CyberSec Update #34: ENISA on the energy sector
In CyberSec Update #11, I discussed the energy sector incident that took place on 29 December last year. The repercussions of this event are still being felt, and CERT Poland has recently published an update to its incident report. More details are available here: CERT Poland report update.
This provides a good opportunity to revisit the assessment of cybersecurity maturity and criticality within the energy sector presented by the European Union Agency for Cybersecurity (ENISA) in its recently published ENISA NIS360 report.
In CyberSec Update #28, we looked at the report’s evaluation of the ICT services and products market. This time, it is worth focusing on the energy sector, which has long been considered one of the most critical areas of infrastructure from a cybersecurity perspective.
Electricity Subsector Leads the Way
In the ENISA report, the energy sector is divided into three subsectors: electricity, gas, and oil. The electricity subsector received the highest assessment, particularly in terms of cybersecurity awareness.
According to ENISA, this is partly due to the implementation of additional sector-specific requirements introduced under the Network Code on Cybersecurity for Electricity (NC CS), which complements the requirements of the NIS2 Directive for the electricity sector.
Another noteworthy finding is that organisations operating in the electricity subsector reported a significantly higher prevalence of management teams holding formal cybersecurity qualifications and participating in regular cybersecurity training programmes.
Entities in the electricity sector also tend to achieve stronger results in asset monitoring, vulnerability management, access control, and network segmentation. Nevertheless, ENISA indicates that there is still room for further improvement.
The Gas Sector Is Catching Up
The ENISA report identifies a clear trend towards higher cybersecurity maturity within the gas subsector, bringing it closer to the level achieved by the electricity sector.
However, outdated infrastructure remains one of the main challenges facing the gas industry. According to ENISA, legacy systems make it difficult to move beyond a moderate level of cybersecurity maturity and also slow the implementation of more advanced asset management solutions.
Oil Sector Shows Lower Maturity
As one of the reasons for the lower maturity level observed in the oil subsector compared to electricity and gas, ENISA points to the more limited availability of dedicated cybersecurity guidance and sector-specific frameworks.
According to the Agency, this contributes to the slower development of cybersecurity practices and governance mechanisms across the oil industry.
The Energy Sector Under the Polish Cybersecurity Framework
Annex No. 1 to the Polish Act on the National Cybersecurity System, which contains the list of key sectors, extends beyond the energy subsectors analysed by ENISA.
Under the Polish cybersecurity framework, the energy sector also includes entities operating in mining and extraction, heating, nuclear energy, and hydrogen. This reflects a broader understanding of the role cybersecurity plays in ensuring the resilience of the economy and critical infrastructure.





