Home / Technology / EU Cybersecurity Sharing Fails: "Achilles Heel" Revealed
EU Cybersecurity Sharing Fails: "Achilles Heel" Revealed
21 Sep
Summary
- EU cybersecurity cooperation hampered by poor information sharing.
- Aviation cyberattack disrupted multiple European airports.
- Member states face EU legal action for non-compliance.

The European Union's initiatives to combat cyberattacks are significantly undermined by member states' reluctance to share crucial incident information. The European Court of Auditors identified this poor information exchange as the "Achilles heel" of the EU's cybersecurity system, diminishing the value of its networks and cooperation mechanisms.
Despite the EU investing substantial funds, including €1.4 billion in its current budget for cybersecurity, the court found that these efforts are not yielding optimal results. Timely and actionable intelligence is vital for responding effectively to serious cyber incidents, a necessity that is currently unmet.
A stark example cited involved a ransomware attack in September 2025 that impacted technology providers for the aviation industry, causing disruptions at airports in London, Brussels, Berlin, and Dublin. Shockingly, none of the affected member states notified the EU cybersecurity agency or fellow members about this significant breach.
National security legislation within individual countries often obstructs the necessary cross-border information sharing. The auditors noted that no EU state has officially reported a "large-scale" cybersecurity incident since 2016, despite the definition applying to attacks affecting at least two members. Consequently, in July, the European Commission referred France, Ireland, the Netherlands, and Spain to the EU Court of Justice for failing to implement EU measures on sharing cybersecurity information into their national laws.