EU’s Cybersecurity Billions: Are We Really Protected?

Brussels has allocated a staggering €1.4 billion to fortify Europe against cyberattacks, but hold on a second—who’s keeping tabs on where all tha

EU's Cybersecurity

Brussels has allocated a staggering €1.4 billion to fortify Europe against cyberattacks, but hold on a second—who’s keeping tabs on where all that money is going? A shocking report released on Monday by the European Court of Auditors (ECA) reveals a glaring issue: when EU funding is handed off to third parties, there’s no independent check to see if it’s reaching organizations that could be influenced by hostile states. Yup, you heard that right.

This critical warning sheds light on the EU’s cybersecurity operation plans for 2022 to 2025. It turns out grant beneficiaries are supposed to assess who’s getting the EU cybersecurity cash, but the European Cybersecurity Competence Centre—the body in charge of these grants—doesn’t verify those assessments. As a result, sensitive infrastructures, key operational data, and crucial security technologies could be left vulnerable. Can you believe that?

The funding falls under the Digital Europe Programme, but here’s the kicker: the EU’s early-warning network for major cyberattacks isn’t even up and running yet! Two key hubs, named ATHENA and ENSOC, which are meant to anchor the European Cybersecurity System, are still without the necessary tools to detect threats and share vital information. This has been delayed repeatedly due to procurement issues. Auditors pointed out that the essential cooperation agreements, a common classification system, and the technical standards needed to kickstart the system are still absent. George-Marius Hyzler, the ECA member overseeing the audit, put it bluntly.

Auditors flagged poor information-sharing as the Achilles’ heel of the EU’s cyber defenses. They stated that incidents on this scale should have been classified as significant or large-scale, which would have triggered formal notifications. But none of the affected states reported it as such. And it doesn’t stop there. No member state has ever classified a single cybersecurity incident as “large-scale.” This is a massive red flag, folks! The crisis-escalation procedure for major cyberattacks hasn’t been fully activated even once. Member states only formally notified 14 cross-border incidents in 2025, and that was from just seven countries—out of a whopping 322 incidents that impacted two or more member states identified by ENISA the previous year.

Now, let’s talk about the Cyber Blueprint adopted in 2025. It was supposed to clarify roles and responsibilities during major cybersecurity crises, but how effective is the EU’s crisis cooperation network? Well, all but two member states missed the deadline to implement the EU’s cyber situation center established in 2022. And guess what? It overlaps with the European Union Agency for Cybersecurity (ENISA), which is already monitoring threats and building situational awareness across the bloc.

The auditors are also calling for a budget revision and changes to existing EU and national laws to streamline the administration and implementation of Union-wide cybersecurity rules. As of September this year, the Cyber Resilience Act mandates hardware and software manufacturers to report any exploited vulnerabilities or serious security incidents within 24 hours to national CSIRTs and ENISA’s Single Reporting Platform. The fines for serious breaches? Up to €15 million or 2.5% of global turnover.

So, where does that leave us? With all this funding and talk of cybersecurity, are we really any safer? Or are we just throwing money at a problem without properly checking if it’s even working? We’ll have to keep our eyes peeled for what happens next in this ongoing saga…

Kaynak: Orijinal Haber

Bir yanıt yazın

E-posta adresiniz yayınlanmayacak. Gerekli alanlar * ile işaretlenmişlerdir