Resources

ENISA threat intelligence & European regulatory insight.

Live advisories and ENISA's Threat Landscape, publications, NIS2 and DORA guidance — synced from official EU sources alongside research from our team.

ENISA / THREAT.LANDSCAPE

Top observed threat categories

Drawn from the ENISA Threat Landscape — the EU's flagship annual report on the cyber threat environment.

  • T-01Ransomware
  • T-02Malware
  • T-03Social Engineering
  • T-04Threats Against Data
  • T-05Threats Against Availability — DDoS
  • T-06Information Manipulation (FIMI)
  • T-07Supply Chain Attacks
Read the full ENISA Threat Landscape
ENISA / LATEST.PUBLICATIONS
SYNC · 08 Sep 2026 · 06:50 UTC

Reports, guidance & studies

ENISA feeds are temporarily unavailable.
/ ENISA.TOPIC.PILLARS

Frameworks we operationalise for clients

POLICY

NIS2 Directive

Directive (EU) 2022/2555 expands EU cyber rules to ~160k essential and important entities across 18 sectors, with board-level accountability and tougher supervision.

  • Scope, registration & national competent authority filings
  • 24h early warning · 72h incident notification · 1-month final report
  • Management liability and sanctions up to €10M / 2% turnover
INTEL

ENISA Threat Landscape

ENISA's flagship annual report on the EU cyber threat environment — prime threats, threat actors, motivations and sector impact across the last 12 months.

  • Top threats: ransomware, malware, DDoS, social engineering, FIMI
  • Threat actor profiles: state-nexus, cybercrime, hacktivists, insiders
  • Sector views: public admin, transport, finance, health, digital infra
OT/ICS

Critical Infrastructure

Sector-specific guidance for operators of essential services — energy, finance, health, transport, water and digital infrastructure — aligned to NIS2 Annex I.

  • OT/ICS security baselines & IEC 62443 alignment
  • Cross-border dependencies & cascading impact analysis
  • Sector CSIRTs, ISACs and information-sharing arrangements
IR

Incident Reporting

Operational frameworks aligned to NIS2 Article 23 and DORA Article 19 — from triage through regulator notification and post-incident review.

  • Triage runbooks mapped to NIS2 / DORA / GDPR timelines
  • Templates for early warning, incident & final reports
  • Lessons-learned loop back into detections & controls
CRYPTO

Cryptography & PQC

Post-quantum readiness and cryptographic agility — moving estates onto NIST FIPS 203/204/205 algorithms ahead of harvest-now-decrypt-later risk.

  • Crypto inventory: keys, certificates, protocols, HSMs, libraries
  • Migration roadmap to ML-KEM, ML-DSA & SLH-DSA
  • Hybrid TLS & signed software supply chain
TRAIN

Awareness & Skills

European Cybersecurity Skills Framework (ECSF), CyberHEAD database and the European Cybersecurity Month (ECSM) — anchoring our Security Academy curriculum.

  • Role-based learning paths mapped to ECSF 12 profiles
  • Phishing simulations, exec briefings & board war-games
  • ECSM campaigns with measurable behavioural KPIs
/ EU.REGULATORY.TIMELINE — 2025 / 2026

The regulatory horizon for boards

Milestones we track across DORA, NIS2, the Cyber Resilience Act and the EU Cloud Certification scheme — mapped to client programmes.

  1. Jan 2025DORA

    DORA enters full application

    EU financial entities and critical ICT third-party providers operate under Regulation (EU) 2022/2554.

  2. Apr 2025NIS2

    Entity registration & supervisory ramp-up

    National authorities expand sectoral oversight; first enforcement actions against late transposers.

  3. Q3 2025ETL'25

    ENISA Threat Landscape 2025

    Annual flagship report — ransomware, FIMI, AI-enabled attacks and supply chain remain top vectors.

  4. Dec 2025CRA

    Cyber Resilience Act reporting kicks in

    Vendors of products with digital elements begin mandatory vulnerability & incident notifications to ENISA.

  5. 2026EUCS

    EU Cloud Certification scheme rollout

    Common criteria for cloud services across Member States; sovereignty controls finalised.

  6. Dec 2027CRA

    Full CRA conformity required

    All in-scope products must meet essential cybersecurity requirements with CE marking.

/ TRENDS.2025-2026

What ENISA, NCSC & CISA are flagging this cycle

AI

AI-enabled attacks & defence

Generative AI scales phishing, deepfakes and code-assisted intrusion; defenders adopt AI for triage and detection at SOC scale.

PQC

Post-quantum migration

NIST FIPS 203/204/205 ratified; ENISA urges crypto-agility roadmaps and HNDL (harvest-now, decrypt-later) risk assessments.

OT

OT & critical infrastructure

Energy, water and healthcare see record ICS exposure; NIS2 brings ~160k+ EU entities into scope.

SUPPLY

Software supply chain

SBOM adoption, signed artifacts and CRA conformity reshape vendor due diligence across the EU.

FIMI

Foreign information manipulation

Election cycles in 2024–2026 drive a sustained uplift in state-aligned influence operations.

IDENT

Identity & access perimeter

Token theft, MFA fatigue and OAuth abuse become the dominant initial-access vector across cloud estates.

LIVE / THREAT.FEED

Active advisories from ENISA, CISA & NCSC

SYNC · 08 Sep 2026 · 06:50 UTC
/ RESOURCE.LIBRARY

Intelligence, research & regulatory horizon-scanning

Six streams of original content produced by our senior advisors, SOC analysts and GRC practitioners — calibrated for technical teams and executive boards.

CATEGORIES · 06  |  UPDATED WEEKLY
RL-01
WEEKLY

Blog

Insights from our senior advisors and SOC team.

  • 12 Jan 2026 · 00:00 UTC·SOC·8 min
    Inside a 24/7 SOC: triage patterns that actually reduce MTTR
  • 03 Dec 2025 · 00:00 UTC·AI·6 min
    Operationalising LLMs in detection engineering — without the hype
  • 18 Nov 2025 · 00:00 UTC·GRC·5 min
    Board reporting that survives contact with auditors
3 latestBrowse all →
RL-02
AS-NEEDED · 24/7

Cyber Alerts

Time-critical advisories on active threats.

  • 22 Jan 2026 · 00:00 UTC·CVE·3 min
    Critical RCE in widely-deployed edge gateway — emergency mitigations
  • 09 Jan 2026 · 00:00 UTC·Ransomware·4 min
    New double-extortion crew targeting EU financials — TTPs & IOCs
  • 21 Dec 2025 · 00:00 UTC·Phishing·3 min
    QR-code phishing wave against C-suite Microsoft 365 tenants
3 latestBrowse all →
RL-03
MONTHLY

Threat Intelligence

Sector-focused intelligence briefings.

  • 15 Jan 2026 · 00:00 UTC·Finance·12 min
    EU banking sector threat brief — Q1 2026
  • 10 Dec 2025 · 00:00 UTC·Healthcare·10 min
    Ransomware exposure across EMEA hospitals & medical IoT
  • 25 Nov 2025 · 00:00 UTC·Energy / OT·11 min
    ICS adversary tracking — pipelines, grid and renewables
3 latestBrowse all →
RL-04
QUARTERLY

Whitepapers

In-depth research on resilience and risk.

  • 05 Jan 2026 · 00:00 UTC·Resilience·32 pp
    Cyber Resilience Blueprint 2026 — from controls to outcomes
  • 02 Nov 2025 · 00:00 UTC·Zero Trust·28 pp
    Zero Trust at enterprise scale — identity, network, workload
  • 14 Sep 2025 · 00:00 UTC·PQC·24 pp
    Post-quantum migration playbook for regulated industries
3 latestBrowse all →
RL-05
CONTINUOUS

Case Studies

Outcomes from enterprise engagements.

  • 08 Jan 2026 · 00:00 UTC·Banking·6 min
    Tier-1 bank — 71% MTTR reduction in 90 days with MDR + SOAR
  • 12 Dec 2025 · 00:00 UTC·Telco·7 min
    National ISP — One Shield rollout protecting 2.4M subscribers
  • 30 Oct 2025 · 00:00 UTC·Public Sector·8 min
    Ministry-grade SOC build-out aligned to NIS2 Article 21
3 latestBrowse all →
RL-06
BI-WEEKLY

DORA & NIS2 Updates

Regulatory horizon-scanning for boards.

  • 20 Jan 2026 · 00:00 UTC·DORA·5 min
    ICT third-party register — what supervisors are actually asking for
  • 06 Jan 2026 · 00:00 UTC·NIS2·4 min
    Member-state transposition tracker — Q1 2026 status
  • 15 Dec 2025 · 00:00 UTC·CRA·6 min
    Cyber Resilience Act — vendor obligations entering force in 2027
3 latestBrowse all →
Subscribe to receive curated briefings — Blog, Cyber Alerts and DORA/NIS2 Updates.
Request access →

Talk to a cyber advisor.

Confidential consultation with our senior team.

Request Assessment