NIS360: The bigger picture on maturity and criticality of NIS critical sectors

This year’s edition of the ENISA NIS360 report shows improvement in cybersecurity maturity of EU critical sectors while the level of criticality in sectors remains comparatively more stable.
The ENISA NIS360 aims to work as an annual assessment tool supporting national authorities, policymakers and other stakeholders in assessing the cybersecurity maturity and criticality of high criticality sectors under the NIS2 Directive.
ENISA Executive Director, Juhan Lepassaar, said: “The findings of this NIS360 report provide grounds to be optimistic. The implementation of the comprehensive EU cybersecurity regulatory framework, and particularly NIS2, has brought significant improvements. ENISA stands for prioritising cybersecurity and advancing the implementation of EU policies, which are vital now more than ever, to enhance the cyber resilience of our critical infrastructure and societies.”.
The report has a comprehensive approach, where each sector is understood to comprise relevant actors (i.e., national authorities, entities, EU bodies) and applicable rules (EU legislation). In this regard, a sector’s maturity under the NIS360 is determined by: legislation and its effectiveness, companies and their preparedness, authorities and their institutional capacity, and sectoral ecosystem structures and their effectiveness.
The assessment relies on a structured methodology developed and continuously refined by ENISA that takes into account the structural and gradually evolving nature of sectoral cybersecurity maturity and criticality. It also builds on evidence gathered over time from organisations operating within the in-scope sectors, national authorities supervising those organisations, but also EU-level data, to reflect our latest evidence-informed understanding of where each sector stands.
As a result, the NIS360 provides both a comparative overview of sectors and a more detailed analysis per sector to help identify gaps and prioritise resources.
Defining the Risk Zone
NIS360 sector risk zone
A combination and joint interpretation of the criticality and maturity dimensions helps identify areas where mismatches exist between the two and define a risk zone.
The risk zone includes sectors with lower-than-average maturity and criticality that exceeds their maturity. This year’s risk zone includes health, railway, maritime, ICT management service, space, public administrations, drinking and waste water.
Its composition changes over time as overall maturity improves across sectors. This explains why three sectors — railway, drinking water, and waste water — previously at the risk zone boundary, are now within the risk zone. A positive development is that the gas sector has started moving out of the risk zone.
Such shift is driven by improved information sharing, stronger collaboration, and better implementation of risk management measures, leading to higher maturity.
Deep-dive on criticality
While criticality of the sectors is defined by NIS2, the NIS360 assessment ranks the sectors taking into account several elements, such as systemic relevance, exposure, and impact of disruption. As these factors typically change gradually, criticality scores tend to remain relatively stable from year to year.
In this year’s edition, sectors such as banking, electricity, aviation, space, and digital-by-default services (including telecommunications, cloud, and data centres) remain the most critical.
Space has joined this group this year, reflecting its growing role in society and across other sectors, which increases dependency, impact, and time criticality. The railway sector increased in criticality due to its growing role in military logistics, and the heightened cyber threat exposure.
Spotlight on maturity 
Maturity is measured by how effectively and consistently the sector manages cybersecurity risks and capabilities over time, meaning the overall preparedness of the sector. Since the previous edition of this report, cybersecurity maturity across EU critical sectors seems to be steadily improving as organisations respond to the evolving policy requirements and to the cyber threats they face.
Three sectors, including trust services, aviation, and financial market infrastructures (FMIs) moved into the high maturity band. In addition, four sectors strengthened their maturity within the moderate band: gas, road, maritime, and health.
This improvement is often driven by several compounding factors including developments in cybersecurity legislation, increased political attention, but also progress across specific maturity dimensions assessed. Particularly, on cybersecurity legislation, findings of the 2025 ENISA NIS Investments study also suggest that it has acted as a key driver for cybersecurity investment and has encouraged organisations to strengthen their cybersecurity posture.
Despite maturity steadily improving across critical sectors, progress still remains uneven both across and within sectors. A number of factors contribute to these variations including skill shortages, sector-specific characteristics and even organisational size.
Moving forward
In the future, it is anticipated that cybersecurity legislation and organisations’ efforts to strengthen their cybersecurity maturity will continue to prompt cybersecurity investment and drive preparedness, leading to more sectors moving out of the risk zone.

Euro-Mediterranean partners advance cooperation on civil protection and disaster risk management

Representatives from across the Euro-Mediterranean region gathered this week for the Union for the Mediterranean (UfM) Civil Protection Meeting to advance regional cooperation on disaster risk management and support the implementation of the 2030 UfM Action Plan on Civil Protection and Disaster Risk Management.
The meeting brought together representatives from UfM Member States, the European Commission’s Directorate-General for European Civil Protection and Humanitarian Aid Operations (DG ECHO), the Prevention, Preparedness and Response to Natural and Man-made Disasters in the Mediterranean programme (PPRD Med), the International Federation of Red Cross and Red Crescent Societies (IFRC), and the United Nations Office for Disaster Risk Reduction (UNDRR). Discussions focused on strengthening regional collaboration on prevention, preparedness, response and recovery in the face of increasingly complex and interconnected risks across the Mediterranean region.
Advancing a shared vision for regional resilience
Participants reviewed recent progress under the UfM Civil Protection and Disaster Risk Management mandate and discussed priorities for strengthening regional cooperation through the UfM Regional Dialogue Platform.
The meeting highlighted key elements of the 2030 UfM Action Plan, including:
- Strengthening public awareness and volunteer engagement
- Enhancing preparedness through capacity development
- Supporting regional disaster assistance and cooperation
- Strengthening national and regional institutions
- Promoting monitoring, evaluation and learning
Discussions emphasized the importance of creating a common culture of risk awareness and resilience, while supporting closer cooperation among governments, civil society, technical institutions, and regional partners.
Strengthening preparedness and knowledge exchange
Participants shared experiences and initiatives aimed at strengthening preparedness and operational readiness across the Mediterranean region.
Discussions highlighted the importance of investing in prevention and preparedness, particularly as countries across the region face increasingly complex and interconnected risks, including wildfires, floods, earthquakes, and climate-related hazards.
Key areas of discussion included:
- Lessons from the 3rd Euro-Mediterranean High-Level Workshop on Fire Risks
- Volunteering and community engagement in disaster risk management
- Early warning systems and information sharing
- Capacity development and training opportunities
- Regional platforms for cooperation and knowledge exchange
Participants also explored opportunities to strengthen collaboration among civil protection authorities and regional partners, while advancing practical approaches to preparedness, information sharing, and mutual support across the Mediterranean.
Building momentum for regional action
UNDRR presented the Stop Disaster Game initiative (an educational tool that helps users better understand disaster risks and resilience-building measures) as an example of innovative approaches to strengthen disaster risk awareness and preparedness.
Participants further discussed opportunities to leverage regional platforms and initiatives, including UfM Med Green Week, to promote collaboration and strengthen engagement on disaster risk reduction and climate resilience.
Looking ahead
The meeting concluded with a shared commitment to continue advancing the implementation of the 2030 UfM Action Plan and strengthening cooperation among Euro-Mediterranean partners.
As countries across the region face increasing risks from wildfires, floods, earthquakes, droughts and other climate-related hazards, continued efforts to strengthen cooperation, preparedness, and operational coordination will help lay the foundations for a more resilient and interconnected Mediterranean.

Next-generation geospatial models to support coastal risk insurance and risk mitigation

Coastal risks such as storm surges, erosion and the impacts of rising sea levels are escalating, impacting millions of homes and high-value assets. At the same time, the combination of this potential high impact with unpredictability is leaving some areas uninsurable. With the support of ESA's Business Applications and Space Solutions (BASS), UK-based Ocean Ledger has developed as a solution a next-generation coastal surge model to improve accuracy, transparency, and nuance for insurance risk exposure management.
Digital Elevation Models (DEMs) are essential for understanding and managing coastal risks. Existing models are however often static, may rely on outdated bathymetric or shoreline elevation data or are too coarse to capture localised coastal dynamics, which limits their value for risk assessment and operational decision-making.
Ocean Ledger is addressing the gaps in coastal risk data used in DEMs by integrating multiple sources of satellite Earth observation data, delivering a market-ready geospatial service that provides high-value insights for the insurance and climate resilience sectors, while supporting broader economic and societal protection against climate-driven hazards.
“The specific problem being addressed by Ocean Ledger is the absence of frequently updated, spatially granular and environmentally realistic elevation models which are suitable for integration into risk and insurance models,” explained Ocean Ledger CEO Paige Roepers.
In contrast to existing models, Ocean Ledger takes an observation-driven approach, effectively creating a digital twin of the coastline by using standardised satellite-derived topography workflows for shoreline elevation, shoreline position, vegetation and bathymetry. Their hazard model can be used in comparison to other models and to inform risk reduction strategies for those that own and operate assets.
“Through our project with ESA’s Business Applications and Space Solutions (BASS) team, we have been improving our DEMs, making them more accurate with the latest coastline elevation data and historical trend analysis. This allows us to make better predictions and offer more up-to-date insights than others,” says Ms Roepers. “With that, we can provide more transparency to make confident decisions around risk selection and pricing in highly exposed areas.”
Reflecting on the value of taking part in an ESA BASS programme, Ms Roepers added: “Working with ESA BASS has been a catalyst for us, significantly accelerating both our technological road map and commercial traction. The funding has allowed us to transition from high-level research and development to actionable market entry.”
“Having the ESA brand and funding behind us has been an invaluable asset and has helped us achieve the letters of support we needed to carry out pilots. We are looking forward to hopefully start a Demonstration Project with ESA BASS soon, to continue our journey with ESA and to deliver those pilots that will then take us closer to commercial contracts across Europe and the US.”
ESA BASS Applications and Partnerships Officer Ana Raposo said: “It has been wonderful to support Ocean Ledger and see the opportunities they have been able to secure within the ESA BASS Kick-start framework. I look forward to seeing how their journey continues and they go on to capitalise on the springboard for success they have now built.”

Supply Chain Compromises Impact Nx Console and GitHub Repositories

CISA is prioritizing the response to multiple emerging software supply chain intrusion campaigns targeting developer ecosystems Continuous Integration/Continuous Development (CI/CD) pipelines. These recent incidents, including the GitHub compromise via a malicious Nx Console Visual Studio Code (VS Code) extension and the “Megalodon” supply chain intrusion campaign, demonstrate how cyber threat actors are abusing tools and processes that support enterprise, cloud, and DevOps environments—specifically CI/CD pipelines, code extensions and workflows.
Threat actors leveraged a prior compromise of Nx developer systems to compromise a GitHub employee’s device through a poisoned third-party VS Code extension, resulting in unauthorized access and exfiltration of internal GitHub repositories. The malicious extension version (18.95.0) was distributed through VS Code’s automatic update mechanism, meaning systems with Nx Console previously installed may have received the malicious build without developers taking any manual installation action. GitHub released a security advisory on this activity, and CVE-2026-48027 has been assigned to the malicious version of Nx Console and added to CISA’s Known Exploited Vulnerabilities (KEV) Catalog.
Additionally, in a campaign known as “Megalodon,” a cyber threat actor injected malicious GitHub Action workflows to harvest CI/CD secrets, cloud credentials, and tokens, impacting both development and deployment pipelines in public GitHub repositories.
CISA urges organizations to implement the following recommendations to detect and remediate a potential compromise:
- Monitor and audit workflow files and contributor activity for suspicious pull requests and direct commits, particularly those authored by automated accounts.
- Revert unauthorized changes, especially from automated accounts, e.g., build-bot, auto-ci, ci-bot, pipeline-bot and especially those made after May 18, 2026.
If your organization discovers a compromise resulting from previously compromised GitHub or Nx Console software, CISA recommends the following steps:
- Conduct a forensics review of CI/CD logs, cloud audit trails, and affected developer machines.
- Rotate/revoke all secrets including: all credentials, tokens, and secrets accessible to CI/CD pipelines, including API keys, cloud provider credentials (Amazon Web Services, Google Cloud Platform, Microsoft Azure), SSH keys, Docker/npm/PyPI/Vault/Terraform/Kubernetes tokens, GitHub/GitLab/Bitbucket tokens, and developer or pipeline secrets.
- Notify proper stakeholders if necessary.
CISA recommends the following best practices for using package repos:
- Wait at least three hours before pulling a new package. This gives the software community time to identify suspicious or malicious packages before they are widely downloaded.
- Pin software to specific trusted versions. Pinning software prevents pulling a malicious or unscreened package during the build process.
- Only pull packages from known and trusted sources. Relying on known and trusted sources reduces the likelihood of downloading a package that has been maliciously forked.

CISA, NCSC-UK and Partners Release Cybersecurity Advisory on Chinese Government-Linked Covert Networks

CISA and the United Kingdom’s National Cyber Security Centre, in collaboration with other federal and international partners, have released a cybersecurity advisory, Defending Against China-nexus Covert Networks of Compromised Devices, providing network defenders with vital tools and resources to combat the threat posed by Chinese government-linked threat actors’ use of covert networks of compromised devices.
The advisory outlines tactics, techniques, and procedures associated with Chinese government-linked covert networks built from compromised small-office-home-office routers, Internet of Things, and smart devices. It explains how threat actors leveraging these covert networks, including those previously tied to groups such as Volt Typhoon and Flax Typhoon, use large scale botnet infrastructure to obscure attribution and enable reconnaissance, intrusion, command-and-control, and data exfiltration.
The advisory provides tailored defensive guidance for cyber defenders to identify, baseline, and mitigate activity originating from dynamic, deniable covert networks to reduce the risk of organizational compromise.
CISA and partners recommend the following steps to protect against this threat:
• Map and understand network edge devices, developing a clear understanding of organizational assets and what should be connected to them.
• Baseline normal connections, especially to corporate VPNs or other similar devices.
• Maintain log collection and storage solutions to assist with detecting and responding to unauthorized access attempts.
• Implement multifactor authentication for remote connections.
For more information on Chinese government-linked threat actor activity, please visit CISA's China Threat Overview and Advisories page.

OSCE promotes marine transport security and relevant Convention implementation

The OSCE Programme Office in Astana co-organized a practical seminar on inspection of higher educational institutions and maritime training centres of Kazakhstan in co-operation with the Committee of Railway and Water Transport of the Ministry of Transport and with the support of the Kazakhstan Maritime Academy of the Kazakh-British Technical University. The main goal of the seminar was to strengthen oversight of inspection and accreditation of higher educational institutions and maritime training centres in Kazakhstan, in line with the International Convention on Standards of Training, Certification, and Watchkeeping for Seafarers (STCW).
Maritime safety begins long before a vessel leaves port, it starts in the classroom, where future seafarers are trained to meet international standards. The STCW sets globally accepted minimum standards for the training, certification, and competence of seafarers, ensuring that ships are operated safely worldwide. Before STCW, standards varied widely between countries, creating risks to maritime safety and uneven levels of crew competence. The Convention also plays a key role in protecting the marine environment, as competent seafarers are better equipped to prevent pollution and respond effectively to environmental emergencies.
The seminar focused on the strict STCW requirements governing seafarer training, including curriculum development, teaching methodologies, assessment processes, and institutional facilities. Participants gained a comprehensive understanding of how inspections are conducted, the methodologies used for evaluation, and the specific criteria applied during accreditation.
Through in-depth discussions and practical guidance delivered by an international expert, the seminar helped to identify areas for improvement and support the Ministry’s efforts to modernize and adapt its national framework, where needed. This initiative represents an important step toward modernizing national inspection systems, strengthening compliance with international standards, and enhancing maritime safety and environmental protection.

CISA Helps Johnny Secure Operational Technology: New Guidance Addresses Cyber Risks from Legacy Protocols

CISA released the guidance Barriers to Secure OT Communication: Why Johnny Can’t Authenticate. This guidance highlights the known issues with insecure-by-design legacy industrial protocols and seeks to understand why the technology to secure these protocols is not widely adopted. CISA developed this guidance in partnership with operational technology (OT) equipment manufacturers and standard development organizations, by interviewing OT asset owners and operators to understand:
1. What motivates owners and operators to secure communication, and
2. What barriers prevent successful adoption from design through deployment and operations.
Legacy OT protocols lack strong protections against data alteration, device impersonation, and unauthorized access, making critical infrastructure vulnerable to cyber threats. Securing these protocols requires solutions that are practical for current operators as well as cyber experts. Based on the research conducted, CISA provides recommendations for how owners and operators can avoid the negative experiences of their peers, as well as recommendations to OT manufacturers to drive sustainable, more usable capabilities.
For OT Owners and Operators:
• Learn why message signing is the foundation for secure OT communication and when encryption is essential.
• Discover practical strategies for phased adoption of secure protocols to minimize operational risk.
• Identify which OT communications should be prioritized for enhanced security and resilience.
• Explore ways to simplify secure workflows and key management for easier implementation.
For Manufacturers:
• Gain insights from customer research to reduce customer friction and deliver more usable, secure products.
• Explore actionable recommendations to address cost and complexity barriers to secure communication.
• Learn how usability metrics like deployment time and ease of integration can differentiate your solutions and accelerate adoption.
CISA encourages critical infrastructure organizations and OT manufacturers to review and implement the recommendations in this guidance.

Ignitis Gamyba Allocates €1.1 Million in Humanitarian Aid for Ukraine’s Critical Infrastructure

From September 2024 to this October, Ignitis Gamyba allocated €1.1 million in humanitarian aid to support the restoration of Ukraine’s war‑damaged energy infrastructure. According to the European Commission, this is the largest logistical operation it has ever coordinated.
In just over a year, 145 lorries loaded with equipment were dispatched from the Vilnius TE‑3 Combined Heat and Power Plant. According to the company’s calculations, a total of 2,681 tonnes of equipment have been allocated for humanitarian aid.
“In this challenging period, as Ukraine experiences continued russian aggression and the destruction of its energy infrastructure, we remain firmly committed to supporting the Ukrainian people. Lithuania’s initiative to relocate a full thermal power plant, with a combined heat and electricity capacity of nearly 1,000 MW, to Ukraine through the EU Civil Protection Mechanism is a powerful example of solidarity and cooperation. A thermal power plant of this size can provide heating for approximately half of Vilnius households. This support is necessary to rebuild the energy sector, which is vital to the daily lives of Ukrainians. I am sincerely grateful to all the countries, companies and institutions involved in this massive project. This operation only became possible through the efforts of all of our partners,” says Minister of Energy Žygimantas Vaičiūnas.
The principal activities of Ignitis Gamyba’s TE‑3 were suspended in 2015 due to high operating costs and an assessment that operation of the power units would not have a significant impact on the stability of the electric power system.
“For more than 30 years, this power plant provided heating for roughly half of Vilnius households. Now it is no longer being used, but the equipment we preserved and kept operational was able to contribute to restoring vital functions in Ukraine,” said Ignitis Group CEO Darius Maikštėnas.
The transfer of equipment was officially confirmed on 15 July 2024, following the signing of a support agreement between Ignitis Gamyba and the electricity distribution network operator in Ukraine. For security reasons, more detailed information about the aid being provided, including the exact names of the equipment as well as the power plants it will be going to, cannot be disclosed.

Poland Energy Sector Cyber Incident Highlights OT and ICS Security Gaps

In December 2025, a malicious cyber actor(s) targeted and compromised operational technology (OT) and industrial control systems (ICS) in Poland’s Energy Sector—specifically renewable energy plants, a combined heat and power plant, and a manufacturing sector company—in a cyber incident. The malicious cyber activity highlights the need for critical infrastructure entities with vulnerable edge devices to act now to strengthen their cybersecurity posture against cyber threat activities targeting OT and ICS.
A malicious cyber actor(s) gained initial access in this incident through vulnerable internet-facing edge devices, subsequently deploying wiper malware and causing damage to remote terminal units (RTUs). The malicious cyber activity caused loss of view and control between facilities and distribution system operators, destroyed data on human machine interfaces (HMIs), and corrupted system firmware on OT devices. While the affected renewable energy systems continued production, the system operator could not control or monitor them according to their intended design.
CERT Polska’s incident report highlights:
- Vulnerable edge devices remain a prime target for threat actors.
  - As indicated by CISA’s Binding Operational Directive (BOD) 26-02: Mitigating Risk From End-of-Support Edge Devices, end-of-support edge devices pose significant risks.
- OT devices without firmware verification can be permanently damaged.
  - Operators should prioritize updates that allow firmware verification when available; if updates are not immediately feasible, ensure that cyber incident response plans account for inoperative OT devices to mitigate prolonged outages.
- Threat actors leveraged default credentials, a vulnerability not limited to specific vendors, to pivot onto the HMI and RTUs.
  - Operators should immediately change default passwords and establish requirements for integrators or OT suppliers to enforce password changes in the future.
CISA and the Department of Energy’s Office of Cybersecurity, Energy Security, and Emergency Response (DOE CESER) urge OT asset owners and operators to review the following resources for more information about the malicious activity and mitigations:
- CERT Polska’s Energy Sector Incident Report - 29 December 2025.
- CISA’s joint fact sheet with FBI, EPA, and DOE Primary Mitigations to Reduce Cyber Threats to Operational Technology.
- DOE’s Energy Threat Analysis Center’s threat advisories.

€113 million in EU funding allocated to strengthen the resilience of Baltic and Polish electricity grids

The European Commission has allocated €113 million in funding from Connecting Europe Facility (CEF) for critical Synchronisation infrastructure protection implemented by the transmission system operators of Lithuania, Estonia, Latvia and Poland. The implementation of wider range of projects aimed at ensuring energy security against potential cyber and physical threats began on February 9 last year, following the successful synchronization of the Baltic States with the Continental European electricity network.
“Having successfully completed the synchronization project, the Baltic States and Poland continue to invest in energy independence and security. We are grateful to the European Commission for supporting our ambition to make the Baltic Sea region a model for strengthening the security and resilience of critical energy infrastructure across Europe. This funding is the result of our consistent efforts and sets a new precedent, as until now the European Union had no dedicated financing for the protection of critical energy infrastructure. By consistently applying the lessons learned from Ukrainian energy specialists, we are expanding the scope of protection for our critical energy infrastructure projects. We plan to apply for further funding for resilience projects and are actively working to ensure that a long-term EU-level instrument for financing critical energy infrastructure protection is established,” – said Žygimantas Vaičiūnas, Minister of Energy of the Republic of Lithuania.
The protection of critical energy infrastructure is being financed on the EU level for the first time. These possibilities have been empowered due to the implementation of the synchronization project by the Baltic States and Poland. Lithuania together with Estonia, Latvia and Poland is targeting the long-term legal and financial instruments for the financing of the critical energy infrastructure within the EU. Currently the legal instruments are under review, it is expected and the efforts are pursued the initiative to be properly aligned also during the negotiations of Multiannual Financial Framework for 2028-2034.
“We launched the resilience programme just over a year ago, and we have already made significant progress in many areas: we have procured and are installing drone neutralization solutions, implemented initial protection measures for substation equipment, designed and prepared to build physical barriers – materials for which were tested at Lithuanian Armed Forces training grounds – and introduced measures to ensure rapid restoration of damaged infrastructure. We continue to raise the level of cybersecurity. By sharing information and insights with partners in the Baltic States and Poland, working with universities and security experts, and learning from Ukraine’s experience, we are constantly looking for ways to supplement and improve existing solutions,” said Litgrid CEO Rokas Masiulis.
The critical infrastructure protection projects implemented by the Baltic and Polish transmission system operators – Litgrid, AST, Elering, and PSE – as part of the Baltic synchronization effort will be financed through the Connecting Europe Facility (CEF).
The projects will receive up to the maximum possible co financing rate of 50% of eligible costs. Funding for projects in Lithuania amounts to €22 million.
Litgrid’s energy infrastructure resilience programme includes strengthening the physical protection of critical facilities, establishing emergency and crisis reserves for transmission network equipment, installing electronic security systems, deploying unmanned aerial vehicle detection and neutralization systems, enhancing perimeter protection, and preparing to operate under critical conditions.
Litgrid is implementing 13 projects under the resilience programme, comprising more than 150 measures deployed across various transmission network facilities. The programme is continuously reviewed based on threat assessments and new technological solutions.
On February 8, 2025, the Baltic States disconnected from the Russia controlled IPS/UPS electricity system, and on February 9 successfully synchronized their electricity systems with the Continental European synchronous area. Synchronization with Continental Europe enables the Baltic States to operate their electricity systems in close cooperation with other Continental European countries, ensuring stable and reliable frequency regulation, thereby strengthening energy independence and enhancing energy security across the region. The Baltic States joined the Continental European network, which serves more than 400 million consumers in 26 countries.
1 2 3 4 59