Ransomware is the cyber threat with the biggest impact in the EU
A report by the European agency Enisa finds that ransomware is the threat with the biggest short-term impact in the Union, and that 57% of the incidents analysed were driven by ideological motives.

Ransomware remains the cyber threat with the biggest short-term impact in the European Union. That is the conclusion of a report by the European Union Agency for Cybersecurity, Enisa. The agency looked at a set of incidents and found that 57% of them were driven by ideological motives. Attacks are no longer only an economic activity. More and more often they are a tool of conflict.
A market worth 206 billion
Spending is growing under that pressure. MarketsandMarkets, cited by CorCom, puts the market for critical infrastructure security at 160.28 billion dollars in 2026 and 206.31 billion in 2031. That works out to a compound annual growth rate of 5.2% from 2025, when the figure stood at 153.87 billion. Telecommunications is the most dynamic segment, growing 7.4% a year. Lockheed Martin and Thales are its main players, in a sector now going through consolidation.
The Italian case: OT under attack
For Italy the most worrying figure does not concern the big operators. It concerns the manufacturing base. A whitepaper produced by a cybersecurity company and taken up by CorCom indicates that 90% of Italian manufacturing companies suffered at least one cyber incident in the last year. The events range from ransomware and denial-of-service attacks to industrial espionage and physical tampering with automation systems. Those are the OT systems that run production, and they were often not designed to be exposed to the network.
The document identifies three structural problems. The first is the difficulty of assessing risks precisely. The second is the regulatory and organisational constraints that slow down interventions. The third is a mainly reactive approach, in which security is strengthened after the incident rather than before. The document adds a point that is not trivial: the lack of specialised staff in OT security is one of the main obstacles even when budgets and willingness are there.
"The industrial perimeter is today the weak point of the chain, because a plant standing still costs more than any ransom," is the message that emerges from the two documents.
The countermeasure indicated is organisational before technological: segment factory networks, inventory connected assets, define recovery plans tested periodically and train production staff, not only IT staff.
Sources
3- 01ANSA — Enisa: ransomware minaccia cyber con il maggiore impatto a breve termine in UeIT
- 02CorCom — Infrastrutture critiche: il mercato della sicurezza varrà 206 miliardi nel 2031IT
- 03CorCom — OT sotto attacco: la cybersecurity è la sfida urgente per il manifatturiero italianoIT
All figures and quotations in this text come from the sources listed below.
Content prepared by the editorial team with AI assistance.
Comments
0- No comments yet — be the first.