Hyzler described the failure to pass on information as placing a "spoke in the wheels" of cyber resilience. He stated that the European Commission must work on building trust to ensure information flows freely. The auditors also highlighted a lack of cooperation between Europe’s network of Computer Security Incident Response Teams and the informal EU-Cyclone coordination network.

Delayed Alert System Implementation

The European Cyber Alert System, designed to facilitate real-time sharing of incident data, is not yet operational due to procurement delays and a lack of agreed technical standards. According to Computer Weekly, the auditors recommend that the EU prioritize this system to allow member states to share information while respecting national security constraints. The system aims to process, analyze, and correlate incident reports in real-time to enhance situational awareness.

Only 13 countries have opted into the preliminary framework for the alert system so far. The auditors warn that without a unified approach and common classification systems, the EU will continue to face fragmented responses to cyber threats. They call for better coordination among EU cyber security bodies to avoid duplication of work and to ensure that sensitive security information is not inadvertently shared with non-EU authorities.

Next Steps for Resilience

Looking ahead, the key question is whether the European Commission will act on the auditors' recommendations to streamline data sharing protocols. The success of future cyber defense efforts will depend on establishing robust trust mechanisms and resolving the technical and legal hurdles that currently impede cooperation among member states.

Based on reporting by Computer Weekly, compiled by the Tradingbird desk.

Read next

More in World

More from the World desk

All desk stories