Politics Business Culture Technology Environment Travel World
Home Technology Feature
Technology · Exclusive

EU's €1.4bn cyber shield unverified as alert system stays offline

EU's €1.4bn cyber shield unverified as alert system stays offline
Technology · 2026
Photo · Kai Lindgren for European Pulse
By Kai Lindgren Technology Editor Sep 22, 2026 4 min read

Brussels has committed €1.4 billion to hardening Europe against cyberattacks, but the European Court of Auditors (ECA) has concluded that the bloc cannot confirm whether that money is flowing to organisations potentially under the sway of adversarial governments. The finding, published on Monday, covers EU efforts to detect and respond to major incidents between 2022 and 2025.

Under the Digital Europe Programme, the EU's principal funding vehicle for cybersecurity in the 2021–2027 budget, grant recipients are supposed to vet the ownership and control of third parties receiving money. The European Cybersecurity Competence Centre, which administers the grants, does not independently check those assessments. Auditors warn this leaves sensitive infrastructure, operational data and security-critical technologies exposed.

An alarm system that never rang

The audit also found that the EU's early-warning network for large-scale cyberattacks is not yet up and running. Two hubs intended to anchor the European Cybersecurity Alert System — known as ATHENA and ENSOC — have not begun operations because of procurement delays. The cooperation agreements, common classification system and technical standards needed to make the alert system function are likewise absent.

"The EU has made progress in building a cybersecurity cooperation framework, but it is not yet working as effectively as it should," said George-Marius Hyzler, the ECA member responsible for the audit. "When a serious cyber incident occurs, timely and actionable information is essential. Without it, networks and mechanisms lose much of their added value."

The alert system was established under the EU Cyber Solidarity Act in February 2025 to serve as a unified network for real-time monitoring, early threat detection and cross-border intelligence-sharing on large-scale attacks against Europe.

Information-sharing as the weak link

Auditors singled out poor information-sharing as the central flaw in the EU's cyber defences, calling it the Achilles heel of the entire system. The Cyber Blueprint, adopted in 2025, largely clarifies roles during major crises, but the report found that how the EU's two main cyber networks interact has still not been formally defined. That has hindered cooperation between the CSIRTs network, which gathers national incident-response teams, and EU-CyCLONe, the bloc's crisis cooperation network.

Some member states are still transposing the updated NIS 2 Directive into national law, while security legislation in certain countries restricts what information can be shared at all. Taken together, the auditors say, these gaps mean EU networks may struggle to detect threats early and mount an effective joint response.

Overlapping mandates and unspent leverage

The report also flagged duplication between EU bodies monitoring cyber threats. The European Commission's cyber situation centre, set up in 2022 and largely staffed by external providers, was found to be doing work that overlaps with the European Union Agency for Cybersecurity (ENISA), which already tracks threats and builds situational awareness across the bloc.

The auditors' recommendations include improving information-sharing between EU networks, clarifying how bodies with overlapping mandates should cooperate, accelerating the rollout of the alert system, and strengthening security checks on funding recipients.

Responsibility for responding to cyber incidents rests mainly with individual member states, but the EU plays a critical role when disruptions are severe, cause significant financial losses or affect several countries at once — beyond what any single state can handle alone.

Earlier this year, the European Commission proposed a new Cybersecurity package to revise the Cybersecurity Act, including a strict, risk-based supply chain security framework aimed at preventing high-risk third countries from accessing critical EU infrastructure. The package also proposes drastically increasing ENISA's budget and revising existing EU and national laws to streamline the administration of Union-wide cybersecurity rules.

For now, the gap between spending and verification remains. As Europe confronts a threat landscape that includes state-linked intrusions and AI-generated political deepfakes, the auditors' findings suggest that the bloc's cyber shield is still more aspiration than operational reality.

More from this story

Next article · Don't miss

Baghdad Pushes to Collect 6 Million Weapons as Iran-Backed Militias Resist

Baghdad has recast its 30 September deadline as the start of a regulatory process rather than a hard cut-off for armed factions to surrender weapons. Kataib Hezbollah and Harakat al-Nujaba have refused to hand over what they call "resistance weapons". Washingt

Read the story →
Baghdad Pushes to Collect 6 Million Weapons as Iran-Backed Militias Resist