Drooid Logo
Back to story perspectives

Full Breakdown

EU Cybersecurity Spending Faces Oversight Gaps, Audit Finds

By Drooid · · How we work

Core Findings on Funding and Oversight

The European Court of Auditors (ECA) reports that the EU has earmarked €1.4 billion from the Digital Europe Programme to protect Europe from cyberattacks. The audit reveals that when this funding is transferred to external grant beneficiaries, no independent body verifies the beneficiaries’ assessments of third-party ownership or control. Auditors warn that this gap could expose sensitive infrastructure, operational data and security-critical technologies to actors linked to hostile states.

Gaps in Early-Warning and Incident Reporting

The ECA also notes that the EU’s early-warning network, the European Cybersecurity Alert System (ATHENA and ENSOC), remains non-functional because required tools, cooperation agreements and technical standards have not been procured. Since 2016, no member state has classified any cyber incident as “large-scale,” not even major events such as WannaCry or the 2024 CrowdStrike-related outage. Consequently, the crisis-escalation procedure has never been fully triggered. In 2025, only 14 cross-border incidents were formally notified by seven countries, a fraction of the 322 incidents that ENISA independently identified that year.

Official Responses and Planned Reforms

The European Commission has responded by proposing a new cybersecurity package that would revise the Cybersecurity Act, introduce a risk-based supply-chain security framework, and drastically increase ENISA’s budget. Under the Cyber Resilience Act, hardware and software manufacturers must report exploited vulnerabilities or severe incidents within 24 hours to national CSIRTs and ENISA’s Single Reporting Platform; breaches can be fined up to €15 million or 2.5 % of global turnover.

Verbatim Quotes

  • “The EU has made progress in building a cybersecurity cooperation framework, but it is not yet working as effectively as it should,” — George-Marius Hyzler

Data & Statistics

  • €1.4 billion allocated for EU cyber defence (ECA).
  • 14 cross-border incidents formally notified in 2025 (ECA).
  • 322 multi-state incidents identified by ENISA in 2025 (ECA).
  • Fines of up to €15 million or 2.5 % of global turnover for serious breaches under the Cyber Resilience Act (EU legislation).