ENISA’s latest NIS360 assessment highlights that cybersecurity maturity continues to improve across Europe’s critical sectors, but progress remains uneven. While industries such as banking, telecommunications, and electricity have strengthened their cybersecurity capabilities, several essential sectors continue to face significant challenges in keeping pace with increasingly sophisticated threats. The report evaluates maturity across governance, preparedness, regulatory effectiveness, and sector-wide cooperation.

Particular concern remains around sectors considered highly critical but insufficiently mature from a cybersecurity perspective. According to the report, healthcare, railway systems, maritime transport, public administration, ICT service management, and drinking and wastewater services remain areas where cyber resilience falls below the level warranted by their societal importance. Disruptions in these sectors could have wide-ranging consequences beyond a single organization.

For CISOs, the findings reinforce the importance of looking beyond technical controls and focusing on broader resilience capabilities. Strong governance structures, sector-wide information sharing, incident preparedness, and supply-chain visibility increasingly determine how effectively organizations can withstand cyber incidents. Security leaders should assess whether current programs align with both industry threats and the expectations emerging from NIS2 implementation.
 
The report also demonstrates that cybersecurity maturity is becoming a strategic benchmark across Europe. CISOs can use these findings to support investment discussions, prioritize risk reduction initiatives, and benchmark their organizations against sector-wide trends. As regulatory scrutiny increases, understanding where an organization stands relative to its peers is becoming an important component of cyber resilience planning.