Publications

Featured publications

NIS Investments 2025

The annual NIS Investments report presents the findings of a study conducted by ENISA to explore how cybersecurity policy translates in practice across organisations in the EU and its effects on their investments, resources, and operations.

ENISA Threat Landscape 2025

Through a more threat-centric approach and further contextual analysis, this latest edition of the ENISA Threat Landscape analyses 4875 incidents over a period spanning from 1 July 2024 to 30 June 2025. At its core, this report provides an…

NIS2 Technical Implementation Guidance

This report provides technical guidance to support the implementation of the NIS2 Directive for several types of entities in the NIS2 digital infrastructure, ICT service management and digital providers sectors. The cybersecurity requirements for…

All publications

Publish Date

Consumerization of IT: Final report on Risk Mitigation Strategies and Good Practices

This report presents security policies that can be deployed to mitigate risks that are related with the trend of Consumerization of IT (COIT) and Bring Your Own Device (BYOD). The aim of this document is to identify mitigation strategies,…

Implementation of Art 15: Security breaches notifications in trust services

The European Commission proposed on July 2012 a draft regulation on electronic identification and trust services for electronic transactions in the internal market, which will replace the existing Electronic Signature Directive 1999/93/EC.…

Cyber Europe 2012 - Key Findings Report

Cyber Europe was the biggest pan-European cyber security exercise to date. This report gives the key findings from ENISA.

National Cyber Security Strategies: An Implementation Guide

This report introduces a set of concrete actions, which if implemented will lead to a coherent and holistic national cyber-security strategy. It also proposes a national cyber-security strategy lifecycle, with a special emphasis on the…

Implementation of article 15

E-Government services have significant potential to make public services more efficient for the benefit of citizens and businesses in terms of time and money. And while these benefits are increasingly being felt nationally, e-Government services…

Be Aware, Be Secure. Synthesis of the results of the first European Cyber Security Month

The report provides a synthesis of the results of the European Cyber Security Month (ECSM) which took place as a pilot project across Europe throughout last October 2012. The report gives an overview of the security-related weeks organised at…

Baseline Capabilities of n/g CERTs - Updated Recommendations 2012

This document lists updated set of recommendations on gaps and shortcomings identified in the Status Report 2012. The number of gaps and shortcomings that still need to be addresssed in order for n/g CERTs to fully meet their baseline…

Deployment of Baseline Capabilities of n/g CERTs - Status Report 2012

This document will familiarise the reader with the current situation in Europe with regards to the n/g CERTs' capabilities, and how these capabilities are deployed.

EISAS Large-Scale Pilot - Collaborative Awareness Raising for EU Citizens & SMEs

To continually raise the level of cyber security awareness of all citizens and businesses, the European Commission decided to promote a collaborative approach for awareness raising in Europe. Introduced in 2006, EISAS, the European Information…

Report on 7th ENISA CERT Workshop

ENISA and Europol organised jointly the 7th annual CERT Workshop, Part II, as a follow up event to the very successful 6th Annual CERT workshop1 held last year in Prague, Czech Republic. This year the workshop was held at the Europol premises in…