When ENISA's Threat Landscape 2025 landed last October, we walked through what it found: operational technology breaking out as its own threat category, hacktivists probing exposed energy and water systems, ransomware still doing the most damage. I want to pick up where that piece left off. The report's findings are established; the question I keep getting asked by operators and underwriters is the one that comes next: given what ENISA measured, what actually changes about your compliance obligations and how your risk gets priced in cyber insurance? The short version is that ENISA's dataset has quietly become the closest thing the EU has to an evidence base for NIS2, and that has consequences for both sides of the risk-transfer table (i.e., insurers and OT asset owners).
Start with the one number that reframes the conversation
For readers who haven't seen the report, one figure anchors everything: for the first time, OT appears as a distinct threat category in ENISA's accounting, at 18.2% of all threat categories tracked, behind only mobile (42.4%) and web (27.3%) threats. ENISA's own framing is worth reading directly: this reflects "the growing exposure of industrial and critical systems as they continue being increasingly connected and targeted". That's not a forecast. It is a curated dataset of 4,875 reported incidents and events affecting EU Member States and EU-based organizations from 1 July 2024 through 30 June 2025, compiled mainly from open-source reporting and supplemented by anonymized voluntary information from Member States and partners [1].
The rest of the report fills in who and how, and our earlier post covers the threat detail in full. Three findings matter for what follows here. Hacktivist groups in the Z-PENTEST-ALLIANCE ecosystem claimed attacks against internet-accessible OT management interfaces in the energy and water-management sectors across several EU Member States; ENISA notes that the reported attacks did not result in significant operational impact. Ransomware remained the most directly impactful cybercrime threat. Its recorded share remained stable, and manufacturing accounted for the largest share of ransomware claims, at 14.9%. Cyberespionage campaigns accounted for 7.2% of assessed objectives, while state-aligned groups continued long-term espionage activity; ENISA says Sandworm’s apparent mandate remains focused on the energy vertical
ENISA also reports that Infrastructure Destruction Squad, or IDS, reportedly developed an ICS-focused tool called VoltRuptor and advertised it for sale. KELA subsequently corroborated the IDS actor brand and its August 2025 promotion of VoltRuptor, while Cyble and Forescout separately documented claimed HMI/SCADA access and other OT-oriented tooling associated with IDS or the overlapping Dark Engine cluster.[8][9][10] Those sources do not independently validate VoltRuptor’s advertised capabilities or confirm its deployment in an incident: none provides a public VoltRuptor sample, hashes, reverse-engineering analysis or incident forensics tied to the tool. ENISA’s qualifications should therefore be retained, and the possible Russia nexus should be treated as a working hypothesis rather than established attribution [1]. Cyble and Forescout use IDS and Dark Engine as aliases, while KELA reports that IDS itself disputes that identification.[8][9][10]
The operative phrase in all of this is the hacktivist one: internet-accessible OT management interfaces. Not a zero-day. Not a supply-chain compromise. An interface someone left reachable from the public internet. Hold onto that, because it's exactly what NIS2 is now asking operators to account for.
Why this maps almost exactly onto NIS2
ENISA didn't set out to write a NIS2 compliance document, but its data ends up looking a lot like one. After redacting the roughly 28.5% of incidents that couldn't be attributed to a sector, the top five targeted sectors were public administration, transport, digital infrastructure, finance, and manufacturing. Essential entities under NIS2 accounted for 53.7% of all recorded incidents. ENISA states plainly that this overlap "with sectors explicitly covered under the directive confirms the relevance of the NIS2 approach".
That's not a coincidence worth marveling at. It's a signal worth acting on. If your organization sits in energy, water, transport, or manufacturing and meets the NIS2 size thresholds, you're not just in a regulatory category. You're in the empirical target set the agency responsible for EU cybersecurity just measured.
NIS2 itself has had an uneven rollout. (For the full definition and scope thresholds, see our NIS2 glossary entry and NIS2 FAQ; we won't re-explain the directive here.) Member States were required to transpose the Directive by 17 October 2024. As of 8 July 2026, France, Ireland, the Netherlands and Spain had not notified full transposition, and the European Commission had referred them to the Court of Justice with requests for financial sanctions [11]. On 20 January 2026, the Commission proposed targeted NIS2 amendments intended to clarify scope and jurisdiction, streamline the collection of ransomware-attack data and facilitate supervision of cross-border entities [2]. That proposal is not yet law. The Directive’s existing core obligations remain: management-body approval and oversight under Article 20; cybersecurity risk-management measures under Article 21; and significant-incident reporting under Article 23—an early warning within 24 hours of awareness, an incident notification within 72 hours, and a final report generally within one month after the incident notification. For essential entities, Member States must provide maximum administrative fines of at least €10 million or 2% of worldwide annual turnover, whichever is higher [12].
The operational challenge is to detect and triage incidents quickly enough that, once the organization becomes aware of a significant incident, it can meet Article 23’s 24-hour early-warning deadline. A phishing-driven intrusion that ENISA's data says accounts for roughly 60% of initial access, and a vulnerability-exploitation path that accounts for another 21.3%, both need to be detected before they can be reported [1], and detection in a segmented OT environment without real-time visibility is not a 24-hour proposition by default. It becomes one only with deliberate investment.
What this means for insurers and reinsurers
ENISA's report contains no loss figures of its own, but the exposure it documents has a well-established price tag elsewhere. IBM's 2024 Cost of a Data Breach research put the global average breach cost at $4.88 million, a 10% year-over-year increase and the largest jump since the pandemic [3]. Siemens/Senseye estimates that unplanned downtime costs the world’s 500 largest companies approximately USD 1.4 trillion annually, equivalent to about 11% of revenue [4].
UK research commissioned by e2e-assure and fielded by Censuswide among 250 cybersecurity decision-makers in January 2026 found that, among manufacturing and critical-national-infrastructure respondents experiencing OT downtime, around 80% reported losses between £100,000 and £5 million. Twenty-three percent said their most severe OT downtime incidents cost more than £1 million, while 6% reported costs above £5 million. The study reported an average 52 days from compromise to detection, while one in ten large enterprises took more than a year to remediate major incidents [5].
On the capacity side, Munich Re estimates the 2026 global cyber insurance market at approximately $15.7 billion, including $3.9 billion in Europe—roughly one quarter of the total—and projects European premium volume to reach $7.4 billion by 2030 [14]. Premium growth does not eliminate the accumulation problem: Munich Re’s 2026 analysis warns that increasing cloud, technology and digital-supply-chain dependencies may require insurers to adapt their accumulation models and budgets, while reinsurance remains vital for sharing large or unpredictable losses and expanding primary-market capacity [6]. S&P reported that primary cyber insurers ceded approximately 44% of premiums to reinsurers on average in 2024 [13]. Beazley’s fourth 144A cyber catastrophe bond, the $300 million PoleStar Re 2026-1, brought its cyber-catastrophe-bond protection to $670 million and added three-year cover for remote-probability catastrophic and systemic cyber events through the end of 2028 [7]. The market is growing, but its ability to absorb correlated OT and critical-infrastructure losses still depends on disciplined accumulation management, reinsurance and alternative capital.
The practical takeaways
For OT operators, the immediate move is to inventory and eliminate internet-exposed management interfaces. That is the specific attack surface ENISA says hacktivist groups claimed to have targeted in the energy and water sectors during its July 2024–June 2025 reporting period. Next, close the two access paths that account for roughly 80% of intrusions in ENISA's data: phishing and vulnerability exploitation [1]. Phishing-resistant MFA, stronger identity and email controls, edge-device hardening, and risk-based vulnerability remediation address important parts of those initial-access pathways. Segmentation, asset visibility, logging and rehearsed escalation and reporting workflows improve the organization’s ability to contain an incident and meet NIS2’s reporting deadlines.
These top ENISA recommendations align with DeNexus’ recommendations in our Top 6 Cybersecurity Solutions for Industrial Environments blog, which prioritizes a Defensible Architecture, Securing the Perimeter and External Access. These are foundational requirements that are most effective at reducing risk (aka., financial losses due to a cyber incident) and must be established first.
For Risk Assumers, ENISA's dataset is a genuinely useful calibration input for European critical-infrastructure books, provided the numbers are read correctly. The 18.2% OT figure describes a share of threat categories, not a share of incidents that physically hit OT systems, and DDoS volume shouldn't be confused with loss severity: ransomware remains the actual driver of financial impact even as its raw incident count declined. Underwriting to the specific gaps this report names, exposed OT interfaces, patch velocity, segmentation, backup integrity, gives you a sharper signal than a generic cyber questionnaire ever will. Turning a threat report like this one into an expected loss figure a board or a binding decision can actually use is a good part of what we work on at DeNexus.
The report closes on a note worth ending on here too. ENISA states its purpose is "to enable informed decision-making and prioritization to safeguard our critical infrastructure" [1]. The data makes clear where that prioritization should start: at the exposed interface, not at the next headline-grabbing malware name.
This post is the compliance-and-underwriting companion to our October walkthrough of the ENISA Threat Landscape 2025 findings, which covers the threat detail in full. For how ENISA's OT findings map to specific attack techniques step by step, see Inside One MITRE ATT&CK for ICS Attack Path, our companion piece on the FrostyGoop/Modbus incident. For the underlying survey data on how these intrusions typically begin, see our analysis of SANS's ICS/OT attack vector survey data. And for the readiness question this all comes back to, whether you would actually catch one of these intrusions in time, see How to Assess OT Cybersecurity Maturity, including how a NIS2-driven regulatory push should factor into your maturity roadmap. NIS2's technical alignment with IEC 62443 is covered in our IEC 62443 Learn article and glossary.
ENISA tells you where the attack surface is. NIS2 tells you what you're obligated to do about it. Neither tells you what a significant incident would actually cost you, which controls measurably reduce that number, or how much residual risk you're carrying into a renewal conversation.
The DeRISK Platform quantifies OT cyber risk in financial terms — Expected Annual Loss, Value at Risk, and loss exceedance curves — so operators can prioritise the controls that reduce exposure, and risk assumers can underwrite to evidence rather than to a questionnaire.
References
[1] European Union Agency for Cybersecurity (ENISA). ENISA Threat Landscape 2025. v1.2, Jan. 2026, www.enisa.europa.eu/sites/default/files/2026-01/ENISA%20Threat%20Landscape%202025_v1.2.pdf.
[2] European Commission. "Proposal for a Targeted Amendment to Directive (EU) 2022/2555 (NIS2)." 20 Jan. 2026, https://digital-strategy.ec.europa.eu/en/library/proposal-directive-regards-simplification-measures-and-alignment-cybersecurity-act.
[3] IBM Security. Cost of a Data Breach Report 2024. Ponemon Institute, 2024, www.ibm.com/reports/data-breach.
[4] Siemens / Aberdeen Strategy & Research. The True Cost of Downtime 2024. Siemens Digital Industries Software, 2024. https://assets.new.siemens.com/siemens/assets/api/uuid:1b43afb5-2d07-47f7-9eb7-893fe7d0bc59/TCOD-2024_original.pdf
[5] e2e-assure. OT Security Review 2026. Censuswide research, Jan. 2026. https://newsbywire.com/e2e-assure-finds-80-of-cni-organisations-face-up-to-5m-in-ot-downtime-costs-from-cyberattacks/
[6] Munich Re. "Cyber Insurance: Risks and Trends 2026." Munich Re Insights, 2026, www.munichre.com/en/insights/cyber/cyber-insurance-risks-and-trends-2026.html.
[7] Artemis.bm. "Beazley's PoleStar Re Ltd. Cyber Catastrophe Bond Series." Artemis, Dec. 2025, www.artemis.bm.
[8] KELA Cyber Intelligence Center. “Infrastructure Destruction Squad & BLACKNET-00: The Rise of a Hybrid Hacktivist-Ransomware Threat.” Updated 6 July 2026. https://www.kelacyber.com/blog/blacknet-00-infrastructure-destruction-squad-ransomware/
[9] Cyble. “Hacktivist Attacks on Critical Infrastructure Grow as New Groups Emerge.” 11 July 2025. https://cyble.com/blog/hacktivists-attacks-on-critical-infrastructure/
[10] Forescout Research – Vedere Labs. “RDP Security: CPS Threats Spark Need for Secure Remote Access.” 28 April 2026. https://www.forescout.com/blog/rdp-security-cps-threats-spark-need-for-secure-remote-access/
[11] European Commission. “Commission Refers Ireland, Spain, France and the Netherlands to the Court of Justice for Failing to Transpose the Rules on Cybersecurity.” 8 July 2026. https://digital-strategy.ec.europa.eu/en/news/commission-refers-ireland-spain-france-and-netherlands-court-justice-failing-transpose-rules
[12] European Union. Directive (EU) 2022/2555 on Measures for a High Common Level of Cybersecurity Across the Union, Articles 20–23 and 34. Official Journal of the European Union, 27 December 2022. https://eur-lex.europa.eu/eli/dir/2022/2555/oj
[13] S&P Global Ratings. “Cyber Insurance Market Outlook 2026: Resilient Earnings, Tougher Competition, Pockets of Growth.” 9 December 2025.
[14] Munich Re. “Global Cyber Risk and Insurance Survey 2026,” including the accompanying Cyber Market Premium Estimation 2026. 22 April 2026.
[15] Munich Re. “Cyber Insurance: ‘The Market Will Double Every Five Years.’” Interview with Jürgen Reinhart. 15 July 2026.