EU Cybersecurity Incident Response Gaps Exposed

EU Cybersecurity Incident Response Gaps Exposed

A new European Court of Auditors report finds serious EU cybersecurity incident response gaps at the very top of the escalation ladder: no EU member state has ever formally classified a cyber incident as “large-scale,” the tier that triggers cross-border EU crisis coordination, since that classification system existed from 2016. Not WannaCry. Not NotPetya. Not the 2024 global outage triggered by the faulty CrowdStrike update. Not last year’s ransomware attack on Collins Aerospace that forced London Heathrow, Brussels, Berlin Brandenburg and Dublin airports to revert to manual check-in for days.

What Happened

The European Court of Auditors published Special Report 19/2026 on September 21, auditing EU cybersecurity cooperation actions between 2022 and 2025, with field visits to Ireland, Greece and Italy. The audit’s central finding is that the EU has built a cooperation framework, coordination between national CSIRT networks and EU-CyCLONe, the body created specifically to manage major cyber crises, but that framework has never been triggered at its highest severity tier in nine years, including for incidents the report itself says should have qualified. Beyond classification, the auditors found the EU’s dedicated early-warning infrastructure, two centers named ATHENA and ENSOC, still not operational at the time of the audit, delayed by procurement procedures, with cooperation agreements and shared incident classification still incomplete. The report also flags that the European Cybersecurity Competence Centre does not itself verify the ownership and control assessments that recipients of EU cybersecurity grants are required to submit, a gap the auditors say could expose EU-funded critical infrastructure or strategic technology projects to undisclosed foreign influence. Separately, the audit notes that only a minority of member states had transposed the NIS2 Directive into national law by its original October 2024 deadline.

Why It Matters

For a NIS2-regulated organization in the DACH region, the practical takeaway is not abstract criticism of EU institutions, it is that any incident response plan implicitly counting on EU-level crisis coordination as a backstop (“if this gets bad enough, Brussels steps in”) is resting on a mechanism that, per the EU’s own auditors, has never once fired, for anything, in nine years. The burden of detection, internal escalation, regulatory reporting and public communication sits with the organization and its national CSIRT contact, not a supranational response network still finalizing its own procurement.

What You Should Do Now

  1. Review your organization’s incident escalation plan for any assumption that a sufficiently severe incident will trigger external EU or cross-border support; treat that support as unlikely to materialize in practice.
  2. Confirm your NIS2 significant-incident reporting timelines and contacts (early warning within 24 hours, incident notification within 72 hours) are current and do not depend on external classification.
  3. If your organization receives EU cybersecurity grant funding involving third parties, confirm your own ownership and control assessments are documented and defensible, since the report finds the funding body does not verify them independently.
  4. Revisit tabletop exercises to explicitly test the scenario where no external large-scale classification occurs, even during a genuinely severe, multi-organization incident.

DIESEC Perspective

The gap this report describes is not a technical one, it is organizational, and it is the kind of gap that only becomes visible during an actual crisis, when it is too late to close. Nine years without a single “large-scale” classification, despite incidents that plainly qualified, tells DACH Mittelstand organizations something concrete: build your response plan assuming you are on your own until proven otherwise.

Not sure whether your incident escalation plan assumes support that may not materialize in practice? Contact DIESEC for a rapid NIS2 incident-response and escalation-plan review.

Sources: Euronews | DigitalShield
Published: 2026-09-25 | Category: Compliance & Governance | ~4 min read