TL;DR: ENISA’s 2025 threat landscape analysis of 5,000 incidents shows phishing remains a dominant initial access path, DDoS accounts for more than 75% of incidents, and ransomware plus AI-supported attacks are reshaping adversary behaviour across Europe, according to Semgrep. The security shift is from reactive controls to intelligence-driven resilience, where attacker convergence and automation matter as much as raw volume.
NHIMG editorial — based on content published by Semgrep: ENISA threat landscape 2025 analysis
By the numbers:
- ENISA analysed 5,000 incidents across the European Union for its 2025 threat landscape.
- DDoS attacks make up more than 75% of all incidents in the report.
Questions worth separating out
Q: How should security teams reduce phishing risk in high-value access paths?
A: They should replace phishable MFA methods on privileged and remote access routes with phishing-resistant authentication that binds the factor to the device or certificate chain.
Q: Why do DDoS and ransomware require joint resilience planning?
A: Because both attacks are designed to create operational pressure, just through different mechanisms.
Q: What do security teams get wrong about AI-assisted investigations?
A: They assume the model is the main value.
Practitioner guidance
- Harden initial access controls against human-targeted attack paths Prioritise phishing-resistant authentication, strong email and domain protections, and user verification workflows for high-risk actions.
- Tie resilience planning to identity and access telemetry Correlate DDoS, ransomware, and authentication anomalies in the same operating view so diversion attacks do not hide privilege abuse.
- Consolidate campaign analysis across security domains Build a shared incident taxonomy that spans email, identity, cloud, endpoint, and SOC teams.
What's in the full article
Semgrep's full analysis covers the operational detail this post intentionally leaves for the source:
- ENISA's incident breakdown by attack category and sector, including the specific patterns behind the 5,000 cases
- The article's full discussion of state-linked activity, hacktivism, and financially motivated attack blending
- Examples of how AI is changing phishing research, campaign scale, and attacker efficiency
- The report context for budget planning and defensive prioritisation going into 2026
👉 Read Semgrep's analysis of ENISA's 2025 threat landscape →
ENISA threat landscape 2025: what do phishing, DDoS, and AI mean now?
Explore further
Phishing remains the most durable form of identity abuse because it attacks the human decision point before any control can fail. ENISA’s analysis reinforces that initial access is still heavily shaped by human trust, whether through email, voice, or social platforms. That means identity security cannot be treated as a post-login problem. The governing assumption that users can reliably spot malicious access attempts is still too weak for current attacker economics, and practitioners should design controls that assume human error will occur.
A question worth separating out:
Q: How do organisations know if threat intelligence is actually helping?
A: They should look for shorter time to block new patterns, fewer repeated incidents from the same campaign, and faster coordination between fraud, SOC, and compliance teams. If intelligence is not changing decisions or reducing exposure during peak traffic, it is reporting rather than defence.
👉 Read our full editorial: ENISA threat landscape 2025 shows phishing and DDoS convergence