CyberSec Update#28: ICT Sector Maturity – ENISA
How Mature Is the ICT Services and Products Sector in Terms of Cybersecurity?
ENISA (the European Union Agency for Cybersecurity), in its latest ENISA NIS360 report, assessed the cybersecurity maturity and criticality of highly critical sectors listed in Annex I to the NIS2 Directive. For the ICT services and products sector, the overall level of cybersecurity maturity was assessed as medium. The full report is available on the Agency’s website.
Delays in the Implementation of Guidelines
Approximately every second entity declares that it is aware of the available guidelines; however, it has either not familiarized itself with them in detail or has not taken any action based on their provisions. Some organizations point to difficulties in aligning the recommendations with existing cybersecurity solutions, while others emphasize staffing and organizational constraints.
Resource Shortages Hinder Risk Management
Across the sector, insufficient budget is considered one of the main barriers to the effective achievement of cybersecurity objectives. National authorities, however, also highlight other significant challenges, such as a shortage of qualified cybersecurity professionals and risks associated with cooperation with external suppliers.
Inconsistent Approach to Risk Management
Most surveyed entities declare that they conduct risk assessments at least once a year. Nevertheless, around half indicate that they do not have a formal process for managing identified risks or that, where such a process exists, risk mitigation measures are not always prioritized and implemented systematically.
Implementation of Security Measures Remains a Challenge
Entities in the ICT sector struggle primarily with the timely deployment of security patches, network segmentation, and data protection. Financial constraints and the widespread use of legacy systems are identified as the main causes of these challenges.
Concerns Regarding Security Assessment Processes
More than half of the surveyed entities in this sector indicated that they do not conduct regular security assessments or perform them only to a limited extent or on an ad hoc basis. According to ENISA, this is a cause for concern, particularly given that many entities in this sector act as providers of services and solutions to organizations operating in other sectors of the economy.
Uneven Preparedness for Incident Response and Recovery
Across the sector, the level of preparedness for incident response and recovery remains inconsistent. A significant number of organizations report insufficient readiness to handle cyberattacks resulting from supply chain threats or causing disruptions in IT and OT environments.
Approximately half of the ICT sector entities declare that their incident response procedures are tested only to a limited extent or are activated only after an incident has occurred.
In turn, 37% of organizations admit that their Business Continuity Planning (BCP) and Disaster Recovery procedures are tested only to a limited extent or on a reactive basis.




