Skip to content
Skip to content
CYBERSECURITY

The cyber threat landscape in ENISA's 2026 report: the loud attacks are not the costly ones

Summarise with

Half of what ENISA recorded in 2025 was DDoS, and the organisations it surveyed call that noise. The buyer your security brand is courting reads the same report, so the message has to follow the damage rather than the din.

Quick answerENISA's cyber threat landscape for 2026 recorded 8,257 incidents, 51.3 per cent of them DDoS. Ransomware, unpatched flaws and supplier compromise did the real damage, so security marketing should lead with harm, not volume.
Section 01

What the cyber threat landscape report actually counted#

The fox listens for the quiet step beneath the loud one, and reads every rustle in the hedgerow twice. That habit suits ENISA's Threat Landscape 2026, published on 22 September, because it reads like a report written by someone who has heard a great deal of noise and learned to ignore most of it. The EU agency's cyber threat landscape covers incidents from 1 January to 31 December 2025, drawn from open sources and from anonymised information shared by member states, as its press release explains.

The headline split is stark. In the full ENISA report, DDoS attacks make up 51.3 per cent of what was recorded and unauthorised access 39.5 per cent. Motive tells the same story of volume without weight: threats targeting or affecting the EU were ideology-driven in 57 per cent of incidents, while almost 30 per cent were financially motivated.

Half the record is DDoS
Waffle chart: DDoS attacks were 51.3 percent of the 8,257 incidents ENISA recorded in 2025 for the EU cyber threat landscape51.3% of the 8,257 incidents in ENISA's 2026report were DDoS attacks
Waffle chart: DDoS attacks were 51.3 percent of the 8,257 incidents ENISA recorded in 2025 for the EU cyber threat landscape
ItemValue
51.3% of the 8,257 incidents in ENISA's 202651.3% of the 8,257 incidents in ENISA's 2026
report were DDoS attacksreport were DDoS attacks
DDoS accounted for 51.3 per cent of the incidents ENISA recorded in 2025, and the organisations it surveyed describe it as noise rather than harm.

Now the sentence that matters most to anyone selling security. ENISA notes that representatives of EU organisations in high-criticality NIS sectors characterise DDoS as noise, while ransomware dominates their concerns. The finding rests on a survey published separately, ENISA's NIS Investments 2025, whose sample was mainly large enterprises (83 per cent) with a smaller share of SMEs (17 per cent). So it is a view from the big end of the market, and honest copy says so.

Two cautions keep the reading honest. First, a count of recorded incidents is a count of what was visible in open sources and shared by states, not a census of everything that happened. Second, ENISA itself calls ransomware the most impactful incident type in the short term, a reminder that frequency is not impact, and Digital Watch's summary notes the report's central message is the convergence and scaling of existing threats rather than anything brand new.

  • 8,257

    incidents analysed for the 2025 window

  • 51.3%

    of them DDoS attacks

  • 39.5%

    unauthorised access

  • 4,709

    hacktivist claims against EU states

  • 73%

    of targeted organisations were NIS2 essential or important entities

Those last two figures deserve a moment. The press release counts 4,709 claims against EU member states, more than 89 per cent of them DDoS, which is why hacktivist attacks fill the headlines without filling the loss column. And because 73 per cent of targeted organisations are essential or important entities under NIS2, the people reading the report are exactly the regulated buyers a security vendor wants to reach.

Section 02

Where the damage really sits: ransomware, flaws and suppliers#

If DDoS is the moth at the lantern, the harm hides in the undergrowth behind it. In this cyber threat landscape, ENISA lists ransomware as the most impactful incident type in the short term, and cybercrime overall covered 36 per cent of total events. Anyone tracking ransomware trends will notice that the report describes persistence, not novelty, with extortion, data theft and encryption layered on the same old routes in.

Those routes matter more than the labels. Across the unauthorised-access incidents where ENISA could identify an intrusion vector, which was only 5.2 per cent of them, 60.4 per cent were seen leveraging a vulnerability, and 20.7 per cent involved misconfiguration or accidental exposure. That is a small subset, so nobody should read it as 60 per cent of all break-ins. It still points one way, and 2025 also saw more than 48,000 new vulnerabilities published, 22 per cent more than the year before.

Who ENISA saw targeted
Public administration
31.8%
Business services
8.5%
Transport
8%
Manufacturing
6.9%
Finance and banking
5.6%
Public administration took 31.8 per cent of recorded incidents, nearly four times the next sector, though a count of incidents is not a measure of impact.

The independent evidence agrees. Verizon's 2026 Data Breach Investigations Report says nearly a third of breaches, 31 per cent, start with vulnerability exploitation, the first time in 19 years that it has passed stolen credentials as the biggest point of entry. Its sample is large: 31,000 incidents, more than 22,000 of them confirmed breaches.

The supplier is part of your attack surface#

ENISA's headline is dependency. The report says the targeting of cyber dependencies, including supply-chain and third-party attacks, continued to be observed, with several large-scale and impactful incidents. Verizon puts a number on it: third-party involvement in breaches reached 48 per cent, up from 30 per cent last year, a 60 per cent relative rise.

Breaches that involve a third party
Breaches that involve a third partyDumbbell chart: third-party involvement in breaches rose from 30 percent in the 2025 Verizon report to 48 percent in the 2026 report2025 report2026 reportThird-party breaches: 30 to 48Third-party breaches48%
Dumbbell chart: third-party involvement in breaches rose from 30 percent in the 2025 Verizon report to 48 percent in the 2026 report
ItemValue
Third-party breaches30 to 48
Third-party involvement in breaches rose from 30 per cent in Verizon's previous report to 48 per cent, a 60 per cent relative rise after already doubling the year before.

Read the two reports side by side and the pattern in the cyber threat landscape is plain. ENISA counts recorded events across the EU, Verizon counts confirmed breaches globally, and they measure different things. They agree only on direction: flaws left unpatched and suppliers left unwatched carry the cost, while volume attacks carry the headlines.

Section 03

One flaw, two months: how a supplier bug becomes ransomware#

A single recent case shows how the damage curve unfolds across the cyber threat landscape. JetBrains disclosed a critical authentication bypass in TeamCity, a build server many software suppliers run, on 27 July. Its follow-up update says that since the announcement it had received reports of active exploitation, as well as attempted exploitation, against unpatched servers.

CISA listed the flaw, CVE-2026-63077, in its Known Exploited Vulnerabilities catalogue on 5 August. On Wednesday 23 September it updated the entry again, flagging the bug as abused by ransomware gangs, as BleepingComputer reported. Note the wording: this was an update to an existing entry, not a new addition, and CISA had not shared details of the attacks.

Days from disclosure to each official escalation
Days from disclosure to each official escalationBar chart of days after the 27 July disclosure of TeamCity flaw CVE-2026-63077: CISA listing at 9 days and ransomware flag at 58 daysCISA listing: 9Ransomware flag: 5860402009CISA listing58Ransomware flag
Bar chart of days after the 27 July disclosure of TeamCity flaw CVE-2026-63077: CISA listing at 9 days and ransomware flag at 58 days
ItemValue
CISA listing9
Ransomware flag58
From JetBrains' 27 July announcement, CISA's listing arrived at 9 days and its ransomware flag at 58 days, so the loud part of a flaw's life is over long before the costly part begins.

The two bars use CISA's own listing date and the date BleepingComputer reports for the ransomware flag, counted from JetBrains' 27 July announcement. The arithmetic makes the marketing point: a supplier flaw does not stay news for a week. It becomes a customer's incident report eight weeks later, down a trail the vendor could have marked, which is exactly the moment a buyer decides whether they trust the vendor who warned them.

For folkfox's earlier reading of how a vendor's own flaw reshapes its marketing, see the Check Point zero-day piece, and for the software supplier angle, the Brevo supply chain attack.

Section 04

What a security brand should say when the buyer has read the report#

Regulated buyers who study the cyber threat landscape are not naive. They have read the agency report, they know the clocks, and they will test a vendor's claim against it. Under NIS2, an essential or important entity must submit an early warning within 24 hours of becoming aware of a significant incident, and an incident notification within 72 hours. Under the Cyber Resilience Act, manufacturers must submit an early warning within 24 hours of becoming aware and a full notification within 72 hours.

So a vendor's copy is judged against two questions. Does it describe the harm the buyer actually fears, and does it help them meet the clock they actually face? A page that boasts of blocking billions of attacks answers neither. A page that explains how a customer moves from a flaw in a supplier's software to a notified, contained incident within seventy-two hours answers both.

Five lessons for cybersecurity marketing
Lead with harm, not volume

Open with ransomware, exploited flaws and supplier compromise, the threats ENISA and Verizon both put on the damage curve, and give DDoS its proper small place.

Show your working

Name the dataset, the sample and the year beside every statistic, and never blend numbers from reports that count different things.

Write to the clock

Explain how your service helps a customer meet the NIS2 and Cyber Resilience Act reporting clocks, with the hours stated plainly.

Own your own supply chain

Buyers now ask how a vendor handles its own suppliers, so publish that answer before they have to ask.

Keep the flaw timeline honest

When a flaw touches your product, publish disclosure, fix and exploitation dates in one place, the way the TeamCity record shows they matter.

The second lesson deserves its own table, because cybersecurity statistics travel badly through a thicket of near-identical claims. The three most quoted datasets this month count different things, and a careless brochure that stitches them together will be caught by the first analyst who reads it.

  • ENISA Threat Landscape 2026

    Recorded EU incidents, 2025

    Counts
    8,257 open-source and member state events
    Strength
    EU scope, sector split

    Best for

    • Regulated EU buyers
    • Threat-mix context
  • Verizon DBIR 2026

    Confirmed breaches, global

    Counts
    31,000 incidents, 22,000+ breaches
    Strength
    Entry points, third parties

    Best for

    • Vulnerability and supplier claims
  • FBI IC3 2025

    US victim complaints

    Counts
    1,008,597 complaints, $20.877bn
    Strength
    Reported losses

    Best for

    • Fraud and loss framing, US only

The FBI figure is a good example of a number that is easy to misuse. The 2025 IC3 report counts 1,008,597 complaints and $20.877 billion in losses, a 26 per cent rise on 2024. It is real, and it is self-reported American complaint data, so it says nothing about the EU incident mix and should never sit beside ENISA's count as if the two were one series.

Section 05

How to write a threat page a buyer will cite#

A cyber threat landscape page is among the most linked assets a security brand owns, and among the most careless. Begin with a patient prowl through the report's method pages. The fox does not leave a scent it cannot defend. A page that a buyer, a journalist or an answer engine will quote needs self-contained sentences, sourced numbers and a stated method.

@2eubrussels
But ENISA says ransomware and supplier compromises can have much wider impact.
25 September 2026View on X

That post, from a Brussels-based account summarising the report, is a fair distillation of the damage curve. It also shows how a good sentence travels: short, attributed and self-contained. That is the register a threat page should aim for.

A watercolour fox listening at a dark doorway with an ear trumpet, a picture of the cyber threat landscape and its loud and quiet dangers
The loud moth is not the one that gets in.

Start with the headline a buyer will search for, and answer it in the first forty words. Then give the number, the dataset and the year, and link the number to the regulator's own page. If the report is inconsistent with itself, as parts of ENISA's PDF are on the exact financial-motive share, say almost 30 per cent and move on. Precision you cannot defend is worse than a rounded truth, and a cyber threat landscape summary should never outrun its source.

For teams that want this rhythm built rather than described, folkfox's cybersecurity marketing work pairs regulator-grade sourcing with content marketing that reads like evidence, and SEO and GEO that keeps a threat page findable when a buyer asks a question of an answer engine. The Cyber Resilience Act reporting clock piece shows the same discipline applied to a single deadline.

One more caution for any cyber threat landscape brief. ENISA's report covers 2025, not the present month, and cybersecurity statistics age quickly. Date every figure in the prose, not only in a footnote, and re-check it whenever the next report lands. A page that says what was measured and when will outlive one that claims to describe now.

DDoS is what happened most often. Ransomware and unpatched flaws are what hurt most. Write for the buyer who can tell the difference.
folkfox, on the ENISA cyber threat landscape
Questions

Frequently asked questions#

What is the ENISA cyber threat landscape 2026?

It is the EU cybersecurity agency's annual assessment of incidents observed from 1 January to 31 December 2025. It analysed 8,257 incidents drawn from open sources and information shared by member states, and highlights ransomware, vulnerability exploitation and dependencies on suppliers.

What do the latest cybersecurity statistics say about DDoS?

ENISA recorded DDoS attacks as 51.3 per cent of the incidents in its 2026 report, yet organisations in high-criticality sectors describe DDoS as noise and say ransomware dominates their concerns. Volume and impact are different measures.

Are DDoS attack statistics a good measure of risk?

Not on their own. Counts of DDoS attack statistics show how often a service was disrupted, not how much harm followed. ENISA's own survey evidence says large organisations weigh ransomware more heavily than DDoS when they judge risk.

What are the main ransomware trends in the EU?

ENISA calls ransomware the most impactful incident type in the short term. The wider pattern is persistence and convergence, with extortion and data theft layered on familiar routes in, including unpatched vulnerabilities and compromised suppliers.

Why do hacktivist attacks matter to buyers?

ENISA counted 4,709 hacktivist claims against EU member states, more than 89 per cent of them DDoS. They rarely cause deep damage but they generate headlines and disrupt public services, which is why regulated buyers still ask vendors about them.

How should a security vendor cite threat data?

Name the dataset, the sample and the year beside every figure, link to the primary report, and never blend numbers from reports that count different things. ENISA counts recorded EU events, Verizon counts confirmed global breaches, and the FBI counts US complaints.

Keep reading

Read more on this topic#

Ready to market security the way buyers actually read it?

folkfox builds regulator-grade, evidence-first content for security vendors: pages that name the dataset, follow the damage curve and survive an analyst's read.

Want folkfox in your Google results and AI answers? Set folkfox as a preferred source.

The den

Where to?

Pricing

Choose a section. Enter opens it, Escape continues reading.

Cookie preferences

folkfox uses data the way we use strategy: only when it earns its place.