ENISA Threat Landscape — operationalised.
The EU's flagship annual report on the cyber threat environment.
Prime threats, threat actors, motivations and sector impact across the last 12 months — the reference Europe's CISOs benchmark against.
Published annually since 2012, the ENISA Threat Landscape (ETL) report identifies prime threats, major trends, threat actors and the impact of cyber incidents across the European Union. ETL has become the de-facto reference for European boards, regulators and security teams. We map every client risk register, detection use-case and exercise scenario back to the current ETL edition so executives can speak the same language as their regulator.
Read the latest ETL on ENISA- Publisher
- ENISA — EU Agency for Cybersecurity
- First edition
- 2012
- Cadence
- Annual flagship + thematic studies
- Latest edition
- ETL 2024 (Sept 2024) — ETL 2025 due Q3 2025
- Coverage window
- Rolling 12 months (Jul → Jun)
What this framework covers
Prime threats tracked by ETL
ETL groups observed activity into eight prime threat categories, ranked by prevalence and impact across EU sectors.
- ›Ransomware — most prolific impact across sectors and Member States
- ›Malware — infostealers, loaders and RATs dominate volume
- ›Social engineering — phishing, vishing, smishing and deepfake-enabled fraud
- ›Threats against data — breaches, leaks, extortion and data poisoning
- ›Threats against availability — DDoS, including hacktivist-driven surges
- ›Information manipulation (FIMI) — state-aligned narrative operations
- ›Supply chain attacks — software, MSP and dependency compromise
- ›Threats against availability of the internet — routing, DNS and submarine cable
Threat actor groupings
ETL classifies actors by motivation and capability so defenders can match controls to plausible adversaries.
- ›State-nexus actors — espionage, pre-positioning and FIMI
- ›Cybercrime — financially motivated, ransomware-as-a-service ecosystems
- ›Hacktivists — ideology-driven DDoS and defacement, often around geopolitics
- ›Insiders — intentional and accidental, increasing alongside layoffs and AI tooling
Sector impact view
Each edition includes a sectoral breakdown so operators of essential services can benchmark their exposure.
- ›Public administration, transport and finance consistently top the incident counts
- ›Health and digital infrastructure show the steepest year-on-year increases
- ›Manufacturing and energy dominate OT-related incident reporting
How we put ETL to work
- Quarterly threat-landscape briefing for the executive committee, mapped to ETL prime threats
- Detection use-case coverage matrix benchmarked against ETL TTPs
- Sector-specific tabletop scenarios drawn from the latest ETL incident analysis
- Risk register alignment so board reporting language matches the regulator's