Framework / INTEL

ENISA Threat Landscape — operationalised.

The EU's flagship annual report on the cyber threat environment.

INTEL

Prime threats, threat actors, motivations and sector impact across the last 12 months — the reference Europe's CISOs benchmark against.

Published annually since 2012, the ENISA Threat Landscape (ETL) report identifies prime threats, major trends, threat actors and the impact of cyber incidents across the European Union. ETL has become the de-facto reference for European boards, regulators and security teams. We map every client risk register, detection use-case and exercise scenario back to the current ETL edition so executives can speak the same language as their regulator.

Read the latest ETL on ENISA
/ KEY.FACTS
Publisher
ENISA — EU Agency for Cybersecurity
First edition
2012
Cadence
Annual flagship + thematic studies
Latest edition
ETL 2024 (Sept 2024) — ETL 2025 due Q3 2025
Coverage window
Rolling 12 months (Jul → Jun)
/ GUIDANCE

What this framework covers

§ 01

Prime threats tracked by ETL

ETL groups observed activity into eight prime threat categories, ranked by prevalence and impact across EU sectors.

  • Ransomware — most prolific impact across sectors and Member States
  • Malware — infostealers, loaders and RATs dominate volume
  • Social engineering — phishing, vishing, smishing and deepfake-enabled fraud
  • Threats against data — breaches, leaks, extortion and data poisoning
  • Threats against availability — DDoS, including hacktivist-driven surges
  • Information manipulation (FIMI) — state-aligned narrative operations
  • Supply chain attacks — software, MSP and dependency compromise
  • Threats against availability of the internet — routing, DNS and submarine cable
§ 02

Threat actor groupings

ETL classifies actors by motivation and capability so defenders can match controls to plausible adversaries.

  • State-nexus actors — espionage, pre-positioning and FIMI
  • Cybercrime — financially motivated, ransomware-as-a-service ecosystems
  • Hacktivists — ideology-driven DDoS and defacement, often around geopolitics
  • Insiders — intentional and accidental, increasing alongside layoffs and AI tooling
§ 03

Sector impact view

Each edition includes a sectoral breakdown so operators of essential services can benchmark their exposure.

  • Public administration, transport and finance consistently top the incident counts
  • Health and digital infrastructure show the steepest year-on-year increases
  • Manufacturing and energy dominate OT-related incident reporting
/ THECYBERCO.SERVICE

How we put ETL to work

  • Quarterly threat-landscape briefing for the executive committee, mapped to ETL prime threats
  • Detection use-case coverage matrix benchmarked against ETL TTPs
  • Sector-specific tabletop scenarios drawn from the latest ETL incident analysis
  • Risk register alignment so board reporting language matches the regulator's

Talk to a cyber advisor.

Confidential consultation with our senior team.

Request Assessment