Summary
- EU auditors found that major-incident information is not consistently shared quickly enough to support an effective cross-border response.
- No member state has formally reported a “large-scale” cyber incident through the relevant mechanism since 2016.
- The findings expose an operational gap between Europe’s expanding cyber-response architecture and the information supplied to it.
Europe has built an increasingly elaborate system for coordinating its response to major cyber incidents, but national authorities are still not supplying enough timely information for that system to work as intended, according to a new audit of the EU’s cyber-crisis arrangements.
The European Court of Auditors found that cooperation has improved and significant public money has gone into joint cybersecurity capacity, yet information-sharing between member states remains a material weakness when incidents cross borders or threaten to become large-scale crises.
The audit examined the EU framework for detecting and responding to significant and large-scale cyber incidents. It found that roughly €1.4 billion has been committed to cyber-related measures, while institutional structures now include national authorities, computer security incident response teams, the European Union Agency for Cybersecurity, or ENISA, and mechanisms intended to support coordination during serious events.
Those structures still depend on member states reporting incidents quickly enough, and with enough operational detail, for other authorities to build a common picture. The auditors concluded that the information supplied is often incomplete or delayed, limiting the value of the wider response framework.
One of the more striking findings is that no member state has formally notified an incident as large-scale through the relevant EU process since 2016. That does not mean Europe has avoided attacks with substantial cross-border effects. The audit identifies disruptive incidents whose effects reached several countries without producing the level of shared reporting that the framework is intended to support.
A ransomware attack on an aviation technology provider in September 2025, for example, contributed to disruption at several European airports. The auditors found that the affected countries did not make a large-scale incident notification through the mechanism examined in the report.
The gap is partly structural. Cyber incidents can involve national-security information, sensitive intelligence, commercial confidentiality, criminal investigations, and operational details that authorities may be cautious about circulating widely. National reporting practices also differ, meaning that a cross-border event can be viewed through several administrative and legal frameworks before it reaches a shared European mechanism.
That creates a difficult dependency inside the EU’s wider resilience programme. NIS2 has expanded cybersecurity obligations across essential and important sectors, while the Cyber Solidarity Act and other initiatives are intended to increase common detection, preparedness, and crisis-response capability. Those measures can improve technical capacity, but collective response still depends on national authorities contributing usable information at the point when an incident is developing.
The problem is not simply whether an event is formally reported. Effective coordination requires information that can support decisions: which services are affected, whether an attack is still spreading, what dependencies are involved, whether infrastructure in other countries faces the same exposure, and what containment measures have worked.
A weak shared picture can also complicate the allocation of EU resources during a crisis. Assistance mechanisms, cross-border response teams, and political coordination become less effective when the institutions responsible for deploying them are operating from inconsistent or incomplete information.
The audit arrives as Europe continues to expand its cybersecurity rulebook and central capabilities. Its findings suggest that implementation is increasingly becoming a question of operational behaviour rather than institutional design. The EU has created channels through which member states can coordinate; the remaining weakness is whether those channels receive enough useful information when a serious incident is actually under way.




