EU auditors find critical gaps in response to large-scale cyberattacks

The European Court of Auditors has found significant gaps in the EU’s ability to coordinate its response to major cybersecurity incidents, particularly when sharing timely and actionable information between national and EU-level organizations.

The audit found that cooperation between two key cyber response networks has still not been formally defined, while differences in national security laws and implementation of the NIS2 Directive can hinder information sharing. The European Cybersecurity Alert System was also not operational at the time of the audit, with two security hubs delayed by procurement issues and key cooperation agreements, technical standards and classification systems still missing.

Auditors also identified overlapping responsibilities among EU cybersecurity bodies and weaknesses in checks on organizations receiving EU cybersecurity funding. The findings come despite €1.4 billion being allocated to cybersecurity through the EU’s Digital Europe Programme for 2021–2027.

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

“Critical infrastructure crosses borders faster than authority does. A state-backed attacker can probe the same router or remote-access service across energy, transport, healthcare, telecoms, and water. The first defender to see the intrusion needs a way to warn every operator running the same technology.

“The European Court of Auditors’ audit shows why that warning can stall. National response teams, EU-CyCLONe, and the European Union Agency for Cybersecurity operate across different security laws, NIS2 implementations, classifications, and mandates. During an active incident, a technical warning becomes a permissions problem.

“CISA’s Automated Indicator Sharing moves machine-readable indicators and defensive measures in real time. The Joint Cyber Defense Collaborative adds playbooks and rapid exchanges across government, industry, and international partners. Europe needs those functions tied to its existing institutions, with shared rules for confidence, urgency, and action.

“I would measure the investment by one clock, the time between an energy operator seeing a state-backed probe and every similarly exposed operator receiving something usable. Every unresolved permission is attack surface.”

John Strand, Owner, Black Hills Information Security:

“There is absolutely nothing about this report that surprises me. It really doesn’t matter what type of organization you’re dealing with. It could be nation-states trying to coordinate during an incident, or internal security teams working inside the same company. You’re going to see the same communication gaps, overlaps, and confusion.

“My recommendation is simple. Drill. Run incident response tabletop exercises regularly. Keep them terse. Keep them quick. Don’t make them overly complicated. Run multiple scenarios specifically designed to expose where communication starts to break down.

“Then document those gaps and build a plan of action and milestones to fix them. Communication problems during an incident aren’t unusual. I would expect to find them in almost any organization. The important question is whether you find them during an exercise or during a real incident.”

Seemant Sehgal, Founder & CEO, BreachLock:

“The audit findings track with a pattern that shows up in a lot of large organizations trying to coordinate incident response across independent teams. Frameworks describe how the handoffs should work, but during a live incident, the seams where responsibilities were never clearly assigned are where delays happen, and 1.4 billion euros in funding does not close that gap on its own if the operational agreements underneath it are still being negotiated.

“The useful question is whether the ECA report will apply enough pressure to get the European Cybersecurity Alert System operational and to define those handoffs before the next major incident, rather than during one.”

Co-ordinating any sorts of incidents is key to bringing them under control quickly. And if anyone has the will to do it, the EU does. So I hope that they don’t prove me wrong.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading