The EU spent billions on a cyberattack shield - nobody checked if it worked
Key Points:
- The European Court of Auditors (ECA) reported that €1.4 billion allocated by the EU to cybersecurity lacks independent verification when passed to third parties, risking exposure to hostile state influence.
- The EU's early-warning system for major cyberattacks, including the ATHENA and ENSOC hubs, remains non-operational due to delays and missing cooperation agreements, limiting timely threat detection and information sharing.
- Poor information-sharing among member states is a critical weakness, with significant cyber incidents often unreported or under-classified, preventing activation of the EU's crisis-escalation procedures.
- Overlapping mandates between EU cybersecurity bodies, such as the European Commission's cyber situation centre and ENISA, create inefficiencies, prompting recommendations for clearer cooperation and integration of alert systems.
- Recent legislative efforts include the Cyber Resilience Act mandating rapid vulnerability reporting and proposals to strengthen supply chain security and increase ENISA’s budget to enhance the EU's overall cybersecurity framework.