Shane Barney Keeper Security Chief Information Security Officer
EU auditors want real-time incident sharing between member states. Keeper Security’s CISO Shane Barney says the first bottleneck is detection inside organisations.

European countries are failing to share information about large-scale cybersecurity incidents with other European Union (EU) members, which weakens Europe’s ability to fend off cyberattacks. The European Court of Auditors recommends that the bloc give priority to its long-planned European cyber alert system, so that member states can exchange incidents and attack information in real time without endangering their national security.

Shane Barney, Chief Information Security Officer (CISO) at Keeper Security, has commented on the auditors’ findings. In his view, they overlook a critical shortcoming in the EU’s existing cybersecurity capabilities: the information-sharing gap begins inside organisations, not between them.

The planned alert platform is meant to help overcome legal restrictions, national security concerns, differing national approaches and delays in implementing EU rules, and to shorten the time member states need to report cyber incidents overall. Yet a platform of the kind the auditors propose can only work as quickly as the organisations that feed it with data. According to Barney, that is where the problem lies: a large share of companies currently cannot report anything because they cannot tell what has happened.

The tension the platform must resolve is a familiar one. Cyberattacks do not stop at national borders, and a campaign that hits a company in one member state can reach organisations in others within hours. Yet governments are reluctant to hand over incident details that touch on national security, and national reporting practices differ. The auditors’ recommendation is aimed at building a channel that works despite these frictions.

A 2026 study by Keeper Security points in the same direction. According to the company, only 24 percent of German organisations notice the misuse of credentials or unauthorised privileged access within minutes. For the rest, it takes hours, days or longer, and some do not know how long detection takes at all. Privileged accounts, such as administrator logins, grant broad control over systems, which makes their misuse both damaging and difficult to spot without close monitoring.

The reporting obligations raise the stakes. Under the NIS2 directive, more than 100,000 companies across Europe must report serious incidents to national authorities within 72 hours. Barney argues that the ability to detect an incident is the bottleneck, well before a report can be written and incident data passed on.

Real-time correlation between member states is a reasonable and desirable goal, Barney says. But if detection speeds within individual organisations remain where they are today, he expects the goal to prove unattainable. The EU auditors have called for indicators of compromise to be identified and shared in real time. According to Barney, this can only start inside companies, with transparency about who or what accesses privileged systems, and when. Without that transparency, the infrastructure built to exchange information between states after an incident will be of limited practical use.

In practical terms, this means knowing which accounts hold elevated rights, recording what they do, and being able to flag unusual activity quickly enough to meet a 72-hour window. That visibility is also what produces the indicators of compromise the auditors want shared: without an internal record of what happened, there is little to pass on.

The task is becoming harder rather than easier. As AI agents and other non-human identities multiply, the number of accounts that can reach sensitive systems grows, and so does the difficulty of attributing an action to a specific identity. Keeper Security says its platform is designed to govern access for humans, machines, non-human identities and AI agents alike. Whether such tooling closes the detection gap will depend on how widely organisations deploy it.

For IT decision-makers, the argument shifts the focus from Brussels to their own environments. Before national authorities and their EU counterparts can compare notes, individual organisations need to know which identities, human or machine, touch their most sensitive systems. Readers should note that Keeper Security markets privileged access management, so the commentary reflects a vendor’s perspective. The underlying point about detection times, however, follows directly from the reporting deadlines that NIS2 already sets.

The Court’s recommendation and Barney’s critique are not mutually exclusive. A functioning alert system remains necessary, but the two points address different links in the same chain: detection inside organisations, reporting to national authorities, and exchange between member states. A weakness at the first link limits the value of the others.

Keeper Security describes itself as a provider of zero-trust and zero-knowledge identity security. Its KeeperPAM platform combines password and passkey management, secrets management, privileged session management and endpoint privilege management, and its KeeperAI offering adds AI-based threat detection for privileged sessions, according to the company.

By Jakob Jung

Dr. Jakob Jung is Editor-in-Chief of Security Storage and Channel Germany. He has been working in IT journalism for more than 20 years. His career includes Computer Reseller News, Heise Resale, Informationweek, Techtarget (storage and data center) and ChannelBiz. He also freelances for numerous IT publications, including Computerwoche, Channelpartner, IT-Business, Storage-Insider and ZDnet. His main topics are channel, storage, security, data center, ERP and CRM. Contact via Mail: jakob.jung@security-storage-und-channel-germany.de

Leave a Reply

Your email address will not be published. Required fields are marked *

WordPress Cookie Notice by Real Cookie Banner