Skip to content
RegionEurope

MediumII Cyber Warfare & Critical Infrastructure22 September 2026, Tuesday

European Court of Auditors: in a €1.4 billion cyber defence effort, member states reported only 14 cross-border incidents in 2025

In special report 19/2026, published on 22 September 2026, the European Court of Auditors said that despite €1.4 billion allocated to cybersecurity from the Digital Europe Programme, the EU's capacity to detect and respond to serious cyber incidents works only partially, with information sharing the weak link.

LUXEMBOURG

As reported by Trending Topics, the report covers 2022–2025. In 2025 member states reported only 14 cross-border incidents from 7 countries; the figure was 2 in 2024, 0 in 2023 and 3 in 2022. The EU cybersecurity agency ENISA counted 322 cross-border incidents; Trending Topics attributes this figure to 2024, Euronews to 2025. While 1,276 incidents were reported to ENISA in 2024, the agency identified around 4,800 incidents from open sources alone. According to Euronews, no member state has classified an incident as large-scale since 2016 and the EU crisis escalation procedure has never been fully activated.

Neither of the 2 hubs of the early-warning network is operating: ATHENA, comprising Bulgaria, Greece, the Greek Cypriot Administration and Malta, and ENSOC, covering Spain, Italy, Luxembourg, the Netherlands, Austria, Portugal and Romania, have not become operational because of procurement delays; funding for a 3rd hub was approved this year and the network expanded to 20 countries. The roughly €18 million, 4-year external services contract of the Cyber Situation Centre set up by the Commission in 2022 was criticised for overlapping with ENISA. Only 2 member states met the autumn 2024 transposition deadline of the NIS 2 directive; the new scope rises from 15,500 entities to more than 110,000.

According to Euronews, when funds are passed on to third parties there is no mechanism to independently verify recipients' ownership and control assessments. The report cites the Collins Aerospace ransomware attack of September 2025, which affected 4 major airports, as an example of an incident that was not properly reported. On 22 September the Commission said it would examine the recommendations carefully.

Talay assessment

Bottom line

The report shows that the EU's cyber problem is data flow, not money: with a €1.4 billion budget in place, the gap between 14 notifications and 322 incidents reveals that shared situational awareness exists only on paper. The most likely direction is for the Commission to tighten notification obligations and expand ENISA's role; but while NIS 2 compliance keeps lagging, the effect will be slow.

Likely effects

  • EU critical infrastructure securityNegativeWeeks

    With neither of the 2 early-warning hubs operating, the risk that a warning in a cross-border attack gets stuck in national channels persists.

  • Corporate compliance burdenUncertain1–6 months

    NIS 2 scope rising above 110,000 entities and the reporting gap being documented could increase supervisory and enforcement pressure over the medium term.

  • Cyber cooperation with TürkiyeUncertain1–6 months

    With information sharing weak even within the EU, incident data sharing with candidate and neighbouring countries outside the EU should not be expected to expand in the near term; for Turkish institutions this sustains the need for a separate channel.

Possibilities, ranked

  1. 1
    Gradual tightening55%

    The Commission accepts the recommendations and reviews notification and funding oversight rules; the hubs become operational with delays.

    Watch: An announcement that ATHENA or ENSOC is operational and the Commission's formal response document

  2. 2
    Status quo persists30%

    The report draws brief attention, member states' notification habits do not change and NIS 2 transposition progresses slowly.

    Watch: The number of cross-border notifications in ENISA's next annual report

  3. 3
    Major incident as trigger15%

    A new cross-border attack leads to the first full activation of the crisis procedure and rapid reform.

    Watch: An incident being classified as large-scale for the first time

Probabilities are calibrated judgement based on the sources, not measurement, and are revised as new information arrives. Not investment advice.

Market reaction

Indicators affected

  • Cyber funding (2021–2027) €1.4 billion
  • 2025 cross-border reports 14

Sources

  1. Euronews — The EU spent billions on a cyberattack shield — nobody checked if it worked
  2. Eunews — Cybersecurity: Court of Auditors says EU response falls short
  3. Trending Topics — Europe's Cyber Defence Only Partly Effective: Special Report