The 60-second summary
On 22 September 2026, ENISA published its 2026 Threat Landscape, analysing events observed from 1 January through 31 December 2025. It reports that ransomware remains a high-impact threat, social engineering and vulnerability exploitation enable intrusions, supplier dependencies can amplify incidents, and AI supports malicious activity while creating new targets. The report is a threat assessment for planning, not a new law, mandate or incident deadline. Its figures reflect ENISA's observed dataset and should not be read as universal rates.
Timeline that matters
1 January–31 December 2025
Observation window
ENISA gathered and analysed reported events during the calendar year.
22 September 2026
Report released
ENISA published the 2026 Threat Landscape and an official summary.
25 September 2026
Editorial review
PrivacyBuilt checked the publication and source summary.
25 December 2026
Next review
Review major updates, corrections and subsequent official threat assessments.
What changed
ENISA's new annual assessment analyses 2025 incidents and places particular emphasis on interconnected digital services, supply-chain exposure, ransomware, social engineering, vulnerabilities and AI. It reports public administration as the most targeted sector by incident count in its dataset and cautions implicitly against assuming an incident count is the same as impact.
Who should pay attention?
Security and incident-response teams
Prioritise high-impact ransomware scenarios, detection and recovery testing.
Vendor-risk and procurement teams
Map critical service dependencies and request evidence of supplier resilience.
Cloud, identity and IT operations
Harden privileged access, patch exposure and monitor interconnected services.
Privacy and breach-response teams
Coordinate data-theft response, notification assessment and evidence preservation.
AI governance teams
Include AI-enabled abuse and AI system exposure in threat models.
What the guidance clarifies
- Time period
- The report was published 22 September 2026 and covers events observed during calendar year 2025.
- Ransomware
- ENISA describes ransomware as the most impactful short-term incident type; DDoS accounts for many recorded incidents but is often lower impact.
- Dependencies
- Third-party and supply-chain incidents can propagate through connected services and infrastructure.
- Intrusion vectors
- Social engineering and exploitation of known and unknown vulnerabilities remain prominent; ENISA could identify an initial vector for only a small subset of unauthorised-access incidents.
- AI
- Attackers increasingly use AI to support operations; deployed AI systems also enlarge organisations' attack surfaces.
- Legal status
- This is an analytical report, with no new statutory duty or deadline.
Dependencies can turn one supplier incident into many downstream incidents
Why this matters for global organisations
Connected services, privileged identities and shared infrastructure concentrate exposure. Teams should map critical dependencies, verify recovery paths, test breach coordination and prioritise controls using their own exposure and incident evidence.
- Map systems and suppliers whose failure would interrupt essential processes.
- Test identity, backup, restoration and communications under ransomware conditions.
- Track exploitable vulnerabilities and phishing pathways in real environments.
- Coordinate incident evidence and notification decisions across suppliers.
14 actions to start now
- Inventory essential services, data stores, identities and external dependencies with accountable owners.
- Rank suppliers and platforms by potential outage, data exposure and concentration risk.
- Map how a compromised supplier account, integration or update could reach sensitive systems.
- Require critical suppliers to document incident notification, containment and recovery commitments.
- Review privileged and service accounts, enforce strong authentication and minimise standing access.
- Patch internet-facing and high-exposure assets based on exploitability and business impact.
- Harden email and browser workflows against phishing, credential theft and ClickFix-style social engineering.
- Segment systems and constrain east-west movement and remote administrative access.
- Monitor suspicious access, supplier connections, data movement and ransomware precursors.
- Keep recoverable, protected backups and measure restoration time in realistic exercises.
- Run a tabletop in which a supplier compromise causes simultaneous service outage and personal-data theft.
- Agree evidence preservation, privacy breach assessment and regulator/customer communication responsibilities.
- Update AI threat models for malicious use of AI and attacks on deployed AI services.
- Record residual risks, exceptions, owners and dates for retesting controls.
Suggested next steps
- Run one joint exercise involving a critical supplier, a ransomware outage and possible personal-data theft; record time to detection, containment, restoration and notification decisions.
Evidence worth retaining
- Critical service, data-flow and dependency inventory with owners.
- Supplier contracts, assurance reports, subprocessor and incident contacts.
- Identity access reviews and privileged session logs.
- Vulnerability inventory, exposure ratings, remediation and exception records.
- Phishing and endpoint detection tests with measured outcomes.
- Network segmentation and integration trust diagrams.
- Backup integrity, restore tests and recovery objectives.
- Monitoring rules, alerts, investigation records and retention settings.
- Supplier incident playbooks, tabletop outcomes and notification timelines.
- Data theft and privacy impact assessments, communication approvals and remediation tracking.
Questions to take to counsel or your conformity team
These are discussion prompts, not legal advice or conclusions.
- Which third party failure would disrupt several essential services at once?
- What access do suppliers retain after support work finishes?
- Can we detect and isolate a compromised integration without losing all operations?
- How quickly can we restore trustworthy services and confirm data integrity?
- Do contracts provide timely incident facts and usable forensic evidence?
- Which data exposures could trigger notification duties in the jurisdictions that apply?
- Are AI systems both a misuse vector and a target in our threat model?
- Are our risk priorities based on our own exposure rather than general incident statistics?
Official sources
- ENISA — Threat Landscape 2026, 22 September 2026
- ENISA — Official threat landscape announcement, 22 September 2026
PrivacyBuilt / PrivacyBuilt is an independent educational publisher. It is not affiliated with, or endorsed by, any regulator or the European Union.
PrivacyBuilt publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation.