ENISA: 73% of targeted organisations were in NIS2 sectors—what businesses should learn
ENISA Threat Landscape 2026 examines ransomware, DDoS, vulnerabilities and supplier dependencies. We translate its findings into board-level decisions.
- AUTHOR
- Karol Rapacz / CEO Breachroad · OSCP · PNPT
- PUBLISHED
- 2 October 2026
- READING TIME
- 10 min read
- TOPIC
- Threats and Incidents
Of the organisations targeted in incidents analysed by ENISA, 73% belonged to categories considered essential or important entities under NIS2. Public administration accounted for 32% of targets, followed by business services and transport at 8% each, manufacturing at 7%, and finance and banking at 6%. These figures show where risk was concentrated; they do not mean that three quarters of all European organisations covered by NIS2 were successfully compromised.
The ENISA Threat Landscape 2026 examines incidents and events observed from January to December 2025. Its evidence combines open-source reporting, anonymised information from EU Member States and ENISA’s partnership programme. It is a view of reported and collected events, not a complete census of every attack in Europe.
Ransomware still has the greatest short-term impact
ENISA identifies ransomware as the incident type with the greatest short-term impact. Operators combined encryption, data theft and extortion. Among recorded financially motivated activity, ransomware deployment accounted for 40%, data breaches for 31%, and fraud and impersonation for 19%.
For a board, the more useful question goes beyond encryption: what is the minimum operation the organisation must sustain? Can it process orders, serve customers, pay employees and communicate without its primary system? Backups are essential, but they do not replace recovery priorities, protected emergency accounts, alternative communications and a rehearsed decision about shutting down a service.
Ransomware does not begin when the ransom note appears. Before that point, an attacker may compromise an identity, exploit a vulnerability, enter through a supplier or use phishing. Defence therefore requires people, identity, patching, segmentation and monitoring to work together; it cannot be reduced to buying a single product labelled “anti-ransomware”.
DDoS dominates the event count, but frequency is not impact
DDoS attacks represented 51% of recorded cases and were mostly low-impact events. Ideological motives accounted for 57% of all incidents, while almost 30% were financially motivated. Of 4,709 claimed hacktivist actions, more than 89% involved DDoS.
Public administration was especially prominent because 82% of events in that sector were ideologically motivated DDoS attacks. That does not mean DDoS is the only risk facing public bodies, nor that every disruption signals a serious data breach.
The practical lesson is to measure harm to the service, not just the number of alerts. Organisations need rate limiting and edge protection, external availability monitoring, an established contact with their provider, and a customer-communications procedure. At the same time, a noisy DDoS event must not distract the team from a quieter compromise of an account or data.
Vulnerabilities and dependencies expand a shared attack surface
More than 48,000 new CVE identifiers were published in 2025, a 22% increase over the previous year. ENISA also reports that in unauthorised-access cases where an initial vector could be identified—and this was only 5% of such incidents—60% involved exploitation of a vulnerability. The small size of the subset with a known vector is an essential caveat: the 60% figure cannot simply be applied to all intrusions.
The report highlights attacks involving supply chains and third parties. A shared platform, managed service provider or software library can spread the impact across many organisations. A company needs a dependency map: which services are critical, who has access, where data is held, how the supplier reports incidents and what the exit path looks like.
It is not possible to remediate 48,000 CVEs with the same priority. Exposure, active exploitation, asset importance, compensating controls and the potential for impact to spread all matter. Boards should see the time taken to reduce risk in critical systems, not merely a total count of open vulnerabilities.
AI helps attackers and creates new assets to protect
ENISA notes growing use of AI to generate text, images and audio, translate content and scale distribution. At the same time, integrating AI systems into business processes expands the attack surface through new data, integrations, models, agents and suppliers.
This does not make every campaign an autonomous AI attack. In most cases, AI increases the speed, reach and plausibility of established methods. Organisations should strengthen the fundamentals—payment verification, account protection, data controls and secure deployment of tools—instead of waiting for a separate category called an “AI incident”.
The report’s findings can be turned into three exercises: a day without a core service, compromise of a supplier’s account, and a convincing impersonation of an executive. Cybersecurity training prepares employees for the third scenario, tabletop exercises connect business and technical decisions, and third-party risk management helps reduce exposure to dependencies.
Source facts and Breachroad’s conclusions
The ENISA Threat Landscape 2026 report covers January through December 2025. ENISA’s summary of the findings provides the sector shares, motivations, significance of ransomware, DDoS, vulnerabilities, supply chains and AI, and describes the data sources.
The proposed metrics, board questions and three exercise scenarios are Breachroad’s conclusions. The report describes an observed collection of events, so its figures should not be treated as the precise probability of an attack against any individual organisation.


