Cyber dependencies weaken resilience, warns report

Cyber dependencies are increasing organisations’ exposure to attack and creating the potential for incidents to have a wider impact across digital supply chains, according to the European Union Agency for Cybersecurity.

The warning comes in ENISA’s 2026 Threat Landscape, which analyses cyber incidents and events recorded between January and December 2025. The report highlights the continued targeting of cyber dependencies, including through supply-chain and third-party attacks, which can amplify the impact of individual incidents.

Ransomware remains the most impactful short-term cyber threat, while ENISA says organisations are increasingly facing a combination of cybercrime, cyberespionage and hacktivist activity influenced by geopolitical developments.

Vulnerability exploitation also remains a significant intrusion route. Of the unauthorised-access incidents where ENISA could identify the initial intrusion vector, 60% involved the exploitation of a vulnerability. More than 48,000 new vulnerabilities were assigned CVE identifiers during 2025 – a 22% increase on the previous year.

The public sector was the most targeted, accounting for 32% of incidents, followed by business services and transport, each at 8%, manufacturing at 7%, and finance and banking at 6%. Overall, 73% of targeted organisations were classified as essential or important entities under the EU’s NIS2 directive.

ENISA also identifies the growing dual role of artificial intelligence as a key development. AI is increasingly being used by threat actors to support malicious activity, while the integration of AI systems into business environments is creating an additional attack surface. The agency said the increasing interconnectedness of digital services and infrastructure means organisations need to consider not only their own security controls but also the dependencies that could provide attackers with routes into their operations or amplify the consequences of an incident.



Share Story:

YOU MIGHT ALSO LIKE


Resilience Rooted in Reality
In this podcast, CIR speaks to CLDigital’s Tejas Katwala about why organisations must move beyond checklist compliance to build living, data driven resilience. He explains how rethinking governance, risk and compliance, breaking down silos and focusing on value streams can create sustainable, real time resilience that is rooted in the way businesses actually operate today.

Building cyber resilience in a complex threat landscape
Cyber threats are evolving faster than ever. This episode explores how organisations can strengthen defences, embed resilience, and navigate regulatory and human challenges in an increasingly complex digital environment.