ENISA's annual threat report for 2026: the most-quoted number in the coverage is misread
The ENISA press release of 22 September 2026 presents the agency's annual threat report for 2026, analysed are incidents from 1 January to 31 December 2025, gathered from open sources and from member-state reports. We looked at the primary page ourselves on 29 September because the follow-up coverage passes around a number with a different denominator than the one on ENISA's page. Both need sorting, since the original version is the more useful finding.
The number with the wrong denominator
The coverage ran with: 60 per cent of unauthorised access happened through known vulnerabilities. On the ENISA page the sentence carries its own restriction: among the incidents where ENISA could identify an intrusion vector, and those are 5 per cent of the incidents, 60 per cent used a vulnerability. Read correctly the number says two things. First: where the route in was known, it almost always was a vulnerability. Second, and that is the worse finding: for 95 per cent of incidents the entry route stayed unknown. A security strategy that only bets on patching covers the identifiable share and says nothing about the rest.
What else is in the report
Ransomware remains the type of incident with the strongest short-term effect, encryption with data theft and extortion across sectors. Phishing stays the most common enabling tactic, with ClickFix a technique whose use ENISA says is increasing. Public administration is the most targeted sector; the report's sector split puts business services and the transport sector level behind it, followed by manufacturing and finance. The report counts just above 48,000 newly recorded vulnerabilities in the covered year, roughly a fifth more than before. Among low-impact incidents DDoS dominates, and hacktivist claims concentrate almost fully in that same technique. The report's AI sentence is an expectation, not a measurement: new models are expected to be used increasingly for malicious operations, the report does not measure this for 2025.
What it means for an Austrian company the day after the NISG started
The law has been in force since 1 October 2026, registration runs until 31 December through the company service portal. If the reporting duties make you build an inventory you would never have built otherwise, then ENISA's unknown-entry-route figure is the justification: an inventory that only knows systems which already had an incident is exactly the inventory that does not cover the 95 per cent. For our industry (logistics, and we see the transport sector recur in the report) the rest is unglamorous craft: the patch backlog is the vector that is identifiable, so patch discipline has to be run measurably. Reporting paths have to be rehearsed before the first real incident, 24 hours for the early warning and 72 for the full report is not a line spacing.
Further reading
Is it true that 60 per cent of all unauthorised access ran through known vulnerabilities?+
Not like that. ENISA writes: among the incidents where ENISA could identify an intrusion vector at all, 60 per cent used a vulnerability. That sentence applies to the 5 per cent of incidents with a known vector. Scaling it to all unauthorised access is an invention of the retelling, and it hides the actually uncomfortable number: for 95 per cent of incidents the entry route stayed unknown.
Which sectors does the report name as most targeted?+
Public administration first by clear distance, then business services and the transport sector, which sit level around second place in the report's count. The sector data come from the report the ENISA published as a whole.
What does this have to do with Austria's NISG?+
The report states 73 per cent of the addressed entities as entities required under NIS2 or ones that would fall under it. NIS2 in Austria is the NISG, in force since 1 October 2026, and if you belong to the transport industry you sit exactly where the report locates the hits.
senn-tech