14.07.2026

CyberSec Update#28: ICT Sector Maturity – ENISA

How Mature Is the ICT Services and Products Sector in Terms of Cybersecurity?

ENISA (the European Union Agency for Cybersecurity), in its latest ENISA NIS360 report, assessed the cybersecurity maturity and criticality of highly critical sectors listed in Annex I to the NIS2 Directive. For the ICT services and products sector, the overall level of cybersecurity maturity was assessed as medium. The full report is available on the Agency’s website.

Delays in the Implementation of Guidelines

Approximately every second entity declares that it is aware of the available guidelines; however, it has either not familiarized itself with them in detail or has not taken any action based on their provisions. Some organizations point to difficulties in aligning the recommendations with existing cybersecurity solutions, while others emphasize staffing and organizational constraints.

Resource Shortages Hinder Risk Management

Across the sector, insufficient budget is considered one of the main barriers to the effective achievement of cybersecurity objectives. National authorities, however, also highlight other significant challenges, such as a shortage of qualified cybersecurity professionals and risks associated with cooperation with external suppliers.

Inconsistent Approach to Risk Management

Most surveyed entities declare that they conduct risk assessments at least once a year. Nevertheless, around half indicate that they do not have a formal process for managing identified risks or that, where such a process exists, risk mitigation measures are not always prioritized and implemented systematically.

Implementation of Security Measures Remains a Challenge

Entities in the ICT sector struggle primarily with the timely deployment of security patches, network segmentation, and data protection. Financial constraints and the widespread use of legacy systems are identified as the main causes of these challenges.

Concerns Regarding Security Assessment Processes

More than half of the surveyed entities in this sector indicated that they do not conduct regular security assessments or perform them only to a limited extent or on an ad hoc basis. According to ENISA, this is a cause for concern, particularly given that many entities in this sector act as providers of services and solutions to organizations operating in other sectors of the economy.

Uneven Preparedness for Incident Response and Recovery

Across the sector, the level of preparedness for incident response and recovery remains inconsistent. A significant number of organizations report insufficient readiness to handle cyberattacks resulting from supply chain threats or causing disruptions in IT and OT environments.

Approximately half of the ICT sector entities declare that their incident response procedures are tested only to a limited extent or are activated only after an incident has occurred.

In turn, 37% of organizations admit that their Business Continuity Planning (BCP) and Disaster Recovery procedures are tested only to a limited extent or on a reactive basis.

1 58 59 60 61 62

Newsletter

Want to stay up to date?
Subscribe to our newsletter.

By entering your e-mail address above and clicking ‘Subscribe!’ you declare that you have read and accept the Terms of Service and subscribe to the newsletter, i.e. information on legal topics, including information on important legal events, legislative changes and the Law Firm's activities, services and products, via e-mail communication.

The controller of your personal data is KWKR Konieczny Wierzbicki i Partnerzy S.K.A. with its registered office in Kraków, Kącik 4 Street, 30-549 Kraków. Your data will be processed in order to provide the newsletter service and thus send commercial and marketing information to the e-mail address provided, in accordance with the Privacy Policy and the Terms of Service. For more information on the principles of personal data processing, including your rights, please see the Privacy Policy.

Please wait...

Thank you for sign up!