EU Auditors: €1.4 Billion Cyber Budget Undermined by Delays, Secrecy and Patchy Reporting
Published on 09/22/2026 at 16:51 | Editorial boerse-global.de
Europe's ability to detect and contain a large-scale cyberattack is being held back not by a shortage of money but by the way that money is spent and information is shared, according to the European Court of Auditors. In a special report published on 21 September 2026, the EU's external auditor singles out weak information exchange between the bodies involved as the central flaw in the bloc's current security architecture.
Responsibility for cyber defence rests primarily with individual member states, with Brussels stepping in only when disruptions spill across borders or threaten the functioning of the single market.
Early-warning hubs still not operational
George-Marius Hyzler, the court member who led the audit, acknowledged progress in the EU's cybersecurity cooperation system but said the machinery was not running smoothly. Friction in the flow of information, he argued, erodes the effectiveness of the whole setup, and EU funding has to deliver measurable results — which in turn requires fast data sharing.
The auditors examined how €1.4 billion in cybersecurity funding from the 2021–2027 EU budget, channelled through the Digital Europe programme, was used during a review period running from 2022 to 2025 that included visits to Ireland, Greece and Italy.
Their fieldwork uncovered significant hold-ups in key infrastructure projects. The planned early-warning systems ATHENA and ENSOC were not yet operational when the audit took place, having fallen foul of delays in tendering and procurement. Eighteen months after the projects got under way, no contract had been signed, forcing extensions of 15 and 18 months respectively.
Essential cooperation agreements, technical standards and a common classification system were also missing for both hubs — ATHENA, which covers Bulgaria, Greece, Cyprus and Malta, and ENSOC, which involves Spain, Italy, Luxembourg, the Netherlands, Austria, Portugal and Romania.
Blurred mandates and a trust deficit
Coordination between operational units is running into limits of its own. According to the court, the division of labour between the network of Computer Security Incident Response Teams (CSIRTs) and the EU-CyCLONe network is not clearly defined. National security rules and strict confidentiality requirements further restrict the sharing of security-relevant information, while a lack of mutual trust puts a brake on exchanges.
At the same time, the auditors flagged overlaps between the European Commission's cyber situation centre, set up in 2022, and the EU cybersecurity agency ENISA. The situation centre's mandate comes with just under €18 million over four years and expires at the end of 2026.
Regulatory compliance and grant controls showed weaknesses too. Only two member states met the autumn — specifically October — 2024 deadline for transposing the NIS-2 directive. Whereas the previous directive covered roughly 15,500 organisations, NIS-2 now binds more than 110,000 entities; in Austria, the national implementing law NISG 2026 does not enter into force until October 2026. The European Cybersecurity Competence Centre, meanwhile, did not fully verify the ownership and control structures of grant recipients.
Between 2022 and 2025, 7 percent of applicants and subcontractors failed such checks. Of 11 projects examined in detail, the auditors rated four as satisfactory, found weaknesses in two and failed three.
One incident classified in a decade
The report highlights stark differences in how attacks are classified and counted. Since 2016, not a single member state has officially classified an incident as a large-scale or significant cross-border security incident.
In 2025, seven member states reported a combined 14 significant cross-border incidents, up from two in 2024, none in 2023 and three in 2022. ENISA, by contrast, recorded 322 incidents in 2024 that affected at least two member states.
Reporting practice to ENISA diverges as well. After annual figures of between 100 and 500 notifications from 2018 to 2021, the number rose to 1,276 cases in 2024, while the agency itself identified around 4,800 incidents from open sources.
For response capacity, €36 million has been earmarked for the Cyber Reserve for 2025 to 2027. Back in 2023, 84 percent of spending went purely on defence readiness; between 2024 and 2026, only nine member states had corresponding response services in place.
New regulatory frameworks are meanwhile taking effect, among them the Cyber Blueprint 2025 and the Cyber Resilience Act, applicable since September 2026. The latter requires exploited vulnerabilities to be reported within 24 hours and provides for fines of up to €15 million or 2.5 percent of worldwide annual turnover.
How unevenly prepared member states are is illustrated by Austria, which ranked 24th in the 2024 National Cyber Security Index (NCSI) with 85 out of 100 points and was placed in Tier 2 of the 2024 Global Cybersecurity Index.
