With the digitalisation of the workplace, organisations and their employees must navigate and manage the digital risks.
Initially launched by ENISA in 2012, the European Cybersecurity Month (ECSM) is now driven by EU Member States as well as public and private organisations across Europe. However, ENISA continues to support the ECSM campaign together with the European Commission to promote cybersecurity among EU citizens and organisations.
Is the workplace cybersecure? The new ENISA threat landscape report, based on the analysis of more than 8000 events, draws the list of the main threats across all sectors of the economy. 73% of targeted organisations are essential and important entities as per the NIS2 definition. The most targeted sector remains public administration in 32% of cases. Other targeted sectors include business services (8%), transport (8%), manufacturing (7%) and finance/ banking (6%).
The last ENISA threat landscape sheds the light on such threats:
-
Scammers still resorting to social engineering. Users' trust is abused particularly through phishing campaigns and the ClickFix technique.
-
Ransomware operators still disrupting organisations across multiple sectors, through encryption, data theft, and extortion-based operations.
-
Cybercrime remained a main threat across the EU and globally during the reporting period, covering 36% of total cyber incidents. In 2025, the most recorded financially motivated activities included ransomware deployment for 40% of all analysed events, followed by data breaches for 31% of events and fraud and impersonation making the third largest category with 19%.
-
Fraud being facilitated thanks to compromised data and credentials. Sites such as Baiting News Sites (BNS) are designed to attract and deceive individuals promising easy profits. They look credible and legitimate.
-
We still observe an increasing use of AI by malicious cyber threat groups, primarily to facilitate or enhance their activities. For example, AI systems are used by Information Manipulation actors to sharpen their operations. AI-enabled foreign information manipulation and interference (FIMI) campaigns rose from 41 to 147 in a single year, equivalent to a 259% increase.
The Eurobarometer survey of the European Commission on employee's cybersecurity awareness and preparedness give us some answers on the level of exposure of cybersecurity risks at the workplace and looks at practices of employees across the EU.
ENISA engages in skills development and provides tools to support both organisations and individuals in their endeavours to strengthen their cybersecurity resilience.
Why an EU barometer survey on cybersecurity at the workplace?
Cybersecurity threats at work suffer widespread exposure. Over the 6 months prior to the survey, three quarters of employees had been exposed to suspicious emails, messages or links at work. The EU barometer survey measured how employees perceived cyber risks, how aware they are of threats targeting them such as phishing, fraud, identity misuse, ransomware and AI generated scams.
The survey aimed to assess employees' capacity to identify and to report suspicious activities and incidents. Survey questions also intended to showcase whether organisations have security measures in place including rules, reporting channels and their capacity to engage in awareness or training activities.
What are the key figures of the survey?
- While only 18% of employees report no incident at all in their organisation, 74% declare having received suspicious emails, text or vocal messages, or links.
- Phishing remains the most widespread threat, but employees report other malicious attempts as well: 39% declare having received phishing or fraudulent emails followed by attempts to steal personal data for 18%. Reported incidents include malware attacks, attempts to steal password, AI-generated scams, ransomware, etc.
- 83% consider that the consequences of a cyberattack would be serious for their organisation.
- 82% rate the digital systems and tools of their organisation as effective against cyberattacks.
- Cybersecurity is widely recognised as important - by employees even more than by their management but most employees think the organisation is effective in protecting against cyberattacks.
- Only 45% report that their organisation sends regular information or cybersecurity awareness updates.
- Around half of organisations have key cybersecurity measures in place, and a quarter plan to adopt them.
Are employees skilled enough and how do organisations invest in training?
Protecting organisations against cyber incidents means improving cybersecurity awareness and preparedness of the workforce. To do so, upskilling is the inevitable way forward.
According to the survey however, the strong demand for cyber skills faces a number of obstacles.
These include:
- finding the time in the workplace for 26% of employees who responded to the survey,
- expensive costs for 16%,
- followed by lack of information on training and lack of support from employers.
However, 85% of employees surveyed are interested in improving skills.
How does ENISA support awareness raising and skills development?
- Awareness Raising-in-a-Box
AR-in-a-Box is a comprehensive solution for cybersecurity awareness activities designed to meet the needs of public bodies, operators of essential services, and both large and small private companies. It provides theoretical and practical knowledge on how to design and implement effective cybersecurity awareness programmes.
- The European Cybersecurity Skills Framework (ECSF)
ENISA developed the ECSF. Formalised through the EU Cybersecurity Skills Academy, it serves as the common reference framework to be used for defining and assessing cybersecurity roles and skills in the EU. The framework is foreseen to help organisations better meet the demands of industry in terms of training and recruitment.
- The Cybersecurity Higher Education Database (CyberHEAD)
CyberHEAD is the largest publicly accessible online repository of higher education programmes in cybersecurity. Updated on a regular basis, the online repository is designed for prospective learners and cybersecurity professionals who seek relevant academic programmes offered by Higher Education Institutions. It is an essential tool as it serves as a central resource available to everyone.
- The Cyber Education Tool
This tool is meant to build children’s cybersecurity literacy. It acts as a central hub for cybersecurity educational resources and is tailored for primary and secondary schools in each Member State, to develop a cybersecurity mindset and build cybersecurity skills foundations from as early as possible.
- Cybersecurity challenges and other exercises
ENISA also designs and organises challenges, trainings and exercises which are essential to develop cybersecurity skills as extensively as possible. The European Cybersecurity Challenge (ECSC) is an annual competition that brings together young cybersecurity talents from across Europe to compete and showcase their skills will be held in Bochum, Germany from 12-16 October 2026.
- Three in four EU employees faced cyber threats at work, new Eurobarometer finds
- Digital Decade 2026 – Special Eurobarometer
- European citizens and the ‘digital decade’ in 2026 - infographics
- ENISA Threat Landscape Report 2026
- AR-in-a-Box | ENISA
- Raising Awareness (Campaigns) | ENISA
- Cyber Hygiene | ENISA
- Cyber Incident Awareness | ENISA
- Education and career path | ENISA