World

EU cyber early-warning shield remains offline

Auditors say €1.4 billion programme lacks basic verification and information-sharing, procurement delays leave networks in name only

Images

The EU spent billions on a cyberattack shield — nobody checked if it worked The EU spent billions on a cyberattack shield — nobody checked if it worked euronews.com

Brussels has spent €1.4 billion building an EU-wide “early warning” shield against major cyberattacks. According to Euronews, auditors now say that roughly 20 months after the system was created it is still not switched on, with key parts stalled by procurement delays.

The European Court of Auditors’ report, which examined the EU’s detection and response to major cybersecurity incidents between 2022 and 2025, describes a structure heavy on networks, hubs and acronyms but light on working links between them. Two hubs meant to anchor the European Cybersecurity Alert System — ATHENA and ENSOC — had not started work, auditors said, while cooperation agreements, a shared classification system and technical standards were still missing. In a serious cross-border incident, minutes matter; the report instead points to “poor information-sharing” as the central weakness, with national security laws in some member states limiting what can be shared.

The same report also flags a funding pipeline that largely runs on trust. Grant beneficiaries are responsible for checking the ownership and control of third parties receiving EU cybersecurity money, but the European Cybersecurity Competence Centre that oversees the grants does not verify those assessments, according to the auditors. The practical risk is not abstract: sensitive infrastructure data and security-critical technologies can end up exposed if intermediaries misjudge — or choose not to scrutinise — who sits behind subcontractors and partners.

Even where institutions exist, mandates overlap. Auditors described duplication between bodies tasked with monitoring cyber threats, including a European Commission cyber situation centre set up in 2022 and supported largely by external providers, alongside the EU Agency for Cybersecurity (ENISA), which also monitors threats and builds situational awareness. The EU’s Cyber Blueprint, adopted in 2025, is meant to clarify roles during major crises, but auditors said the way the EU’s two main cyber networks work together still has not been formally defined — a bureaucratic gap that becomes operational during an attack.

The report’s recommendations are basic: accelerate rollout of the alert system, clarify who does what, improve information-sharing, and strengthen checks on funding recipients. Responsibility for responding to incidents still sits mainly with member states, leaving the EU to add value only when disruptions spill across borders and no single national authority can see the whole picture.

The EU’s cyber early-warning network was designed to spot attacks before they spread. Auditors say Europe is still waiting for the warning.