- What: ENISA report on cybersecurity improvements in EU critical sectors
- Impact: Highlights uneven progress and areas needing improvement
Critical Infrastructure Security ENISA NIS360 2026 report shows uneven cybersecurity improvements across EU critical sectors June 2, 2026 Share By SC Staff (Adobe Stock) As reported by Security Affairs, the third annual ENISA NIS360 report reveals that while cybersecurity maturity is generally improving across European Union critical sectors, the progress is uneven and insufficient in key areas. The report assesses the cybersecurity landscape against the NIS2 directive, highlighting a growing gap between the evolving threat landscape and the pace of defensive improvements. The banking, electricity, and telecommunications sectors continue to lead in cybersecurity maturity and criticality. Notably, trust services, aviation, and financial market infrastructures have advanced to the high maturity band, with gas, road, maritime, and health sectors strengthening their positions in the moderate band. However, a significant concern is the "risk zone," comprising sectors where criticality outpaces maturity. This zone now includes health, railway, maritime, ICT service management, space, public administrations, and water sectors. Sectors like rail and water have entered this zone not due to regression, but because the overall maturity bar has risen. The report identifies AI, supply chain vulnerabilities, and geopolitical volatility as key dynamics reshaping the cybersecurity environment, making it harder for organizations to keep pace. The space sector, crucial for critical infrastructure, shows low maturity despite its increasing importance. Conversely, the finance sector demonstrates the impact of sustained regulatory pressure and enforcement, such as through DORA implementation. Source: Security Affairs SC Staff Related Supply chain Why supply chain attacks work and what detection can actually do about it Aaron Beardslee June 2, 2026 Here’s what to do in a world where credential theft has been automated and turned into a commodity. Government security Spanish police arrest individual in connection with data leak from state organizations SC Staff June 2, 2026 The arrested individual is accused of disseminating data from entities such as the State Attorney General's Office, INCIBE, the National Police, the Civil Guard, and the National Security Council. Critical Infrastructure Security AI-powered threats target 2026 election communications SC Staff June 1, 2026 The report highlights a significant trend where threat actors are leveraging artificial intelligence (AI) to amplify the scale and effectiveness of their attacks. Related Events Cybercast From code to cloud: Stopping attacks in the software supply chain On-Demand Event Virtual Conference Securing the Backbone: Strategies to Counter Cyber Threats to Critical Infrastructure in the Public Sector On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe You can skip this ad in 5 seconds