The 2026 edition of the ENISA Threat Landscape was published on 22 September, built on the analysis of 8,257 incidents observed between 1 January and 31 December 2025. One figure in it is the one that will travel: 73 per cent of the malicious events recorded involve entities that would be classified as essential or important under NIS2.
That number is built to be misread, so let us fix its meaning before someone puts it on a sales deck.
What the 73 per cent does not say
It does not say that 73 per cent of European NIS2 entities suffered an incident. It says how heavily the sectors covered by the directive feature inside the threat landscape ENISA observed. Those are different statements, and only one of them is supported.
The distinction matters because the misreading is commercially useful. A loss rate justifies a purchase order. A measure of sectoral exposure only justifies thinking, and nobody has ever hit a quarterly target selling that. Expect the first version anyway, in a slide, in bold, with an exclamation mark.
A report that changes no obligation at all
The report modifies no duty, no deadline and no measure set out in NIS2 or in national implementing law. Anyone announcing new requirements on the strength of it is selling something.
Its value lies somewhere far less marketable: it provides an updated picture of the threats, and that picture is supposed to enter risk assessments and, above all, their periodic reviews. This is where the whole exercise is most likely to collapse quietly.
A risk analysis built on a superseded threat scenario is formally correct and operationally useless. It may well survive an inspection, because inspections read documents. It also describes a world that no longer exists, which is a remarkable thing to base a defence on. The failure mode is easy to picture: the document ages in an archive and reappears at the next review with a new date on the cover and the same content underneath, because updating it properly would mean admitting that last year’s version was already wrong.
Suppliers are not a questionnaire
The report insists on the point that dependencies amplify the effects of an incident. This is not a discovery. It is a description of the job.
Consider what supplier management looks like when it is reduced to an annual questionnaire, a shape anyone who has worked near a procurement function will recognise. It goes out by email, the supplier answers yes to everything, the answers are filed, an auditor ticks a box, and at no point does anyone establish which dependencies actually carry the service. In that arrangement, a critical process can run through a subcontractor that appears on no map, and the day it stops is also the day the organisation finds out. That is not a prophecy. It is what the absence of governance looks like from the inside.
Governing suppliers is risk governance. It means knowing what you depend on, what happens when that dependency stops, who else depends on the same thing, and what you are contractually able to demand when it fails. It costs technical competence, internal conflict and the willingness to tell a business unit that its favourite vendor is a single point of failure.
Documentary compliance costs a form. The market has noticed which of the two is easier to sell, and has organised itself accordingly.
The periodic review is the whole point
If there is one operational instruction to take from the report, it is not a new control. It is the obligation, already in force, to keep the threat scenario current inside the risk assessment.
A review is not a reprint. It means asking whether the scenarios underpinning last year’s decisions still hold, whether the dependency map has changed, whether something that was residual risk has become the most probable event. Answering honestly sometimes requires saying that a measure approved with great ceremony is now ineffective, which is precisely why the honest answer is so rare.
The 73 per cent will be quoted for months. The sentence that should be quoted instead is duller and considerably more inconvenient: an assessment that is formally correct and operationally useless is not compliance, it is a document written to survive an audit rather than an attack.
Raffaele Di Marzio
All my “insane” books on cybersecurity and governance are here 👇 https://cyberium.limited/bookshelf.html
