22 September 2026
Executive Summary
A new audit has identified significant weaknesses in Europe’s ability to share information during major cyber incidents, raising concerns over how effectively cross-border attacks affecting businesses and infrastructure can be contained.
The European Court of Auditors found that despite substantial investment in European cybersecurity, national authorities do not consistently share timely and actionable information with each other or with EU cybersecurity bodies.
Approximately €1.4 billion has been allocated to cybersecurity through the EU’s 2021-2027 budget.
But the auditors found that operational cooperation remains fragmented.
One example examined involved the September 2025 ransomware attack on an aviation technology provider, which disrupted check-in and boarding systems at several major European airports.
Despite the cross-border impact, none of the countries affected notified the EU Agency for Cybersecurity through the mechanism intended for significant incidents.
The auditors also found that no member state had formally reported a “large-scale” cybersecurity incident through the relevant EU mechanism since 2016.
That does not mean Europe has experienced no serious cyberattacks.
Rather, it highlights the problem identified by the auditors: significant incidents are occurring without necessarily being shared through the systems designed to coordinate the European response.
UK Impact
The UK is outside the EU’s institutional cybersecurity framework.
But British companies remain deeply connected to European:
- Airports.
- Banks.
- Logistics companies.
- Manufacturers.
- Technology providers.
- Cloud services.
- Telecommunications.
- Critical infrastructure.
A cyberattack affecting a European supplier can therefore interrupt UK operations regardless of whether UK systems themselves have been compromised.
Global Impact
Modern cyber incidents frequently cross national borders.
A single technology provider may simultaneously serve organisations across numerous countries.
Effective response therefore depends upon organisations understanding:
- Who has been attacked.
- Which systems are affected.
- Which vulnerabilities are being exploited.
- Whether the attack is spreading.
- Which mitigations are working.
Delayed information-sharing gives attackers additional time and leaves other organisations exposed to vulnerabilities that may already be known elsewhere.
The problem is particularly significant where critical infrastructure is involved.
Our View
Businesses should not assume government or regulatory information-sharing will provide sufficient early warning.
Companies should develop their own supplier intelligence and incident-response networks.
They should ask:
- Which technology suppliers are business-critical?
- Which suppliers are shared across multiple operations?
- How quickly must suppliers report cyber incidents?
- Are notification requirements contractual?
- Do suppliers have to disclose ransomware events?
- Are critical systems dependent upon one vendor?
- Can operations continue manually?
- Are alternative providers available?
- Are backups genuinely isolated?
- Have restoration procedures been tested?
- Who monitors supplier cyber incidents?
- Can access credentials be revoked quickly?
- Are cyber insurers notified appropriately?
- Are business-continuity teams connected with IT-security teams?
- Could an incident elsewhere in Europe affect UK operations?
- How would the business learn about it?
Cyber resilience cannot depend solely upon preventing an attack.
It must also depend upon how quickly an organisation learns that an attack elsewhere could affect it.
Risk Indicator: HIGH – EUROPE, CYBERSECURITY & THIRD-PARTY RISK
Does This Risk Affect Your Business?
Invictus Risk Solutions helps businesses find practical solutions to insurance, risk and commercial challenges.
From individual businesses to major international organisations, risk is our business.
TALK TO INVICTUS →Disclaimer
The information contained within these Market Alerts is provided for general market awareness and informational purposes only. It does not constitute financial, legal, investment, regulatory or insurance advice. Whilst every effort has been made to ensure accuracy at the time of publication using multiple reputable and independently verified sources, geopolitical events, legislation, regulation and market conditions may change rapidly. Readers should obtain appropriate professional advice before acting upon any information contained herein.
Invictus Risk Solutions LLP – Helping organisations stay ahead of emerging risks through informed insight and independent analysis.
