Who warns you when the attack is already under way in another member state?
7 min read
Anyone in Italy who has spent the past year tidying up their incident reporting has bought an obligation, not a protection. In 2025, across the whole Union, fourteen significant cross-border incidents were reported, by seven member states. The warning you expect when the same campaign, launched elsewhere, reaches your own systems will not come out of that circuit.
The figure is not an estimate: it is written in special report 19/2026 of the European Court of Auditors, whose publication notice appeared in the Official Journal of the European Union, C series, of 24 September 2026 (C/2026/4990). The audit covers the period from 2022 to 2025 and includes visits to three member states: Ireland, Greece and Italy. The conclusion is that “EU actions only partially facilitate the detection of and response to significant and large-scale cybersecurity incidents”.
Fourteen against three hundred and twenty-two
What the Court establishes has to be kept apart from what it recommends. The findings come first.
The fourteen reports of 2025 were not a bad year: member states had sent two in 2024, none in 2023, three in 2022. For perspective, the Court notes that in its 2024 threat landscape report ENISA had identified 322 incidents specifically targeting two or more member states. Incidents reported to ENISA in total during 2024 numbered 1 276, against roughly 4 800 counted by the same agency between June 2024 and June 2025 through open-source intelligence, meaning by reading the news. The Court is careful here: because member-state data is anonymised, the true extent of under-reporting cannot be measured. What the gap shows is that the two counts never meet.
There is a blunter finding. Since 2016 no member state has ever treated a cybersecurity incident as large-scale, and as a result “the EU-CyCLONe escalation procedure has never been fully activated due to a large-scale cybersecurity incident”.
In September 2025 the ransomware attack on the passenger processing software of Collins Aerospace forced major European airports back to manual operations. The Court writes that “no member state treated this incident as being either significant or large-scale cross-border” and that “The CSIRTs network did not advise EU-CyCLONe, which therefore did not support the coordinated management of the incident”.
Why the information stops at the border
The Court identifies three causes.
The first is transposition. Member states had until October 2024 to transpose NIS 2 and only two met the deadline; in the meantime, entities inside the scope were not legally required to report. The change of scale is not marginal: the Commission estimated 15 500 entities under the original NIS Directive, more than 110 000 under NIS 2.
The second is procedural. It falls to each member-state authority to decide whether a reported incident has cross-border impact and to identify the other states affected, and “Currently, there is no EU-wide platform that receives real-time incident reports from all member states”. Aggregated data reaches ENISA once every three months, anonymised: useful for statistics, useless for stopping a campaign in progress.
The third is sovereignty. If a state considers information about an attack on a critical entity to be classified, it is under no obligation to share it: representatives of the CSIRTs network and of EU-CyCLONe told the auditors that “sharing can only be done within the boundaries of national security legislation”. No analysis of national legal frameworks and their effect on sharing has ever been carried out at EU level. The network has meanwhile grown: from 28 national CSIRTs in 2016 to 42 CSIRTs and over 700 participants. In a network where sharing is voluntary, trust is the whole mechanism, and it does not scale by decree.
The remedy exists, but it is not switched on
The European Cybersecurity Alert System, set up by the Cyber Solidarity Act, is supposed to do precisely what is missing: small clusters of states exchanging indicators of compromise. Italy is in, inside the ENSOC cross-border hub together with Spain, Luxembourg, the Netherlands, Austria, Portugal and Romania — a grant of 10.4 million euro, running to 30 June 2028.
The state of play, according to the Court: the first procurement phase opened in May 2024 for ENSOC and July 2024 for ATHENA; successful candidates were notified only in April 2025; at the time of the audit, eighteen months after the launch, no contract had been signed for any of the lots. The interoperability guidelines ENISA should have issued by February 2026 were not there. The verbatim conclusion: “the cross-border hubs are not on track to achieve their objectives” and “the European Cybersecurity Alert System is not yet functioning”.
The recommendations, and the dates
Here we move to what the Court recommends: commitments by the institutions, not obligations on you. To the Commission, supported by ENISA: have the NIS Cooperation Group analyse the national security restrictions that limit sharing, and ensure that the single-entry point for reporting proposed by the Digital Omnibus can detect cross-border incidents — target implementation date 2027; and “work on solutions to enable real-time incident reporting to ENISA” — target 2028. For the alert system’s cooperation arrangements and interoperability standards to be in place, the Court again indicates 2028.
None of these dates shifts your own deadlines: the 24-hour early warning and the 72-hour notification stay where they are, and who classifies the event at eight on a Friday evening remains a problem inside your own walls, as does the documentary proof an inspection asks for. The difference is that, for at least two years, nobody will correlate what is happening to you with what already happened to a peer of yours in Spain or in Romania on your behalf.
Why a closed system
The Court describes a structural block, not a delay: the information that would save you is classified upstream, or does not exist in real time anywhere. If the alert does not come down to you, the only detection you can count on is the one running on your own material.
That material has two features that rule out a generic external service. It is precisely the up-to-date map of where you are weak — logs, indicators of compromise, asset inventory, supplier contracts, ticket history — and the Collins Aerospace incident is a reminder that the attack comes in through the supplier: the useful correlation has to be run over contracts and integrations, not only over traffic. And it is material that, at the very moment it matters, may already be in the hands of whoever is attacking you: uploading it to an external platform to have it analysed means exporting it with credentials that could be among the compromised ones. A closed system also allows the reverse: extracting the indicator you want to share with a peer or with the national agency without exporting the context around it.
Hence the two axes. Complying: the 24- and 72-hour windows and the incident taxonomy become a control that runs over your logs and your tickets and produces the draft notification, with the record of who decided and when — evidence you can show an inspector, not an opinion. Deciding: the same installation holds monitoring, asset registers, supplier contracts, archives and sensors together in a single operating model, on which AI agents run the checks with an operator in command — for large enterprises, defence, public administration and healthcare. On-premise on self-contained machines that need no deep integration into your network, or on a dedicated cloud with data centres in Italy and premises staffed by us, under shared management: you do not have to hire people to administer models.
Would you like to know what your system would see today of a campaign already running elsewhere? Half an hour with one of our specialists.
What we do not know
We do not provide legal advice: we work from public sources, here the full text of the report and the notice in the Official Journal of the European Union. The replies of the Commission, the ECCC and ENISA are published as separate documents, linked from the Court’s page: we could not download them, so we do not know whether the recommendations were accepted or contested. The report does not attribute individual findings to the three states visited: Italy is among them, but we do not know which observations concern it. Finally, the Court writes “at the time of the audit” without fixing a precise date beyond the 2022-2025 period: the cross-border hub procurements may have advanced since.