Security / WORLD

ENISA publishes its 2026 assessment of Europe’s cyber threat landscape

In its review of 2025 incidents, ENISA said public administration accounted for 32% of targeted organisations and low-impact DDoS attacks for 51% of recorded cases.

Reading sizeSources ↓Share story ↗

ENISA published its European Threat Landscape report on 22 September 2026, reviewing events observed from 1 January through 31 December 2025. The agency said it used open sources, anonymised information shared by EU member states and data from its Cyber Partnership Programme. It described ransomware as the most impactful short-term incident type.

The report said 73% of targeted organisations were essential or important entities under the NIS2 definition, while public administration was the most targeted sector at 32% of cases. Low-impact DDoS attacks made up 51% of recorded incidents. These figures describe ENISA’s 2025 reporting set and are not a forecast.

Data

Timeline

Security development

Security event or institutional action reported by the source.

  1. · Occurred

    ENISA published its 2026 Threat Landscape

    The report assessed events observed during 2025; public administration accounted for 32% of targeted organisations, while 51% of recorded incidents were low-impact DDoS attacks.

Methodology

The event date and description summarise the action reported by the source; no additional measurement or forecast is made.

Updated:

Key figures

Measure reported by the source

Key quantitative figure stated by the source.

Share of analysed events classified as cybercrime
36 percent
2025 · Observed
Methodology

Value is reproduced as stated by the source; a qualifier marks an approximate or bounded figure.

Updated:

Structured coverage

Subjects and places

Subject proposals

Taxonomy version: IPTC Media Topics 2026-Q2

Continue reading

Security

ENISA launches EU Cyber Resilience Act reporting platform

The initial capability of a single EU platform for manufacturers to report actively exploited vulnerabilities and severe incidents went live on 11 September.

European Union Agency for Cybersecurity (ENISA)1 min read
Data included