























News |
By Asma Adhimi
Cybersecurity maturity is improving across Europe’s critical infrastructure sectors, according to the latest NIS360 report from the European Union Agency for Cybersecurity (ENISA). The annual assessment shows that sectors covered by the NIS2 Directive are becoming better prepared against cyber threats, although some high-risk areas continue to lag behind.
The report also highlights that while cybersecurity maturity is progressing steadily, the criticality of key sectors remains largely unchanged due to their growing importance to society and the economy. For eeNews Europe readers working in infrastructure, telecoms, industrial systems, and embedded technologies, the findings provide a useful snapshot of where cybersecurity investments and regulatory pressure are having the biggest impact — and where vulnerabilities still remain.
ENISA’s NIS360 report is designed as an annual benchmarking tool for policymakers, national authorities, and organisations operating in critical sectors. It assesses sectors based on legislation, preparedness of companies, institutional capabilities, and the effectiveness of sector-wide cybersecurity structures.
This year’s report identifies several sectors that remain within what ENISA calls the “risk zone” — areas where cybersecurity maturity falls below the level required by their criticality. These include healthcare, railways, maritime transport, ICT management services, space, public administration, and water utilities.
The railway, drinking water, and wastewater sectors have now moved fully into the risk zone after previously sitting near the boundary. At the same time, the gas sector is showing signs of improvement and beginning to move out of the category.
According to ENISA, stronger collaboration, increased information sharing, and wider adoption of risk management measures are helping sectors improve their cybersecurity readiness.
ENISA Executive Director, Juhan Lepassaar, said: “The findings of this NIS360 report provide grounds to be optimistic. The implementation of the comprehensive EU cybersecurity regulatory framework, and particularly NIS2, has brought significant improvements. ENISA stands for prioritising cybersecurity and advancing the implementation of EU policies, which are vital now more than ever, to enhance the cyber resilience of our critical infrastructure and societies.”
The report notes that banking, electricity, aviation, and digital infrastructure services such as telecoms, cloud platforms, and data centres remain among the most critical sectors in Europe.
One notable change this year is the addition of the space sector to the highest criticality group. ENISA said the increasing dependence of other sectors on satellite and space-based services has raised concerns around disruption impact and operational dependency.
Railways also saw a rise in criticality, partly due to their expanding role in military logistics and greater exposure to cyber threats.
On the maturity side, trust services, aviation, and financial market infrastructures moved into the highest maturity category. Other sectors including gas, maritime, road transport, and healthcare improved within the moderate maturity band.
ENISA said cybersecurity legislation continues to be a major driver for investment and preparedness improvements, although progress remains uneven due to factors such as skills shortages, sector-specific challenges, and organisational size differences.
The agency expects continued regulatory pressure and ongoing cybersecurity investment to gradually move more sectors out of the risk zone in the coming years.
If you enjoyed this article, you will like the following ones: don't miss them by subscribing to :
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。