What happened

The EU Court of Auditors has published a report criticising the bloc's ability to detect and respond to large scale cyber incidents. The audit says the roughly EUR 1.4 billion cybersecurity budget is doing some good, but that the programme has an Achilles heel in what it calls the insufficient exchange of information.

Several specific problems are named. Roles are not formally defined between national CSIRTs and EU-CyCLONe, so cooperation depends on relationships rather than mandate. NIS2 is being transposed into national law slowly, which leaves the underlying obligations uneven across member states. National security laws restrict what can be shared, which works against the cross border picture the incident response network exists to build.

The audit also flags delays to the European Cybersecurity Alert System, with two hubs (ATHENA and ENSOC) still not operational because of procurement delays. It warns that at the time of inspection, organisations receiving EU cybersecurity funding were not being vetted, leaving them exposed to intrusion or influence by non EU states.

In the same week, ENISA published its Threat Landscape 2026 report, based on 8,257 incidents recorded in 2025. Low impact DDoS attacks made up 51 percent of recorded incidents, driven mainly by geopolitical tension, while ransomware remained the highest impact short term threat. Public administration was the most affected sector at 32 percent.

Why this is a GRC story

Reporting duties only work if the pipeline behind them works. NIS2 and the sector rules built on it give organisations tight windows to report significant incidents. Those obligations assume a national authority that can receive, assess and pass on the report. An audit that finds undefined roles and slow transposition is really telling firms that the receiving end of their incident report is still being built.

Information sharing is a governance problem, not a technology one. The blockers named here are mandates, legal restrictions and procurement, not tooling. That is the same shape of problem most organisations meet internally when they try to join up risk data across functions.

Grant recipients are third parties. The finding that funded organisations were not vetted is a supply chain and integrity control gap. Anyone who hands money or data to a partner has the same question to answer: what did we check, and could someone else influence them?

What to watch

Watch the pace of NIS2 transposition, because that sets when enforcement becomes real in each member state. Watch whether formal roles get defined for the response network and whether the alert system hubs finally come online.

The practical takeaway for a security or compliance function: review your incident notification runbook against the authority you would actually report to. Confirm the contact, the format and the clock, and note where you are relying on an assumption.

Attribution: Analysis based on Infosecurity Magazine and related public reporting. This article is original commentary, not a repost of the source material.

More daily case studies
← Back to GRC News