Public Administration Remains in EU Cybersecurity Risk Zone Despite Progress

SECURITYPublic Administration Remains in EU Cybersecurity Risk Zone Despite Progress
- Advertisement -Translation agency in Poland – professional language servicesTranslation agency in Poland – professional language services

The European Union Agency for Cybersecurity has published the third edition of its ENISA NIS360 report, assessing the cyber resilience of sectors considered highly critical under the NIS2 Directive.

Although the report points to a general improvement in cybersecurity maturity across the European Union, progress remains too slow and uneven in several areas. Healthcare, railway and maritime transport, ICT service management, space, public administration, and drinking and wastewater services remain in the report’s “risk zone”, meaning their importance to society and the economy exceeds their current ability to manage cyber risks. (ENISA)

Public administration is of particular concern. It remains the EU’s most frequently targeted sector, while its overall cybersecurity maturity is assessed only as moderate. ENISA found that hacktivist activity accounted for almost 63% of incidents affecting public bodies, usually involving attempts to disrupt government websites and online services. Only around one-third of surveyed public administrations regularly conduct comprehensive security assessments of their systems.

Banking, energy and telecommunications among the most mature sectors

ENISA assesses sectors using two principal dimensions: criticality and maturity.

Criticality includes factors such as the level of digitalisation, dependence on interconnected systems and the potential social and economic consequences of a serious incident. Maturity covers governance, regulatory supervision, cyber-risk management, information sharing, security controls and operational preparedness, including incident response and business-continuity planning.

Banking, electricity and telecommunications remain among the sectors combining high criticality with high cybersecurity maturity. ENISA attributes their position partly to years of sector-specific regulation, strong supervision and greater management involvement in cyber-risk decisions. Trust services, financial market infrastructure and aviation also joined the highest-maturity group in the latest assessment.

According to Tomasz Dziedzic, chief technology officer at Linux Polska, the strongest sectors tend to have more experienced management teams and a corporate culture shaped by extensive regulatory requirements.

“The sectors receiving the highest cyber-resilience scores are distinguished by greater management involvement in risk-management activities and a higher level of competence in this area,” Dziedzic said.

“In the financial sector, one example is the DORA regulation, which imposes clearly defined IT-security requirements on institutions. These include comprehensive frameworks for managing risks and incidents, monitoring external ICT providers, testing operational resilience and exchanging information about threats.”

The EU’s Digital Operational Resilience Act requires financial entities to strengthen ICT risk management, incident reporting, resilience testing and oversight of third-party technology providers. ENISA said DORA compliance had helped make risk-management practices more structured and improve preparedness in parts of the financial sector. (ENISA)

Public administration needs greater operational support

ENISA defines the risk zone as covering sectors whose cyber maturity is below average in relation to their critical importance. In addition to public administration, the latest list includes healthcare, railways, maritime transport, ICT service management, space, and drinking and wastewater services.

The public sector has made only modest progress in operational preparedness, despite facing the greatest volume of attacks. ENISA said public institutions continue to differ significantly in their capabilities, staffing, resources and exposure to threats, making coordinated resilience-building more difficult. (ENISA)

Marek Najmajer, product director at Linux Polska, said the challenge was not limited to detecting vulnerabilities.

“Many institutions can identify vulnerabilities relatively quickly, but eliminating them and implementing patches often takes three months or longer because of limited resources,” Najmajer said.

“In practice, the gap between identifying a risk and actually reducing it remains too large. Another problem is the absence of a clear vulnerability hierarchy. Amid large numbers of alerts, formal approvals and updates addressing minor issues, it is easy to lose sight of vulnerabilities that could genuinely threaten the continuity of public services.”

ENISA similarly found that many public administrations identify vulnerabilities in real time or through scheduled checks but take more than three months to apply patches. Limited skills, inadequate budgets and dependence on legacy systems were among the principal reasons.

Najmajer argued that administrations should move away from reactive IT maintenance towards an observability-based model involving the continuous collection and correlation of logs, metrics, events and information about dependencies between systems.

Such an approach allows an organisation to see not only an isolated technical alert but also its potential impact on a particular public service, the required response priority and the underlying cause of the problem.

In practice, this means monitoring the entire service-delivery chain, including infrastructure, applications, databases, integrations, networks, user identities and third-party suppliers.

This is particularly important for public institutions because a technical failure can rapidly become a service disruption, preventing citizens from accessing official procedures, public benefits, government registers or communication channels.

Security assessments remain inconsistent

ENISA’s detailed assessment shows that risk-management practices within public administration are highly uneven.

Around half of surveyed institutions had limited or no formal cybersecurity policies, while a similar proportion lacked clearly defined security roles. In many cases, cybersecurity responsibilities continued to be treated primarily as a function of the IT department rather than a broader management responsibility.

Although many institutions assessed risks at least annually, one-quarter had no formal risk-treatment process. Around half identified and prioritised threats but did not maintain a formal risk register or apply mitigation measures systematically.

Only about 40% of the public administrations surveyed reported using proactive prevention and detection controls across all systems with continuous monitoring.

One-third did not organise cybersecurity awareness or cyber-hygiene programmes for employees, while approximately half provided no dedicated cybersecurity training for management. Incident-response and business-continuity plans were also tested less frequently than the cross-sector average, sometimes only following a major incident.

Skills and the changing threat landscape are major barriers

The rapidly changing threat landscape and the development of new technologies remain the biggest obstacles to improving public-sector cyber resilience.

According to the World Economic Forum’s Global Cybersecurity Outlook 2026, 67% of public-sector respondents identified the evolving threat environment and emerging technologies as a major resilience challenge. A lack of cybersecurity skills and expertise was cited by 57%, compared with 38% of private-sector respondents.

Sebastian Jaworski, vice-president of Linux Polska, said public administration had one of the lowest levels of management involvement and cybersecurity expertise among the sectors analysed by ENISA.

“One in three organisations has no structured strategy for developing management-level cybersecurity expertise, while approximately half do not provide management training covering threats and risk analysis,” Jaworski said.

“In addition to financial and staffing limitations, organisational culture is a problem. Public-sector bodies often have a high degree of bureaucracy. Attachment to existing procedures and technologies can lead to reluctance to introduce modern solutions, including cybersecurity tools. This is particularly visible at municipal and county level.”

ENISA noted that the NIS2 Directive primarily covers public administrations at central-government level, including ministries, national offices and agencies. Depending on the member state, the estimated number of covered entities ranges from slightly more than 100 to several thousand.

Member states may extend the rules to regional and local authorities, but their approaches vary considerably. Smaller administrations frequently have fewer financial resources and less specialist expertise, even though attacks against local government can have a direct effect on essential services used by citizens.

Delays affected NIS2 implementation across the EU

EU member states were required to transpose the NIS2 Directive into national law by 17 October 2024.

In May 2025, the European Commission issued reasoned opinions to 19 countries, including Poland, for failing to notify the full transposition of the directive. The list also included Germany, France, Spain, the Netherlands, Austria and several other member states.

Poland subsequently amended its Act on the National Cybersecurity System. The legislation was published on 2 March 2026 and entered into force on 3 April 2026.

Under the new rules, organisations meeting the criteria for essential or important entities must apply for inclusion in the national KSC register by 3 October 2026. The principal adaptation period ends on 3 April 2027.

By then, affected organisations will be required to implement measures including the appointment of contact persons, verification of staff eligibility where required and the introduction of an information-security management system.

Such a system should combine organisational and technical safeguards, risk-management procedures, incident-response rules and controls intended to reduce the likelihood of unauthorised access, service disruption or data loss.

Full implementation of NIS2 may improve the position of public administration in future ENISA assessments. The latest report nevertheless shows that regulation alone will not be sufficient. Institutions will also require skilled staff, adequate funding, stronger management involvement and the ability to translate identified vulnerabilities into timely remedial action.

Check out our other content
Related Articles
The Latest Articles