Insight · 4 Aug 2026 · 7 min
ENISA still puts phishing at ~60% of initial access. That should change your spend.
The ENISA Threat Landscape 2025 analysed 4,875 incidents. Ransomware remains the most damaging crime. Phishing is still how most of it starts.

ENISA's Threat Landscape 2025 (July 2024–June 2025, 4,875 incidents) is not a hype report. Phishing — including vishing, malspam, and malvertising — accounts for about 60% of observed initial access. Vulnerability exploitation is second at 21.3%. Ransomware is named the most impactful cybercrime threat in the EU.
For a Namibian or regional operator the lesson is not 'buy more email gateways.' It is: identity and people-controls are the control plane. MFA that users cannot bypass, mailbox rules that get reviewed, and a verification procedure for payment changes will remove more incidents than a sixth dashboard.
Phishing-as-a-Service lowered the skill bar. AI-assisted copy made lures less embarrassing. Your awareness programme has to be drills, not an annual video. Simulate, measure click-to-report time, and fix the mailboxes that fail — then repeat.
If you only fund one thing after reading ENISA, fund phishing-resistant MFA on admins, finance, and anyone who can move money. Then fund a tested backup. Ransomware is what happens after the phish works.
