Key Takeaways

  • Public administration, transport, digital infrastructure, finance, and manufacturing remain prominent cyber targets.
  • Operational technology exposure is turning cybersecurity into a continuity and public-safety issue.
  • Governments can strengthen resilience through enforceable baselines, faster remediation, incident reporting, intelligence sharing, and tested recovery plans.

Cyberattacks against governments and critical infrastructure are becoming less of an isolated IT concern and more of an operational risk spanning public services, industrial systems, and national economies. The latest figures show why policymakers and business leaders are placing greater emphasis on resilience, not simply prevention.

The ENISA Threat Landscape 2025 analyzed 4,875 incidents recorded between July 2024 and June 2025. Public administration, transport, digital infrastructure, finance, and manufacturing were among the most frequently targeted sectors. These are also deeply interconnected industries, meaning an incident at one operator can create consequences for customers, suppliers, and public agencies.

Essential entities covered by the EU’s NIS2 framework represented 53.7% of recorded incidents. That concentration supports closer oversight of critical operators and the technology suppliers serving them. It also raises a practical question: how far down the supply chain should security obligations extend?

Attackers rarely respect contractual boundaries. A vulnerable remote-access product, maintenance provider, or software component can offer a path into several organizations. Governments therefore have reason to consider supplier controls, vulnerability-disclosure processes, and procurement requirements alongside internal agency security.

Operational technology deserves particular attention. ENISA identified OT as 18.2% of tracked threat categories, highlighting exposure across industrial control systems used in energy, water, manufacturing, and transport. Unlike conventional enterprise IT, these environments can include equipment with long replacement cycles, limited tolerance for downtime, and older protocols that were not designed for hostile networks.

Patching an office application and updating a production controller are not equivalent jobs. Industrial changes may require safety reviews, vendor approval, scheduled outages, and physical access. Security policies that overlook those constraints can look strong on paper while producing little measurable improvement.

Ransomware remained the most impactful cybercrime threat in ENISA’s 2025 assessment. Meanwhile, hacktivist campaigns increasingly relied on distributed denial-of-service attacks against public-facing government services. Earlier ENISA findings provide additional context: public administration accounted for 38% of EU incidents observed during 2024, central governments represented 69% of those incidents, and DDoS attacks made up 60%.

Those figures point to two overlapping challenges. Ransomware can interrupt internal operations, encrypt systems, and place sensitive data at risk. DDoS campaigns can deny citizens access to websites and digital services, sometimes during politically sensitive periods. One attack seeks leverage; the other seeks visibility and disruption. Agencies need response plans for both.

A structured approach can help. The NIST Cybersecurity Framework 2.0 organizes security activity around governance, identification, protection, detection, response, and recovery. For public bodies and regulated operators, its governance emphasis can clarify who owns cyber risk, how executives receive information, and which services receive priority during restoration.

The European Commission’s NIS2 Directive provides a complementary regulatory model for essential and important entities. Its broader significance lies in treating cybersecurity as an executive and operational responsibility rather than leaving it solely with technical teams. That said, compliance reporting should not become a substitute for testing whether services can actually continue during an incident.

Practical controls include asset inventories, network segmentation, multifactor authentication, offline or otherwise protected backups, rapid remediation of internet-facing vulnerabilities, and defined incident-reporting channels. OT environments may also benefit from passive monitoring and specialized tools such as Microsoft Defender for IoT or Dragos’ threat-intelligence and incident-response platform. Technology selection, however, should follow a clear understanding of operational assets and risk.

Cross-sector intelligence sharing is also essential. Attack indicators observed by one transport operator may be relevant to energy providers or government agencies using the same supplier. Sharing arrangements can shorten detection times, but information needs to reach the people who can act on it. A long report delivered after an attack campaign has moved on offers limited value.

Finally, continuity plans need rehearsal. Tabletop exercises, backup restoration tests, manual operating procedures, and communication drills can expose gaps before a real crisis. Cyber resilience is not about assuming every attack can be blocked. It is about reducing the chance that a compromised account, overloaded website, or infected workstation becomes a prolonged failure of essential services.