• Home  
  • Europe wants greater Intelligence sharing among member states: How can it keep it out of enemy hands?
Europe wants greater Intelligence sharing among member states: How can it keep it out of enemy hands?
- Europe

Europe wants greater Intelligence sharing among member states: How can it keep it out of enemy hands?

The European Court of Auditors (ECA) has highlighted one of the main weaknesses in the European cybersecurity architecture: Europe increasingly has more networks, mechanisms, and resources to detect and respond to major cyber incidents, but member states still do not share information with the speed, breadth, and uniformity needed for this framework to function as […]

The European Court of Auditors (ECA) has highlighted one of the main weaknesses in the European cybersecurity architecture: Europe increasingly has more networks, mechanisms, and resources to detect and respond to major cyber incidents, but member states still do not share information with the speed, breadth, and uniformity needed for this framework to function as a true European capability.

In its report ‘Detecting and responding to cybersecurity incidents,’ published this past September, the Court concludes that the measures adopted by the EU only partially facilitate the detection and response to significant and large-scale incidents. The main difficulties are the limited exchange of information, deficiencies in incident reporting, and delays in the implementation of some of the planned measures.

The problem is particularly relevant because a cyberattack on critical infrastructure can simultaneously affect several countries and sectors. However, the response still largely depends on national capabilities and decisions.

Information remains the weak point

The European framework already has specific mechanisms for sharing information. The NIS2 Directive consolidated the network of national incident response teams, the CSIRTs Network, and created EU-CyCLONe, the European network of liaison organizations for managing major cybersecurity crises.

On paper, both structures allow building a common picture of a threat and coordinating a response when an incident exceeds the capabilities of a single state. In practice, the Court of Auditors considers that this exchange remains insufficient.

One of the problems lies in the differences between national legislations and, in particular, in the limitations related to national security. When a state considers that certain information is classified or that its dissemination may compromise essential security interests, it may restrict its communication.

This is compounded by delays in the implementation of NIS2. The Court notes that only a portion of the states had timely fulfilled the obligations arising from the directive and that difficulties in determining when an incident has true cross-border repercussions also reduce the number of alerts that reach the entire Union.

The result is a paradox: threats do not respect borders, but the information necessary to combat them continues to be conditioned by legal, administrative, and security borders.

More information, but not for everyone

Here arises one of the most delicate issues for building true European intelligence. Increasing the exchange of information does not necessarily mean that all states, organizations, or authorities should have access to the same volume of data.

European legislation itself sets limits. The Cyber Solidarity Regulation, for example, states that the exchange of confidential information should be limited to that which is pertinent and proportional to the objective pursued, preserving confidentiality and security and defense interests. Additionally, it does not oblige the provision of information whose disclosure is contrary to the essential national security, public security, or defense interests of a member state.

This principle is especially relevant in a European scenario marked by the war in Ukraine and the activity of Russia and other state and non-state actors against European infrastructures and organizations. In July 2026, the EU Council once again denounced Russian cyber activities against member states and pointed out espionage and sabotage operations against governmental networks and critical infrastructures.

The question, therefore, is not only about getting states to share more information but about establishing what information can be shared, with whom, under what conditions, and with what guarantees that it will not end up in the hands of a hostile actor.

This particularly affects those member states whose geographical position, foreign relations, exposure to Russia, or dependence on certain infrastructures or providers may generate an additional risk of indirect access to sensitive information. It does not mean that it can be presumed that a member state will transfer information to Russia or another adversary: any restriction should be based on proven risks and objective security criteria. But it does pose the need to establish different levels of access and control mechanisms capable of reducing the risk of leaks or compromises.

At this point, the principle of need-to-know becomes especially important, meaning that access to sensitive information is determined based on specific operational needs and not simply by belonging to a particular organization or cooperation structure.

A European architecture with more capabilities, but still fragmented

The Court of Auditors considers that the EU has advanced in creating a common architecture but also warns of coordination problems among some of the existing structures.

The Union has allocated 1.4 billion euros from the 2021-2027 budget to cybersecurity within the Digital Europe program. However, some of the planned capabilities were not yet fully operational during the audit.

Among them is the European cybersecurity alert system, while delays have also been detected in projects aimed at improving cross-border detection. The Court also points out overlaps between certain threat monitoring capabilities of the Commission and ENISA.

The EU Cybersecurity Reserve is another instrument created to strengthen the response. Its objective is to provide assistance to member states in the event of serious incidents and subsequently facilitate recovery. The system allows part of the contracted services to be used for preparedness activities when they are not needed to respond to an incident, although the Court warns of the risk that this flexibility may end up shifting resources from response to preparation.

The ECA recommends, among other measures, that the Commission, with the support of ENISA, specifically analyze the restrictions derived from national security legislations that currently hinder information exchange. The goal would be to identify legal and technical solutions that allow increased cooperation without eliminating national safeguards. The expected horizon for this action is 2027.

The EU also wants to advance in intelligence against hybrid threats

The issue of information exchange is not limited to the strictly technical realm of cybersecurity. The European Parliament has placed shared intelligence at the center of its new approach to hybrid threats.

On September 16, the European Parliament approved by 470 votes in favor, 129 against, and 62 abstentions its resolution on hybrid warfare and the protection of the territorial integrity and critical security and defense infrastructures of the EU.

The text again calls for increased intelligence sharing among member states and the systematic incorporation of data and intelligence-based analysis into EU crisis planning and management. It also proposes that the Single Intelligence Analysis Capability (SIAC) be consolidated as the core of intelligence analysis capability within European institutions.

The resolution is also based on a realization: hybrid campaigns can combine cyberattacks, sabotage, espionage, disinformation, and other actions that, individually, may appear to be disconnected incidents but respond to the same operation.

The Parliament identifies Russia, directly or through proxies like Belarus, as the state actor representing the main hybrid threat to the EU, while also noting the growing role of China, Iran, and North Korea in enabling or amplifying certain hostile activities.

The debate anticipated by MEP José Cepeda

The debate on how far this information exchange should go directly connects with the interview we published in Digital Shield on September 28 with MEP José Cepeda, one of the negotiators of the hybrid warfare report approved by the Parliament.

Cepeda argued that “sharing more and better intelligence cannot be based on blind trust.” His approach aligns with one of the central issues now being raised again by the Court of Auditors: the need to increase information exchange without turning European cooperation into an indiscriminate transfer of sensitive information.

 

 

 

The MEP proposed that access should be adjusted to the role of each authority, the sensitivity of the data, and the existing risks, using the need-to-know principle and keeping classified national information protected. He also noted that when there is a proven risk that certain data could reach a hostile actor, access should be limited and safeguards reinforced.

The approval of the report by the European Parliament gives political backing to that approach: the EU needs a more integrated intelligence capability, but the path does not necessarily involve eliminating national controls, but rather ensuring that states can securely share the information necessary to detect patterns and threats that no country could identify alone.

The real challenge: sharing without losing control

The two documents—the one from the Court of Auditors and the one approved by the European Parliament—point, from different perspectives, to the same problem: Europe needs a common situational awareness, but it still does not have a fully integrated system to build it.

The Court’s report identifies the practical deficit: information arriving late, incidents not communicated, different national criteria, and legal restrictions hindering data circulation. And the parliamentary resolution points to a more ambitious solution: strengthening European analysis capabilities and getting states to share more intelligence to detect hybrid campaigns and cross-border threats.

The difficulty will be in finding the balance. A Europe unable to share sufficient information may detect a threat too late; a Europe that shares sensitive information without establishing adequate controls may create new vulnerabilities.

Therefore, the next step should not be measured solely by the amount of information circulating among member states, but by the European capacity to classify it, protect it, share it selectively, cross-reference it, and quickly turn it into operational decisions.

The European Court of Auditors (ECA) has highlighted one of the main weaknesses in the European cybersecurity architecture: Europe increasingly has more networks, mechanisms, and resources to detect and respond to major cyber incidents, but member states still do not share information with the speed, breadth, and uniformity needed for this framework to function as a true European capability.

In its report ‘Detecting and responding to cybersecurity incidents,’ published this past September, the Court concludes that the measures adopted by the EU only partially facilitate the detection and response to significant and large-scale incidents. The main difficulties are the limited exchange of information, deficiencies in incident reporting, and delays in the implementation of some of the planned measures.

The problem is particularly relevant because a cyberattack on critical infrastructure can simultaneously affect several countries and sectors. However, the response still largely depends on national capabilities and decisions.

Information remains the weak point

The European framework already has specific mechanisms for sharing information. The NIS2 Directive consolidated the network of national incident response teams, the CSIRTs Network, and created EU-CyCLONe, the European network of liaison organizations for managing major cybersecurity crises.

On paper, both structures allow building a common picture of a threat and coordinating a response when an incident exceeds the capabilities of a single state. In practice, the Court of Auditors considers that this exchange remains insufficient.

One of the problems lies in the differences between national legislations and, in particular, in the limitations related to national security. When a state considers that certain information is classified or that its dissemination may compromise essential security interests, it may restrict its communication.

This is compounded by delays in the implementation of NIS2. The Court notes that only a portion of the states had timely fulfilled the obligations arising from the directive and that difficulties in determining when an incident has true cross-border repercussions also reduce the number of alerts that reach the entire Union.

The result is a paradox: threats do not respect borders, but the information necessary to combat them continues to be conditioned by legal, administrative, and security borders.

More information, but not for everyone

Here arises one of the most delicate issues for building true European intelligence. Increasing the exchange of information does not necessarily mean that all states, organizations, or authorities should have access to the same volume of data.

European legislation itself sets limits. The Cyber Solidarity Regulation, for example, states that the exchange of confidential information should be limited to that which is pertinent and proportional to the objective pursued, preserving confidentiality and security and defense interests. Additionally, it does not oblige the provision of information whose disclosure is contrary to the essential national security, public security, or defense interests of a member state.

This principle is especially relevant in a European scenario marked by the war in Ukraine and the activity of Russia and other state and non-state actors against European infrastructures and organizations. In July 2026, the EU Council once again denounced Russian cyber activities against member states and pointed out espionage and sabotage operations against governmental networks and critical infrastructures.

The question, therefore, is not only about getting states to share more information but about establishing what information can be shared, with whom, under what conditions, and with what guarantees that it will not end up in the hands of a hostile actor.

This particularly affects those member states whose geographical position, foreign relations, exposure to Russia, or dependence on certain infrastructures or providers may generate an additional risk of indirect access to sensitive information. It does not mean that it can be presumed that a member state will transfer information to Russia or another adversary: any restriction should be based on proven risks and objective security criteria. But it does pose the need to establish different levels of access and control mechanisms capable of reducing the risk of leaks or compromises.

At this point, the principle of need-to-know becomes especially important, meaning that access to sensitive information is determined based on specific operational needs and not simply by belonging to a particular organization or cooperation structure.

A European architecture with more capabilities, but still fragmented

The Court of Auditors considers that the EU has advanced in creating a common architecture but also warns of coordination problems among some of the existing structures.

The Union has allocated 1.4 billion euros from the 2021-2027 budget to cybersecurity within the Digital Europe program. However, some of the planned capabilities were not yet fully operational during the audit.

Among them is the European cybersecurity alert system, while delays have also been detected in projects aimed at improving cross-border detection. The Court also points out overlaps between certain threat monitoring capabilities of the Commission and ENISA.

The EU Cybersecurity Reserve is another instrument created to strengthen the response. Its objective is to provide assistance to member states in the event of serious incidents and subsequently facilitate recovery. The system allows part of the contracted services to be used for preparedness activities when they are not needed to respond to an incident, although the Court warns of the risk that this flexibility may end up shifting resources from response to preparation.

The ECA recommends, among other measures, that the Commission, with the support of ENISA, specifically analyze the restrictions derived from national security legislations that currently hinder information exchange. The goal would be to identify legal and technical solutions that allow increased cooperation without eliminating national safeguards. The expected horizon for this action is 2027.

The EU also wants to advance in intelligence against hybrid threats

The issue of information exchange is not limited to the strictly technical realm of cybersecurity. The European Parliament has placed shared intelligence at the center of its new approach to hybrid threats.

On September 16, the European Parliament approved by 470 votes in favor, 129 against, and 62 abstentions its resolution on hybrid warfare and the protection of the territorial integrity and critical security and defense infrastructures of the EU.

The text again calls for increased intelligence sharing among member states and the systematic incorporation of data and intelligence-based analysis into EU crisis planning and management. It also proposes that the Single Intelligence Analysis Capability (SIAC) be consolidated as the core of intelligence analysis capability within European institutions.

The resolution is also based on a realization: hybrid campaigns can combine cyberattacks, sabotage, espionage, disinformation, and other actions that, individually, may appear to be disconnected incidents but respond to the same operation.

The Parliament identifies Russia, directly or through proxies like Belarus, as the state actor representing the main hybrid threat to the EU, while also noting the growing role of China, Iran, and North Korea in enabling or amplifying certain hostile activities.

The debate anticipated by MEP José Cepeda

The debate on how far this information exchange should go directly connects with the interview we published in Digital Shield on September 28 with MEP José Cepeda, one of the negotiators of the hybrid warfare report approved by the Parliament.

Cepeda argued that “sharing more and better intelligence cannot be based on blind trust.” His approach aligns with one of the central issues now being raised again by the Court of Auditors: the need to increase information exchange without turning European cooperation into an indiscriminate transfer of sensitive information.

 

 

 

The MEP proposed that access should be adjusted to the role of each authority, the sensitivity of the data, and the existing risks, using the need-to-know principle and keeping classified national information protected. He also noted that when there is a proven risk that certain data could reach a hostile actor, access should be limited and safeguards reinforced.

The approval of the report by the European Parliament gives political backing to that approach: the EU needs a more integrated intelligence capability, but the path does not necessarily involve eliminating national controls, but rather ensuring that states can securely share the information necessary to detect patterns and threats that no country could identify alone.

The real challenge: sharing without losing control

The two documents—the one from the Court of Auditors and the one approved by the European Parliament—point, from different perspectives, to the same problem: Europe needs a common situational awareness, but it still does not have a fully integrated system to build it.

The Court’s report identifies the practical deficit: information arriving late, incidents not communicated, different national criteria, and legal restrictions hindering data circulation. And the parliamentary resolution points to a more ambitious solution: strengthening European analysis capabilities and getting states to share more intelligence to detect hybrid campaigns and cross-border threats.

The difficulty will be in finding the balance. A Europe unable to share sufficient information may detect a threat too late; a Europe that shares sensitive information without establishing adequate controls may create new vulnerabilities.

Therefore, the next step should not be measured solely by the amount of information circulating among member states, but by the European capacity to classify it, protect it, share it selectively, cross-reference it, and quickly turn it into operational decisions.


Source: www.escudodigital.com

About Us

Reportage Media Is a Global News Platform Covering the Latest Developments and Breaking Stories from Around The World, Including World News, Business, Finance, Technology, Health, Politics, Science, Entertainment, Sports, and More.

Reportage.Media  @2026. All Rights Reserved.