Estimated reading time: 8 minutes
ENISA published its 2026 Threat Landscape on 22 September. The press release leads with ransomware, geopolitics, and hacktivist DDoS campaigns against essential entities.
Page 13 of the report says something else. ENISA reports that operators in high-criticality NIS sectors describe DDoS as “noise.”
Anyone underwriting European cyber risk should start there.
What The ENISA Threat Landscape 2026 Says About Its Own Top Number
DDoS accounts for 51.3 percent of the 8,257 incidents ENISA analyzed. No other category comes close.
ENISA then separates frequency from impact. The agency writes that ideology-driven claims “did not result in large-scale or significant impact.” It adds that financially motivated activity remains “the most impactful threat to EU organizations” in the short term.
Ideology-driven incidents make up 57.3 percent of the dataset. Financially motivated incidents make up 29.2 percent. The smaller category carries the impact.
ENISA supports the point with its own NIS Investments 2025 research. Representatives of organizations in high-criticality sectors call DDoS noise. Ransomware dominates what they actually worry about.
Underwriters reached that conclusion years ago. An EU agency putting it in print still matters. National regulators and boards read these documents, and they set the questions that reach a broker.
The Intrusion Vector Figure Needs Its Denominator
One sentence on page 11 will travel further than it should.
“Across incidents of unauthorized access for which ENISA was able to identify an intrusion vector (5.2%), 60.4% were seen leveraging a vulnerability, while misconfiguration and accidental exposure remain a concern (20.7%).”
Work the arithmetic. Unauthorized access accounts for 39.5 percent of 8,257 incidents. That gives roughly 3,260 cases. ENISA identified the intrusion vector in 5.2 percent of them. Call it 170 incidents. The 60.4 percent applies to those 170 alone, which is about 103 cases.
Those 103 cases represent roughly 1.2 percent of the dataset. ENISA publishes percentages rather than counts, so the figures in this paragraph are a Cyber Insurance News calculation.
The sentence does not show that 60 percent of EU intrusions exploit a vulnerability. It shows that most diagnosable intrusions did.
That distinction carries weight. The identifiable slice is also likely biased toward vulnerabilities. Vulnerability exploitation leaves artifacts an investigator can name. It produces a CVE, a vendor advisory, and a patch history. Credential compromise can prove far harder to reconstruct.
That reading is analysis rather than an ENISA finding. The agency does warn at length that its open-source dataset carries reporting and granularity biases.
Claims data points the other way, as this publication has reported repeatedly through 2026. A carrier that builds a control questionnaire from this figure risks overweighting patch cadence. Credential hygiene would draw too little attention.
Get The Cyber Insurance News Podcast
Photos, MRIs, X-rays, contracts. Every business decision now rests on digital records, and anyone can alter them in seconds. DigiCert’s Mike Nelson explains how provenance technology tracks where a file came from and every change made to it.
ENISA Improved On Last Year, Quietly
The agency deserves credit here. ETL 2025 published no denominator for that figure.
That edition put phishing at about 60 percent of observed cases. Vulnerability exploitation took 21.3 percent and botnets 9.9 percent. Figure 1 carried the caption “Most identified initial infection vector.” The percentages summed to 100. The report never said how many incidents the sample covered.
ETL 2026 supplies the missing number. It supplies it inside a parenthesis, mid-sentence, where readers stop looking.
Three False Trends In The EU Cyber Threat Landscape
Anyone holding both editions will find comparisons that collapse under inspection.
Vulnerability exploitation appears to climb from 21.3 percent to 60.4 percent. The two figures rest on different bases. The 2025 number sits inside a five-way pie covering all intrusion vectors. The 2026 number covers unauthorized access incidents only, and only the 5.2 percent ENISA could diagnose.
Unauthorized access appears to leap from 0.4 percent to 39.5 percent. The categories do not line up. The 2025 edition classified “Intrusion” at 17.8 percent and “Unauthorized access” at 0.4 percent as separate incident types. The 2026 edition uses unauthorized access as its principal intrusion-related category.
Financially motivated activity appears to jump from 13.4 percent to 29.2 percent. ENISA expanded the cybercrime activities it tracks this year, adding data breaches and fraud. More tracking produces more recorded financial crime.
That expansion also shifts the denominator for every other category. It complicates the apparent fall in DDoS from 76.7 percent to 51.3 percent.
ENISA discloses all of this on page 9. The agency moved its reporting window to the calendar year, which leaves a six-month overlap with the previous edition. It states that the expansion “did not substantially change the trends and rankings.”
The rankings held. The share figures moved a long way.
ENISA adds one more warning worth quoting. Increased reporting of a threat “does not necessarily reflect an increased tempo of activity.”
What The ENISA Threat Landscape 2026 Gives Underwriters
Strip the noise out and useful material remains.
Ransomware claims concentrate in five member states. Germany accounts for 26.5 percent, France 14.7 percent, Italy 13.6 percent, Spain 12.2 percent, and the Netherlands 4.7 percent. Croatia, Estonia, Latvia, Bulgaria, Slovakia and Lithuania each sit below one percent.
That is a territorial exposure map. Few threat reports publish one.
The most active operators in the EU are Qilin, SafePay, Akira, INC Ransom, and Hunters International. Against the finance sector specifically, Akira leads with 20 percent of deployments.
ENISA also recorded more than 48,000 new CVEs during 2025. That marks a 22 percent rise on the previous year.
Insurance Appears In The Report As A Target
Page 35 carries a finding the general press will skip.
Insurance accounts for 17.8 percent of incidents across the EU finance and banking sector. Credit institutions take 61.9 percent. Crypto-asset service providers take 7.7 percent.
ENISA names cases. The cyberattack affecting Generali Tranquilidade exposed customer data. A separate breach reached former Liberty and BBVA Seguros customers through Generali España.
Hacktivists also aimed at public-facing banking and insurance portals. Ideology-driven activity made up 40.6 percent of incidents against the sector. DDoS accounted for 95.8 percent of that activity.
Get The Cyber Insurance News Upload
Subscribe to our weekly newsletter!
NIS2 Entities And The European Underwriting Frame
One number should shape European submissions.
ENISA reports that 73 percent of targeted organizations qualify as essential or important entities under NIS2. Public administration remains the most targeted sector at 32 percent. Ideology-driven DDoS accounts for 82 percent of what lands on it.
NIS2 status is turning into the European equivalent of a sector code. Carriers building EU books may find it sorts risk better than industry classification does.
One further figure carries a date worth watching. The European Banking Authority put online investment fraud at around EUR 4 billion in 2024. That estimate covers the European Economic Area. ENISA cites the 2024 figure in a report covering 2025.
Read the report. Then read page 13 twice.
FAQ – ENISA Threat Landscape 2026
What is the ENISA Threat Landscape 2026?
It is the EU cybersecurity agency’s annual threat report. This edition analyses 8,257 incidents recorded between 1 January and 31 December 2025, drawn from open sources and information shared by member states.
Why does the report describe DDoS as noise?
DDoS makes up 51.3 percent of recorded incidents. ENISA reports that ideology-driven claims, most of them DDoS, did not produce large-scale or significant impact. It cites its NIS Investments research, where operators in high-criticality sectors use the word noise. Ransomware dominates their stated concerns.
What does the 60.4 percent vulnerability figure cover?
It covers the cases where ENISA could identify an intrusion vector, which came to 5.2 percent of unauthorized access incidents. On that basis it represents roughly 1.2 percent of all recorded incidents.
Can the 2025 and 2026 editions be compared?
Not directly. ENISA changed its reporting window to the calendar year, leaving a six-month overlap. It also classifies incident types differently and has expanded the cybercrime activities it tracks. Several apparent year-on-year shifts reflect those changes.
Which EU countries see the most ransomware?
Germany at 26.5 percent of identified claims, then France at 14.7, Italy at 13.6, Spain at 12.2 and the Netherlands at 4.7. Six member states each sit below one percent.
What does the report say about insurance?
Insurance accounts for 17.8 percent of incidents in the EU finance and banking sector. ENISA names the Generali Tranquilidade attack and a breach affecting former Liberty and BBVA Seguros customers through Generali España.
Related Cyber Insurance Posts
- If Nobody Can Prove What Happened To A File, Somebody Still Pays For It
- AI Risk Speeds Up Cyber Insurance Pressure In BakerHostetler’s 2026 DSIR Report(Opens in a new browser tab)
- Tidal Cyber Secures Investments from USAA and Capital One Ventures to Support Growth(Opens in a new browser tab)
- EU Gives Itself Passing Grade, Barely, on Cybersecurity — New Report from European Union Agency for Cybersecurity (ENISA)(Opens in a new browser tab)
- Insurance Europe Urges Enhanced Resilience as EU Cyber Insurance Market Expands(Opens in a new browser tab)