Threat guide

Threat guide · 8 min

ENISA Threat Landscape 2026: what it means for supplier risk

ENISA published its Threat Landscape 2026 on 22 September 2026, covering all of 2025. The number every headline will quote is that DDoS accounts for 51.3% of recorded incidents — but ENISA itself calls those low-impact, and the organisations it surveyed in NIS sectors call them noise. The 29.2% that is financially motivated is what actually stops operations, and ENISA names the targeting of third-party providers and supply chains as a source of large-scale incidents. This guide separates the noise from the risk you are accountable for.

Check your domain now

See what's publicly visible about your organisation's security, no sign-up.

This instant preview checks:

  • HTTPS reachable
  • HSTS enabled
  • HTTP → HTTPS redirect
  • SPF configured
  • DMARC enforced
  • Mail (MX) configured

The full report adds ransomware, dark web, certificates, company intel and 100+ more controls.

Key takeaways

  • • DDoS dominates the count at 51.3% of incidents, but ENISA classifies it as low-impact; financially motivated activity, at 29.2%, is the most impactful threat in the short term.
  • • Attackers increasingly work through third-party providers, which ENISA assesses is highly likely an attempt to optimise the efficiency of their attacks.
  • • 73% of all recorded events hit entities that are essential or important under NIS2, which ENISA says confirms the relevance of the NIS2 approach.

What the report actually says

By assessed objective, ideology-driven activity accounted for 57.3% of incidents affecting the EU, financially motivated operations 29.2% and cyberespionage 6.3%. By incident type, low-impact DDoS made up 51.3% and unauthorised access 39.5%. ENISA is explicit that the volume and the damage point in different directions: ideology-driven claims, despite being most numerous, did not result in large-scale or significant impact, while financially motivated activity remains the most impactful threat in the short term. Within that financially motivated set, ransomware was 47.3% of claims, data breaches 36% and fraud or impersonation 13.3%. Two intrusion routes dominate: phishing as an enabling tactic in 77.8% of cases, and exploitation of known and zero-day vulnerabilities in 60.4% of unauthorised-access incidents. The five most targeted sectors were public administration (31.8%), business services (8.5%), transport (8%), manufacturing (6.9%) and finance or banking (5.6%).

Incidents by objective
  • Ideology-driven57.3%
  • Financially motivated29.2%
  • Cyberespionage6.3%

Highlighted: the most impactful threat in the short term, according to ENISA.

Most targeted sectors
  • Public administration31.8%
  • Business services8.5%
  • Transport8%
  • Manufacturing6.9%
  • Finance and banking5.6%

Share of recorded incidents in 2025. Source: ENISA Threat Landscape 2026.

Official source: ENISA Threat Landscape 2026 — published September 2026, covering 1 January to 31 December 2025. Figures above are taken from the report itself, not from the press summary. Reviewed 22 September 2026.

Five things to do with this

The report is a description of the year, not a to-do list. These five steps translate its findings into supplier-risk work you can actually carry out, and most of it uses signals you can read from outside a supplier.

1

Rank suppliers by impact, not by incident count

If you rank supplier risk by how often something happens, DDoS wins and you spend the year on the thing ENISA calls low-impact. Rank instead by what halts a delivery: ransomware exposure, breached credentials, an unpatched internet-facing system. That is the 29.2% ENISA says hurts most in the short term.

2

Map where your suppliers overlap

ENISA describes attackers moving through third-party providers to optimise the efficiency of their attacks — one compromise, many downstream victims. That efficiency only works because customers share suppliers. Map which of your suppliers sit on the same host, CDN, mail provider or parent group, so you can see where a single incident reaches several of your contracts at once.

3

Close the two routes the report names

Phishing enabled 77.8% of cases and vulnerability exploitation 60.4% of unauthorised access. Both are visible from outside: whether a supplier's domain can be spoofed is a matter of public DNS (SPF, DKIM, DMARC), and whether they expose a known-exploited vulnerability shows in what their systems answer on the public internet.

4

Watch for the events that arrive without warning

Ransomware victim listings and credential dumps are public, and they are usually the first signal that a supplier is in trouble — long before the supplier tells you. Checking them continuously turns a supplier incident from something you hear about late into something you can act on.

5

Write down what you checked

NIS2 Article 21(2)(d) requires you to manage supply-chain risk and Article 20 makes management accountable for it. ENISA noting that 73% of recorded events hit essential and important entities is the argument for doing this properly; a dated record of what you assessed, and what you decided, is what turns the work into evidence.

See how you and your suppliers actually score

Free · no credit card · no expiry

How norppa.io operationalises this

norppa.io monitors your suppliers from the outside, continuously, across the two routes this report puts first. It checks email authentication (SPF, DKIM, DMARC) so you can see which suppliers can be impersonated, and internet-exposed systems enriched with CISA KEV, EPSS and EUVD so exploitable exposure is ranked by what is actually being exploited. It watches public ransomware victim listings and credential leaks for the domains you track, maps shared infrastructure and common ownership across your portfolio, and ties every finding to the relevant NIS2 article with a dated evidence trail. One honest limitation: the report also covers software supply-chain compromise through package repositories, such as the Shai-Hulud npm campaign. That is dependency and SBOM territory, a different discipline from external posture monitoring, and norppa.io does not cover it.

Common mistakes

  • ✕Quoting the 51.3% DDoS figure as the year's main supplier threat, when ENISA classifies it as low-impact and NIS-sector organisations call it noise.
  • ✕Assessing each supplier alone, so shared hosting and common ownership hide the concentration that makes one incident reach several suppliers.
  • ✕Treating a supplier questionnaire as the assessment, with nothing checking the external reality behind the answers.
  • ✕Reacting to a supplier's ransomware incident only after the supplier discloses it, when the victim listing was public days earlier.

Frequently asked questions

Is the ENISA Threat Landscape binding on us?⌄

No. It is a threat assessment, not legislation, and nothing in it creates an obligation. What is binding is NIS2 itself: Article 21(2)(d) requires you to manage supply-chain security risk and Article 20 holds management accountable. The report matters because it tells you where the risk actually was in 2025, which is what a defensible risk assessment is supposed to be based on.

If DDoS is 51.3% of incidents, why should we not prioritise it?⌄

Because ENISA separates frequency from damage. It describes these as low-impact DDoS attacks, notes that ideology-driven claims did not result in large-scale or significant impact despite being most numerous, and reports that organisations in NIS sectors of high criticality characterise DDoS as noise while ransomware dominates their concerns. Prioritise by what stops your operations.

We are a supplier, not an essential entity — does this apply to us?⌄

It reaches you either way. ENISA found that 73% of recorded events hit essential or important entities, and those organisations must assess and manage the risk you carry to meet their own NIS2 duties. A domain that can be spoofed or an exposed unpatched system is what their assessment sees, and increasingly what decides whether the contract continues.

See where your suppliers stand

See a sample supplier report — findings, NIS2 mapping and evidence — in two minutes.

Free · no credit card · no expiry

Free plan: the 41-question NIS2 questionnaire for up to 10 suppliers, public checks on your own domain, and DMARC monitoring for one domain.

Related guides

NIS2's binding technical requirements for cloud, MSP and DNS suppliers (Regulation 2024/2690)

One group of suppliers has binding, itemised technical requirements that apply directly in all 27 Member States, with no national law to wait for. Which eleven provider types are covered, the thirteen requirement areas, and which six of them you can verify from outside.

ENISA's hospital procurement cybersecurity guidelines: how to assess your suppliers

ENISA's July 2026 procurement guidelines make supplier cybersecurity part of healthcare buying. Turn them into concrete steps: specify requirements, assess candidates externally, contract, monitor and document, mapped to the NIS2 Article 21(2)(d) supply-chain duty.

How to comply with NIS2: a step-by-step roadmap

The steps to NIS2 compliance in order: confirm scope, register, management accountability (Art. 20), the Article 21(2) measures, supply-chain security, incident reporting (Art. 23) and continuous, evidenced assurance.

Who is in scope for NIS2? Essential vs important entities, sectors and size thresholds

Determine whether NIS2 applies to you: the two tiers, the Annex I/II sectors, the size thresholds, size-independent exceptions, and how the supply chain pulls you in even if you're not designated.

NIS2 for suppliers: you're not designated, but your customers are

Most companies are never designated under NIS2, yet many must comply anyway. How a covered customer's Article 21(2)(d) supply-chain duty flows down to you, what they'll ask for, and how to respond credibly.

NIS2 and the supply chain requirement: what it means in practice

NIS2 requires essential and important entities to assess their supply chain cyber risks. Supplier tiering, 4th-party risk, Art. 23 notification, and what auditors look for.

How a breach happens in 2026: your external surface and your supply chain

The 2026 attack chain step by step — stolen credentials, exploited edge devices, email spoofing — across both your own external surface and your suppliers', and where norppa.io breaks the chain.

Supplier cyber risk assessment: what automated NIS2 monitoring checks

All check categories explained: ransomware, dark web leaks, TLS/DNSSEC, cookie security, CVE/EPSS, sanctions, MX blocklists and SAQ. Finding lifecycle and NIS2 article mapping.

NIS2 Art. 21(2): supplier security checklist

Checklist for procurement and security teams: what to ask, what evidence to collect, and how to respond when a supplier falls short. Includes suggested evidence documents.

NIS2 supplier questionnaire (SAQ): what to ask, how to score it, and a free template

What to ask suppliers under Art. 21(2)(d), how to score answers and respond to gaps, why self-attestation needs verification, and a free copy-paste questionnaire template.

NIS2 incident reporting: the 24- and 72-hour deadlines explained

What counts as a significant incident, the Article 23 timeline (24-hour early warning, 72-hour notification, one-month final report), and when a supplier's incident becomes your obligation.

NIS2 and management responsibility: what boards and leadership must know

What NIS2 expects of the management body: approval and oversight duties, personal liability (Art. 20), training, board reporting KPIs, and the penalties under Art. 34.

ISO 27001 and NIS2: what your ISMS already covers, and the gaps it doesn't

If you hold ISO 27001, what carries over to NIS2 and what does not: statutory incident reporting, management liability, registration, and continuous supply-chain assurance; plus how to close the gap.

NIS2 fines and penalties: how much, who is liable, and how to avoid them

What NIS2 penalties are: the Article 34 caps (€10M / 2% for essential, €7M / 1.4% for important entities), the management body's personal liability (Art. 20, Art. 32), non-monetary enforcement, and how to avoid them with continuous, evidenced diligence.

NIS2 vs DORA: how they differ, where they overlap, and which one applies to you

How the two EU regimes differ and overlap, why DORA is lex specialis for financial entities, which applies to you, and what both mean for third-party and supply-chain risk.

GDPR vs NIS2: how they overlap, where they differ, and when one incident triggers both

How GDPR and NIS2 differ and overlap, when one incident triggers both (GDPR Art. 33 72h to the data protection authority vs NIS2 Art. 23 24h/72h/1-month to the CSIRT), the Art. 35 cooperation and no-double-fine rule, and what both mean for supplier due diligence.

The EU Cyber Resilience Act (CRA): scope, timeline and what it means for your supply chain

What the CRA requires, its phased dates (in force 2024, reporting Sept 2026, full compliance Dec 2027), who is in scope and why pure SaaS often isn't, how it complements NIS2, and what it means for procurement and supplier due diligence.

The EU AI Act: risk tiers, the timeline, and what deployers must do (Article 26)

What the EU AI Act requires: the risk tiers, the phased dates (in force 2024, prohibited Feb 2025, GPAI Aug 2025, high-risk Aug 2026), the Article 26 deployer obligations, how it stacks with NIS2 and the GDPR, and what it means for AI procurement.

NIS2 transposition status: which EU countries have it in force

Which of the 27 EU Member States have written NIS2 into national law and which are still finalising it, and why the gaps reach your supply chain regardless.

NIS2 supplier contract clauses: what to require from your suppliers

The contract clauses that turn NIS2's supply-chain duty into something enforceable: security baseline, incident-notification window, evidence and audit rights, subcontractor flow-down, and how to verify them continuously.

Your external security posture under NIS2: what suppliers and customers can see

The publicly visible signals customers assess under NIS2 Art. 21(2)(d): email spoofability (SPF/DMARC), certificate hygiene, internet-exposed systems and leaked credentials, why each matters and how to check and fix them.

Do your suppliers use AI? NIS2 supplier risk meets the EU AI Act

Suppliers increasingly embed AI in the services you depend on, and so do their suppliers. Where supplier and nth-party AI creates risk under NIS2 Art. 21(2)(d) and the EU AI Act, what to assess, and how to keep visibility.

Vendor impersonation and CEO-fraud (BEC): email spoofing, DMARC and NIS2

One of the most common supply-chain attacks needs no breach: spoofed email that redirects a payment or steals data. How BEC and vendor impersonation work, the SPF, DKIM and DMARC settings that stop them, and how it fits NIS2 Art. 21(2)(d).

Last reviewed: 19 June 2026

This guide is general information about EU law, not legal advice. NIS2 takes effect through each EU Member State's national transposition law, which can differ in detail. Verify the obligations that apply to you with your competent authority or legal counsel.