{"id":465622,"date":"2026-09-22T08:00:56","date_gmt":"2026-09-22T06:00:56","guid":{"rendered":"https:\/\/www.eunews.it\/2026\/09\/22\/lente-della-corte-dei-conti-sulla-cybersicurezza-la-risposta-ue-alle-minacce-e-carente\/"},"modified":"2026-09-22T10:28:13","modified_gmt":"2026-09-22T08:28:13","slug":"court-of-auditors-puts-cybersecurity-under-scrutiny-eu-response-to-threats-falls-short","status":"publish","type":"post","link":"https:\/\/www.eunews.it\/en\/2026\/09\/22\/court-of-auditors-puts-cybersecurity-under-scrutiny-eu-response-to-threats-falls-short\/","title":{"rendered":"Court of Auditors puts cybersecurity under scrutiny; EU response to threats falls short"},"content":{"rendered":"<p>Brussels \u2013 The measures put in place by the European Union to detect and respond to significant, large-scale cybersecurity incidents are inadequate, <a href=\"https:\/\/www.eca.europa.eu\/it\/news\/NEWS-SR-2026-19\" target=\"_blank\" rel=\"noopener\">the European Court of Auditors said in&nbsp;a report. <\/a>It urged the EU to improve information-sharing practices, refine coordination to avoid duplication of effort among the various bodies involved, make the European cybersecurity alert system operational, and strengthen security checks on recipients of EU funding. <\/p>\n<p>The Court points out that such&nbsp;incidents can \u201cdisrupt public services, businesses, critical infrastructure, and the EU\u2019s internal market.\u201d Responsibility for the response lies primarily with the Member States, but the Union \u201cplays an important role.\u201d For example, when such incidents \u201ccause major disruption, significant financial losses, or substantial harm to people or organisations (significant cybersecurity incidents), or when they affect several member states and go beyond the capacity of a single country to respond effectively (large-scale cybersecurity incidents).\u201d&nbsp;<\/p>\n<p>To tackle these threats, the EU is investing increasingly in strengthening cybersecurity. \u201cUnder the 2021-2027 EU budget, the Digital Europe Programme is the main source of cybersecurity funding, with \u20ac1.4 billion allocated,\u201d according to the Court. According to George-Marius Hyzler, a member of the European Court of Auditors responsible for the audit, this represents \u201cprogress\u201d made \u201cin building a cybersecurity cooperation framework.\u201d At the same time, however, the EU \u201cis not yet working as effectively as it should,\u201d while &#8220;when a serious cyber incident occurs, timely and actionable information is essential. Without it, networks and mechanisms lose much of their added value\u201d, he notes. <\/p>\n<p>According to the auditors,<strong> the Achilles heel of the entire system is the insufficient exchange of information.<\/strong> This is because, although the cybersecurity programme, adopted in 2025, sets out in detail the roles and responsibilities for managing major cybersecurity crises, \u201cthe way the two EU cyber networks work together has still not been formally defined. This hampers the cooperation of the CSIRTs network, which brings together national teams dealing with cyber incidents, and EU-CyCLONe, an EU network for cyber crisis cooperation.\u201d Added to this is the fact that some Member States &#8220;are still implementing&#8221; the updated EU cybersecurity rules, such as the NIS 2 Directive, while \u201cnational security laws restrict what information can be shared.\u201d The result is that EU networks face difficulties in detecting threats at an early stage and coordinating an effective response.&nbsp;<\/p>\n<p>The <span class=\"il\">Court<\/span> also identified \u201coverlaps between some EU bodies responsible for monitoring cybersecurity threats.\u201d In particular, between the European Commission\u2019s Cyber Situation Centre and the European Union Agency for Cybersecurity (ENISA). Furthermore, \u201cat the time of the audit, the European Cybersecurity Alert System was not yet operational. The two hubs examined by the auditors \u2013 ATHENA and ENSOC \u2013 had not started operations because of procurement delays,&#8221; and \u201cthe necessary cooperation agreements, a common classification system, and technical standards needed for the system to work were still lacking.\u201d&nbsp;<\/p>\n<p>Finally, the auditors identified weaknesses in how some organisations receiving EU cybersecurity funding were being checked. \u201cAlthough grant beneficiaries are responsible for assessing the ownership and control of third parties in receipt of financial support, the European Cybersecurity Competence Centre does not verify these assessments. As a result, sensitive infrastructure, operational data, and security-critical technologies could be exposed to security risks,\u201d the Court concluded.<\/p>\n<p>At the Commission, officials \u201cwelcomed\u201d the European Court of Auditors\u2019 special report. \u201c<strong>We will carefully examine its recommendations to strengthen further the Union\u2019s capabilities in the detection, situational awareness and response to cyber threats and incidents<\/strong>. The revision of the Cybersecurity Act puts forward proposals to enhance ENISA\u2019s capabilities to support Member States in situational awareness and incident response,\u201d they said.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>According to the report, the Achilles\u2019 heel of the entire system is the lack of information-sharing<\/p>\n","protected":false},"author":1,"featured_media":234397,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"episode_type":"","audio_file":"","podmotor_file_id":"","podmotor_episode_id":"","cover_image":"","cover_image_id":"","duration":"","filesize":"","filesize_raw":"","date_recorded":"","explicit":"","block":"","jnews-multi-image_gallery":[],"jnews_single_post":{"format":"standard","override":[{"template":"1","parallax":"1","fullscreen":"1","layout":"right-sidebar","sidebar":"default-sidebar","second_sidebar":"default-sidebar","sticky_sidebar":"1","share_position":"top","share_float_style":"share-monocrhome","show_featured":"1","show_post_meta":"1","show_post_author":"1","show_post_author_image":"1","show_post_date":"1","post_date_format":"default","post_date_format_custom":"Y\/m\/d","show_post_category":"1","show_post_reading_time":"0","post_reading_time_wpm":"300","post_calculate_word_method":"str_word_count","show_zoom_button":"0","zoom_button_out_step":"2","zoom_button_in_step":"3","show_post_tag":"1","show_prev_next_post":"1","show_popup_post":"1","show_comment_section":"1","number_popup_post":"1","show_author_box":"0","show_post_related":"1","show_inline_post_related":"0"}],"image_override":[{"single_post_thumbnail_size":"crop-500","single_post_gallery_size":"crop-500"}],"trending_post_position":"meta","trending_post_label":"Trending","sponsored_post_label":"Sponsored by","disable_ad":"0","subtitle":""},"jnews_primary_category":[],"jnews_override_counter":{"view_counter_number":"0","share_counter_number":"0","like_counter_number":"0","dislike_counter_number":"0"},"footnotes":""},"categories":[25710],"tags":[26763,25963,35796,27101,30510,33394],"class_list":["post-465622","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-net-tech-en","tag-corte-dei-conti-en","tag-cybersecurity-en","tag-individuazione","tag-minacce-en","tag-answer-en","tag-ue"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.eunews.it\/en\/wp-json\/wp\/v2\/posts\/465622","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.eunews.it\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.eunews.it\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.eunews.it\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.eunews.it\/en\/wp-json\/wp\/v2\/comments?post=465622"}],"version-history":[{"count":1,"href":"https:\/\/www.eunews.it\/en\/wp-json\/wp\/v2\/posts\/465622\/revisions"}],"predecessor-version":[{"id":465623,"href":"https:\/\/www.eunews.it\/en\/wp-json\/wp\/v2\/posts\/465622\/revisions\/465623"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.eunews.it\/en\/wp-json\/wp\/v2\/media\/234397"}],"wp:attachment":[{"href":"https:\/\/www.eunews.it\/en\/wp-json\/wp\/v2\/media?parent=465622"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.eunews.it\/en\/wp-json\/wp\/v2\/categories?post=465622"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.eunews.it\/en\/wp-json\/wp\/v2\/tags?post=465622"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}