Progress Across the Board, But the Sectors That Matter Most Are Still Falling Short


ENISA NIS360 2026: Progress Across the Board, But the Sectors That Matter Most Are Still Falling Short

Pierluigi Paganini
June 02, 2026

ENISA NIS360 2026 shows cybersecurity improving across EU critical sectors, but health, water, rail, and space remain in the risk zone.

ENISA has published its third annual NIS360 report, assessing the cybersecurity maturity and criticality of all sectors covered by the NIS2 directive. The headline finding is that things are improving across the board. The more important finding is that the improvement is uneven, slow where it matters most, and being outpaced by a threat landscape that’s getting harder faster than defenses are getting better.

Banking, electricity, and telecommunications remain the most mature and most critical sectors, as they have been since the assessment began. Three sectors moved up into the high maturity band for the first time: trust services, aviation, and financial market infrastructures. Four more strengthened their position within the moderate band: gas, road, maritime, and health.

The drivers behind this progress are consistent across the board: cybersecurity legislation that organizations are actually using to unlock investment rather than just checkbox compliance, increased political attention translating into guidance and resources, and gradual improvements in information sharing and incident preparedness.

“Since the previous edition of this report, cybersecurity maturity across sectors of high criticality in the EU, has been steadily improving as organisations respond to evolving policy requirements and cyber threats they face.” reads the report published by ENISA. “Banking, electricity and telecommunications remain the most mature and critical sectors, while three sectors, trust services, aviation, and financial market infrastructures (FMIs) moved into the high maturity band. Four sectors strengthened their maturity within the moderate band: gas, road, maritime, and health.”

The risk zone is where the report gets harder to read. It includes sectors with criticality that exceeds their maturity, meaning they’re more important to society and the economy than they’re currently prepared to protect. This year, that zone includes health, railway, maritime, ICT service management, space, public administrations, and drinking and waste water.

Rail, drinking water, and waste water moved into the risk zone this year, not because they got worse, but because overall maturity improved across other sectors and the bar moved.

The one piece of positive news is that gas has started moving out of the risk zone, driven by better information sharing and stronger risk management implementation.

“Combining and jointly interpreting the criticality and maturity dimensions helps identify mismatches between the two and helps define the risk zone. The risk zone includes sectors with lower-thanaverage maturity and criticality that exceeds their maturity. Its composition changes over time as overall maturity improves across sectors.” continues the report. “This is one of the reasons why three sectors previously at the risk zone boundary – rail, drinking water, and waste water are now within the risk zone. The positive development is that the gas sector has started moving out of the risk zone. This shift is driven by improved information sharing, stronger collaboration, and better implementation of risk management measures that are to higher maturity.”

Health deserves particular attention because it illustrates how a sector can be getting better on paper while remaining fundamentally exposed. Pharmaceutical manufacturers are raising the overall numbers. Hospitals and healthcare providers, which are the parts of the sector most likely to be attacked and where the human consequences of a disruption are most direct, are still struggling with basic asset tracking, legacy systems, budget constraints, and cybersecurity awareness levels that most other sectors left behind years ago. One in three water sector entities surveyed has never conducted a risk assessment. In public administrations, about one third of entities have no structured process for ensuring cybersecurity expertise at management level, and about half don’t provide cybersecurity training to management at all. This is the sector that receives nearly 63% of all hacktivist attacks and is the most consistently targeted sector in Europe.

The report identifies three dynamics that are reshaping the environment across all sectors. AI is making offensive capabilities more accessible and more effective faster than it’s helping defenders, which means organizations need to detect and respond to threats at timescales that most of them aren’t currently capable of. Supply chain risk is growing because every trusted vendor relationship is also implicitly a trust relationship with everyone that vendor trusted, and the compromise of a single widely-used dependency can now cascade across entire sector landscapes in ways that weren’t possible five years ago. Geopolitical volatility is increasing the frequency and sophistication of state-aligned attacks while simultaneously creating pressure to reduce dependency on technology from outside the EU.

“With the benefits of AI thus far materialising faster for attackers than defenders, and the further proliferation and commoditisation of AI-enabled offensive capabilities being a matter of time, sectoral stakeholders are currently faced with mounting pressure when it comes to effectively adapting to the more dynamic threat environment brought forward by AI.” states ENISA.

The space sector’s situation is particularly worth noting given how much Europe is depending on it. Space underpins positioning and navigation used by financial systems for timestamping trades, telecommunications networks for synchronisation, agriculture, emergency response, border surveillance, and military communications. Its criticality score was revised upward this year to reflect this growing dependency. Its maturity score sits at the lower end of moderate, with enormous variation across entities depending on whether they fall under NIS2 scope or not. Some entities have mature, proactive security practices. Others struggle to define cybersecurity roles and responsibilities at all. There’s no dedicated EU-level forum for cybersecurity collaboration in the space sector, and information sharing remains limited. A sector that’s being positioned as a cornerstone of European strategic autonomy is also one of the least cybersecurity-mature sectors in the assessment.

The finance sector, by contrast, shows what sustained regulatory pressure and enforcement actually produces. Banking has long experience with compliance as a floor rather than a ceiling, and it shows. The FMI sector jumped a full maturity band this year, driven in substantial part by DORA implementation giving organizations a structured framework to work from and supervisory authorities the tools to hold them accountable. The lesson isn’t that more regulation automatically produces better security, but that regulation with teeth, clear requirements, and supervisory capacity actually changes behavior at scale. The contrast with ICT service management, where national authorities are often new to the sector, lack sector-specific expertise, and have limited resources, makes this point in the opposite direction.

Progress is real. It’s also not fast enough, and it’s not evenly distributed. The sectors that can least afford to be underprepared are the ones with the most ground to cover.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, ENISA NIS360 2026)







Source link

Leave a Reply

Subscribe to Our Newsletter

Get our latest articles delivered straight to your inbox. No spam, we promise.

Recent Reviews


Tommiee lost both parents when he was young and grew up in the care system, moving between different families and situations. These early experiences followed him into adulthood – he often felt like he didn’t belong, and ongoing housing challenges meant he never had a true sense of security. Despite everything, he held onto hope, and he found community in places where he felt understood, like the skate park in Bedminster.

In this interview with senior support worker, Fisayo, Tommiee reflects on his journey and how meeting Second Step helped him finally find stability after a lifetime of instability.

Dean Lane skate park, near North Street in Bedminster, has been a cornerstone of Bristol’s skate community for decades. Since opening in 1978, it has served generations of skaters and become a much‑loved fixture of the neighbourhood.

“Sharing a space like this, you know, I feel like for a lot of people that don’t want to be at home, or have difficulties inside or with themselves, or interacting with people, it’s a place where you can come,” says Tommiee, “It’s like an outdoor mental health men’s club. So having the opportunity to come back here, even though I don’t live here anymore now, is good, you know?”

Although he doesn’t live in Bedminster anymore, Tommiee came back to the skate park to meet his support worker, Fisayo, and tell his story:

Tommiee: “My name is Tom – Tommiee Mosarey – also known as BS3 Chase. I came to Second Step because I was probably going through a hard time in my life and I was having difficulty in my housing.”

Fisayo: “How has Second Step helped you? How’s your journey been so far?”

Tommiee: “They moved quickly. They actually listened to me, so I’m happy to be where I am now.”

Fisayo: “Do you want to tell a bit about your background and what you faced growing up till now?”

Tommiee: “Yeah, man. I faced a lot. I think everyone’s got a story to tell that would make you feel sad. But, obviously having to deal with that every day… My parents died when I was a baby. I was very young and obviously due to that I had to grow up in different situations, in different families, and yeah it was kind of hard.

“I was always me, if you know what I mean. I had to find me and then find out how I fit into society, you know.”

Fisayo: “What would you say is one thing that actually kept you going?”

Tommiee: “I guess my energy, my resilience, me wanting to have a happy ending, me knowing that it’s working out for this person over here, it’s working out for those people over there. I’m going to get my time soon, and it’s just waiting for the stars to align. Just waiting and being patient.

“I was actually going to give up before Second Step came, not give up but… let me explain this: before Second Step, it was like another house, another home, another group of people that I had to go and see and work with who were going to promise me my happy ending. And I had been failed up until then. And then obviously I met you guys. So I was a bit hesitant at first, and then obviously I met you and we sat down, we spoke, and we had similar interests. So I think that’s what made me grow to you and then, I don’t know, I just was like I trust you, you know? And then, I’m still here now, so it works out.”

Fisayo: “Do you find using a support worker helpful in any way?”

Tommiee: “I think Second Step try and pair you with somebody that you will actually resonate with. I learned how to open up and trust you about other things that I couldn’t do or I didn’t know I had to do that were the steps to take to get my own independence.

“So now I am, and my life’s changed. I got a new job, I live in a whole new area. It’s a lot of responsibilities but living in Second Step (Toll House Court) and taking that step initially and working with you, realising that good things can happen to all of us.

“Like I said at the beginning, everyone’s probably got a story to get you that’s probably going to make you feel sad, do you know what I mean? But it’s part of our movie. And even if you have no one and feel like you got no one, there’s always someone there. There’s always a service there. There’s always a person like you to help, that genuinely just wants to help another person. And when you’re human about it, it’s great and it works out.

“I’ve been through a lot of services, a lot of different things, you know, just growing up from a kid in the system, like a little baby into an adult. I feel like every single one of them services kind of let me down. But every single one of them was a step to find the right step for me, which was Second Step.

“And I feel like, especially the last seven years before I met you guys, being here in Bedminster and growing up and finding myself, it’s great on the outside, but my home life wasn’t great. I was living in shared houses with other people who had issues and problems and stuff like that. And if you do get the opportunity to get engaged with services like Second Step – really lucky. The person they’ve got to work with you, they’ll match you with someone that you know you’re comfortable with. They can see where you’re going wrong and then kind of point you in the right direction, you see what I’m saying? I feel like that’s what you’ve done for me really. I just hope that you’re proud of me, you know?

Fisayo: “Definitely. I’m proud of you. You made the right choice, you know, taking the right steps and we can only wish you the best. And just keep your head held high, keep it moving. So many dreams out there and so many things to achieve as well. Proud of you, man. Yeah, man, that’s good. Thank you.”

Thank you to Tommiee for sharing your story of hope and courage, and to Fisayo for the support and compassion that helped Tommiee along the way.

To find out more about the Second Step services and the support we offer please take a look at the Our Services section on our website.



Source link