Summary
- ENISA found that 73% of organisations targeted in its 2025 dataset were entities classed as essential or important under NIS2.
- Supply-chain and third-party compromises can turn individual breaches into wider operational disruption across connected organisations.
- AI is appearing both as an attack tool and as another enterprise system requiring security controls.
ENISA has put technological dependency at the centre of its latest assessment of Europe’s cyber threat landscape, finding that shared infrastructure, suppliers, software, and services are allowing individual attacks to spread across a much larger operational surface.
The EU cybersecurity agency’s 2026 Threat Landscape analyses events observed between January and December 2025, combining open-source reporting with anonymised information from member states and its Cyber Partnership Programme. Although ransomware, distributed denial-of-service attacks, and vulnerability exploitation remain prominent, the findings describe a security environment in which the connections between organisations increasingly determine how far an incident can travel.
Some 73% of organisations targeted in the dataset were classed as essential or important entities under the NIS2 framework. Public administration accounted for 32% of targets, followed by business services and transport at 8% each, manufacturing at 7%, and finance and banking at 6%.
Low-impact DDoS activity represented 51% of recorded incidents, much of it linked to geopolitical developments, while ransomware remained the category ENISA considers most immediately damaging. More than 48,000 new CVE identifiers were also published during 2025, a rise of 22% from the previous year.
Dependencies multiply operational exposure
Attackers are continuing to target supply chains and third parties where one compromise can provide access to several organisations. Businesses have spent years consolidating infrastructure around cloud platforms, managed services, shared software, and specialist suppliers, gaining efficiency while creating dependencies that attackers can exploit as well.
That dependence has become a central concern for European cyber regulation. NIS2 extends security and reporting obligations across a wider group of critical and important sectors, while the Digital Operational Resilience Act has pushed financial organisations to examine technology suppliers and concentration risk more closely. Compliance measures do not remove the architecture underneath them: organisations still depend on long chains of software, infrastructure, and service providers that may sit outside their direct operational control.
Recent Techopia coverage has shown the same shift in Europe’s preparedness work, with ENISA placing more emphasis on system-level resilience rather than treating cyber defence as a collection of isolated controls.
Threat categories are also becoming harder to separate cleanly. ENISA found similar tools, infrastructure, and access mechanisms appearing across cybercrime, hacktivist, and state-linked activity, even where the groups involved had different objectives.
AI expands both sides of the attack surface
Artificial intelligence is adding another layer to that convergence because threat actors are using it to support malicious operations while organisations are embedding the same technology deeper into their own systems. Synthetic audio and video, automated text generation, translation, and information manipulation can reduce the cost of preparing persuasive campaigns across several languages and jurisdictions.
AI systems themselves are also becoming assets that need protecting. As organisations connect models and agents to corporate data, applications, and workflows, those systems acquire permissions and access paths that can become valuable to an attacker.
Agentic systems complicate security architecture because conventional controls were largely built around identifiable users, applications, and network assets. An agent may operate on behalf of a user while authenticating through machine credentials, reaching several services and generating actions dynamically, leaving security teams to establish whether an apparently legitimate action still falls within its intended role.
Vulnerability exploitation remains an important route into those environments. In the subset of unauthorised-access incidents where ENISA could identify the intrusion vector, exploitation of a vulnerability accounted for the majority of cases.
Resilience becomes an architectural question
Controls around individual systems can only go so far when operational resilience depends on infrastructure crossing organisational boundaries. Procurement choices, cloud concentration, software dependencies, identity architecture, and supplier access now sit inside the same risk calculation as endpoint protection or incident response.
Organisations consequently need a better picture of where critical dependencies actually sit, including providers that may not look critical until a failure propagates through several layers of service. That mapping becomes difficult when subcontractors, software components, and managed services sit several steps away from the business buying the final product.
AI deployment, cloud consolidation, and outsourcing can each improve productivity or reduce internal complexity while also changing the route an attacker can take through the organisation. European regulation is steadily forcing more of those relationships into view, but inventories and compliance exercises are useful only if they translate into an operational understanding of what happens when a dependency fails.
The next serious disruption may begin outside the systems an organisation directly owns, which makes resilience increasingly dependent on how technology estates fit together rather than how well each individual component is defended in isolation.












