European Court of Auditors warns poor data sharing undermines EU cyber defences

Summary

On September 21, the European Court of Auditors reported that poor data sharing among EU member states is significantly hindering the bloc's ability to combat cyberattacks. Despite the EU's increasing investment in cybersecurity, with €1.4 billion allocated in its current budget, the court emphasized that this lack of cooperation is the "Achilles heel of the entire system." The report highlighted a ransomware attack in September 2025 that disrupted major airports across several countries, pointing out that none of the affected nations notified the EU cybersecurity agency or their fellow members. This issue is compounded by national security legislation in individual EU countries, which obstructs timely information sharing during cross-border incidents. In response, the European Commission has launched legal proceedings against France, Ireland, the Netherlands, and Spain for their failure to align national laws with EU requirements concerning cybersecurity information sharing.

Analysis

Spain: Spain is an EU member state referred by the European Commission to the EU Court of Justice for failing to incorporate EU cybersecurity information-sharing requirements into its domestic laws. The case illustrates broader difficulties in harmonizing responses across the union. France: France is an EU member state that has been referred by the European Commission to the EU Court of Justice for not fully transposing EU rules on cybersecurity information sharing into national law. This reflects ongoing challenges in aligning domestic frameworks with cross-border requirements. Ireland: Ireland is an EU member state referred by the European Commission to the EU Court of Justice for delays in updating national legislation to support EU cybersecurity information-sharing measures. The referral underscores compliance gaps affecting bloc-wide incident response. Netherlands: The Netherlands is an EU member state that the European Commission has taken to the EU Court of Justice over incomplete implementation of EU directives on sharing cybersecurity incident data. This action points to persistent issues in national-to-EU information flows. Andrew Heavens: Andrew Heavens is an editor at Reuters responsible for overseeing coverage of international news and policy stories. He edited the report on the European Court of Auditors' assessment of EU cyber defenses. European Union: The European Union is a political and economic union of 27 European member states that coordinates policies on security, including cybersecurity initiatives. It has been increasing investments and cooperation mechanisms to address cyber threats. The news highlights how national barriers are limiting the effectiveness of these bloc-wide efforts. Philip Blenkinsop: Philip Blenkinsop is a Reuters journalist based in Brussels who covers European Union affairs and policy developments. He reported on the European Court of Auditors' findings regarding weaknesses in EU cybersecurity cooperation. European Court of Auditors: The European Court of Auditors is an independent EU institution responsible for auditing the Union's finances and evaluating the effectiveness of its spending and policies. It produces reports highlighting shortcomings in implementation across member states. In this case, it released a report criticizing inadequate information sharing on cyberattacks as undermining collective EU defenses. Regulation: The European Commission has initiated legal proceedings against multiple member states for not fully aligning national laws with EU requirements on cybersecurity information sharing. Incident Response: The failure to share information promptly after attacks, such as those affecting multiple countries' infrastructure, reduces the overall value of EU cooperation mechanisms. Cybersecurity Policy: National security rules in EU countries are creating obstacles to timely cross-border sharing of details about serious cyber incidents.

Categories

politicstech
View Original Tweet