The EU Cybersecurity Index 2024
THE
EU-Cybersecurity
2024
Index
EU-level insights and next steps CONTACT
For contacting the authors please use security-index@enisa.europa.eu For media enquiries about this paper, please use press@enisa.europa.eu.
AUTHORS
ENISA
LEGAL NOTICE
This publication represents the views and interpretations of ENISA, unless stated otherwise. It does not endorse a regulatory obligation of ENISA or of ENISA bodies pursuant to the Regulation (EU) No 2019/881. ENISA has the right to alter, update or remove the publication or any of its contents. It is intended for information purposes only and it must be accessible free of charge. All references to it or its use as a whole or partially must contain ENISA as its source. Third-party sources are quoted as appropriate. ENISA is not responsible or liable for the content of the external sources including external websites referenced in this publication. Neither ENISA nor any person acting on its behalf is responsible for the use that might be made of the information contained in this publication. ENISA maintains its intellectual property rights in relation to this publication.
COPYRIGHT NOTICE
© European Union Agency for Cybersecurity (ENISA), 2025 Unless otherwise noted, the reuse of this document is authorised under the Creative Commons Attribution 4.0 International (CC BY 4.0) licence (https://creativecommons.org/ licenses/by/4.0/). This means that reuse is allowed, provided appropriate credit is given and any changes are indicated. For any use or reproduction of elements that are not owned by the European Union Agency for Cybersecurity, permission may need to be sought directly from the respective rightholders.
Catalogue number: TP-01-25-018-EN-N
ISBN: 978-92-9204-713-9
DOI: 10.2824/7714867
INTRODUCTION
The EU Cybersecurity Index (EU-CSI) is a tool, developed by Disclaimer: ENISA in collaboration with the Member States, to describe The data collection for the 2024 EU-CSI took place in a perithe cybersecurity posture of Member States and the EU. od before October 2024, e.g. the deadline of the transposition of the Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (“NIS2 Di- The intent of this publication is two-fold: rective”). We acknowledge that this is likely to lead to observations and results that may not reflect the respective status • Presenting key EU-level insights of the 2024 EU Cyberafter the transposition of this Directive. security Index (EU-CSI), which have been used, among other sources, to conduct the analysis of the first Report on the State of Cybersecurity in the Union published in December 2024. This publication only refers to EU-level data. National • Accounting for the work that ENISA and the Member data has limited disclosure. States have been carrying out, while setting the basis for the next edition of the EU-CSI in 2026.
WHAT IS THE EU NEXT CYBERSECURITY STEPS INDEX?
As per above, the EU-CSI is a tool to describe the cybersecu- The EU-CSI is developed and implemented by ENISA in colrity posture of Member States and the EU. Making the most laboration with Member States, as represented in the ENISA of the available data and information, the EU-CSI provides National Liaison Officers (NLO) Network according to the insights on the respective cybersecurity maturity and capa- guidelines and recommendations in the OECD/JRC’s handbilities while helping detect opportunities for peer-learn- book on constructing composite indicators . ing between Member States. It also serves as basis for the ENISA and the Member States are currently working to further quantitative and qualitative assessment of the level of marefine the EU-CSI to reflect the lessons learnt from 2024 and to turity of cybersecurity capabilities and resources across the integrate the feed-back received by Member States. Feed-back Union stipulated in the Article 18 of the NIS2 Directive. has been sought also through a public consultation. The EU-CSI is a composite index, with a hierarchical structure. Simplifying as much as possible , it comprises a set In particular, for the next edition, the current structure of qualitative and quantitative indicators that are scaled to would be simplified by optimising the list of indicators and a score from 0 to 100. These indicators, and their respec- the way how they are calculated, with further improvement tive scores, are grouped into cybersecurity areas that score of data sources and further alignment of the EU-CSI to the from 0 to 100. In turn, these areas, and their respective NIS2 Directive. scores, are grouped into a single overall score up to 100. The further refinement of the EU-CSI is part of the contin- An index score quantifies multidimensional concepts that uous effort to improve the available knowledge on the cycannot be measured directly, by integrating multiple factors bersecurity posture MS, which is essential to achieve a high into a single value. 0 is the lowest score: it means that for common level of cybersecurity across the Union and to supa specific indicator or an area the EU is achieving subopti- port the EU and Member States to increase their cybersecumal results. 100 is the highest score: it means that for that rity capabilities. specific indicator or an area the EU is achieving very good results . The data included in the EU-CSI were collected from the relevant authorities in the Member States, data reported to ENISA per applicable legal frameworks such as incident reporting, the Cybersecurity Threat Landscape report of ENI- SA, and from other publications of ENISA and the European Commission. The EU-CSI is a biennial index, which, in the current form, started in 2024. Accordingly, while the data have been collected in 2024, in some cases, where recent data were not available, older data sources were used. The next edition of the EU-CSI will be run in 2026.
Key insights EU-CYBERSECURITY INDEX IN 2024 The overall index value for the EU is 62.65 (out of 100). Almost all Member States score within 10.00 units of the EU average. The average deviation from the EU average is 3.76 units, indicating a general alignment across the Union in the indicators considered. The Member States’ overall index score deviations range from a minimum of q13.18 units below the EU average to a maximum of p7.45 units above the EU average. Capacity prevent EU AVG Market / EU AVG 64.51 62.36
The cybersecurity capacity area, which measures the abil- The cybersecurity market/industry area, which measures ity of society to recognise threats and prevent cybersecurity the private sector’s ability to prevent, detect, and analyse incidents score 64.51. The majority of Member States score cyber threats, score 62.36. Notably, all 27 EU Member States within a 10-point range of the EU average. The average devi- showing scores fell within a 10-point range of the EU averation of Member States’ scores from the EU average is 4.73 age. The average deviation of Member States’ scores from points, ranging from a minimum of q14.29 units to a max- the EU average is 2.78 points, ranging from a minimum of imum of p11.42 units. q7.06 units to a maximum of p7.54 units. The market/industry area exhibits the strongest alignment across the
EU compared to the other index areas.
Operations ensure EU AVG Policy EU AVG 57.63 66.09
The cybersecurity operations area, which measures Mem- The cybersecurity policy area, which measures the state ber States’ ability to conduct cybersecurity operations and of cybersecurity policy development and implementation, ensure resilience, score 57.63, falling below the overall in- attained the highest EU average score compared to the dex value. Despite this, a high degree of consistency is ob- other index areas, at 66.09. Despite this, it exhibits the lowserved among Member States, with the majority of Member est level of alignment among Member States, indicating States scoring within 10 points pf the EU average. The aver- significant variability, in particular with regards to vulneraage deviation of Member States’ scores from the EU average bility disclosure and supervisory measures for essential and is 6.24 units, ranging from a minimum of q11.72 units to a important entities. The average deviation of Member States’ maximum of p15.14 units. scores from the EU average is 9.45 units, ranging from a minimum of q27.28 units to a maximum of p17.45 units.
TOP-SCORING INDICATORS In the reporting period, Member States demonstrate high convergence in areas with the highest EU average scores. Specifically, the five indicators with the highest EU average score exhibit low average deviation. 2.42 10.93 98.02 93.83 Source MAXIMUM Source MAXIMUM
Most SMEs in the EU did not experience incidents leading Likewise, the large enterprises in EU that did not experito disclosure of confidential data (e.g. due to intrusion, ence incidents leading to disclosure of confidential data pharming, phishing, actions by own employees intentionally (e.g. due to intrusion, pharming, phishing, actions by own or unintentionally) with an average score of 98.02 units and, employees intentionally or unintentionally) demonstrate a an average deviation of 0.79 units. The minimum deviation high average score of 93.83, with Member State deviations is q2.42 units, whereas the maximum one is p1.28 units. averaging 2.81 units. These deviations range from a minimum of q10.93 to a maximum of p5.17 units.
Incidents - MINIMUM MINIMUM EU AVG presence EU AVG 94.99 Source 97.62 Source MAXIMUM MAXIMUM Eurostat 3.41 2.38
Similarly, the EU exhibits a high score of 94.99 for SMEs that The score for the indicator measuring CSIRTs in EU Member did not experience incidents leading to destruction or cor- States being FIRST members and TI listed/accredited/cerruption of data (e.g. due to infection of malicious software tified is 97.62, with an average deviation of 2.87 units. This or unauthorized intrusion, hardware or software failures), indicates that all Member States show score within a narrow with MS deviations averaging 1.22 units. The minimum de- range (within 10 units) of the EU average. The country with viation is q3.79 units and the maximum one is p3.41 units. the lowest value deviates from the EU average by q7.62 However, the high scores for the above indicators may be units and the country with highest value deviates by p2.38 inflated due to underreporting of security incidents by en- units. terprises, particularly SMEs, stemming from limited awareness, fear of reputational damage, or complex reporting requirements.
MINIMUM 7.36 u 93.29 Source MAXIMUM
This indicator refers to the way users in the EU behave when they use internet. The EU average for this indicator is at 93.29 units, while Member States exhibit an average deviation of 2.69 units. The minimum deviation is q7.36 units, while the maximum is p5.69 units.
LEAST-SCORING INDICATORS The five indicators with the lowest EU average score in the reporting period, designating areas for improvement are the following. 3.18 7.14 Source MAXIMUM Source MAXIMUM
Most of the enterprises in the EU do not utilise AI technol- Similarly, there is potential for increase in the cybersecuriogies for ICT security, with the relevant indicator showing ty investments by essential/important entities as part of an average score of 3.18. This low score is consistent across their overall IT budgets/spending. The EU average score Member States, with all 27 falling within 10.00 units of the for this indicator is 7.14, with an average deviation of 0.54, EU average and demonstrating an average deviation of ranging from a minimum of q1.24 units to a maximum of 1.67 units. The country with the lowest value deviates by p1.46 units. q2.78 units, while the country with highest value deviates by p7.22 units.
CSIRT(s) MINIMUM MINIMUM certification 10.31 24.93 EU AVG funding EU AVG MAXIMUM MAXIMUM 27.19 30.90
The EU average score for CSIRT(s) certification is also low The indicator measuring the distribution of EU R&D fundat 10.31. The average deviation is 10.58 units, with a mini- ing awarded per country related to cybersecurity also mum deviation of q10.31 units and a maximum deviation reflects relatively low performance, with an EU average of of p27.19 units. These results underscore the need for tar- 24.93 units and an average deviation of 13.19 units. The geted efforts to improve both the score for this indicator minimum deviation is q24.93 units, while the maximum and the alignment among Member States. deviation reaches p30.90 units.
MINIMUM 26.89 32.01 Source MAXIMUM
Likewise, the indicator measuring enterprises conducting cybersecurity risk assessment has an average value of 32.01, with an average deviation of 9.76. The maximum deviation reaches p26.89, while the minimum deviation is q21.31.
ABOUT ENISA
The European Union Agency for Cybersecurity, ENISA, is the Union’s agency dedicated to achieving a high common level of cybersecurity across Europe. Established in 2004 and strengthened by the EU Cybersecurity Act, the European Union Agency for Cybersecurity contributes to EU cyber policy, enhances the trustworthiness of ICT products, services and processes with cybersecurity certification schemes, cooperates with Member States and EU bodies, and helps Europe prepare for the cyber challenges of tomorrow. Through knowledge sharing, capacity building and awareness raising, the Agency works together with its key stakeholders to strengthen trust in the connected economy, to boost resilience of the Union’s infrastructure, and, ultimately, to keep Europe’s society and citizens digitally secure. More information about ENISA and its work can be found here: www.enisa.europa.eu.
ENISA
European Union Agency for Cybersecurity
Athens Office
Agamemnonos 14 Chalandri 15231, Attiki, Greece
Heraklion Office
95 Nikolaou Plastira 700 13 Vassilika Vouton, Heraklion, Greece
Brussels Office
Rue de la Loi 107 1049 Brussels, Belgium
enisa.europa.eu
Fotnoter
- THE EU-CYBERSECURITY INDEX 2024: EU-LEVEL INSIGHTS AND NEXT STEPS
- THE EU-CYBERSECURITY INDEX 2024: EU-LEVEL INSIGHTS AND NEXT STEPS
- THE EU-CYBERSECURITY INDEX 2024: EU-LEVEL INSIGHTS AND NEXT STEPS
- 1 A more detailed explanation can be found in the methodological note here: https://www.enisa.europa.eu/topics/state-of-cybersecurity-in-the-eu 2 More on the use of indexes to measure cybersecurity in OECD (2024), “New perspectives on measuring cybersecurity”, OECD 3 https://www.oecd.org/en/publications/handbook-on-con- Digital Economy Papers, No. 366, OECD Publishing, Paris, https:// structing-composite-indicators-methodology-and-usdoi.org/10.1787/b1e31997-en er-guide_9789264043466-en.html
- THE EU-CYBERSECURITY INDEX 2024: EU-LEVEL INSIGHTS AND NEXT STEPS
- This area This area describes the describes the ability of the ability of society private sector to to recognise 23 27 prevent, detect, threats and and analyse
- cyber threats incidents. Industry and incidents.
- This area This area describes the describes the ability of a MS state of policy to carry out 23 13 development operations to and
- implementation. resilience.
- THE EU-CYBERSECURITY INDEX 2024: EU-LEVEL INSIGHTS AND NEXT STEPS
- SMEs: Security MINIMUM Large enterprises: MINIMUM Incidents - Security Incidents
- Disclosure of EU AVG - Disclosure of EU AVG
- confidential data confidential data
- Eurostat 1.28 Eurostat 5.17
- SMEs: Security CSIRTs
- Destruction 3.79 7.62
- or corruption of data
- ENISA - CSIRTs
- by country map
- Citizens: secure
- internet use EU AVG
- Eurobarometer 5.69 u
- THE EU-CYBERSECURITY INDEX 2024: EU-LEVEL INSIGHTS AND NEXT STEPS
- Enterprises using MINIMUM MINIMUM investments by
- AI technologies 2.78 1.24 EU AVG essential/important EU AVG
- for ICT security entities
- Eurostat 7.22 ENISA-NIS 1.46
- Investments Report
- EU R&D
- Source 10.31 Source 24.93
- ENISA - CSIRTs EC - Horizon
- by country map Dashboard
- Enterprises: risk
- assessment EU AVG
- Eurostat 21.31