It’s Not Just Who Will Attack. What Matters Is Whether We Will Be Ready.

Header Image

By Commissioner of Communications Marios Pieris

 

A few weeks ago, writing about the evolution of ransomware, I posed a simple question: as ransomware evolves, are we evolving too?

Today, I would like to take that question one step further. The more closely we monitor the modern cyber threat landscape, the clearer it becomes that we place disproportionate emphasis on the name of the attacker and not enough on the consequences an attack can cause.

Qilin. Akira. Play. DragonForce. INC Ransom. The Gentlemen.

Names that, a few years ago, would have been familiar mainly to a small circle of cybersecurity specialists. Today, they are part of a much larger, organised and constantly changing cybercrime ecosystem.

Some groups are growing stronger. Others are weakening or disappearing. New ones emerge. Partnerships are formed and dissolved. Tools, techniques and infrastructure change hands.

The European picture confirms this volatility. In the ENISA Threat Landscape 2025 report, covering the period from July 1, 2024, to June 30, 2025, 82 different ransomware variants targeting organisations in EU member states were recorded. The most prevalent was Akira (11.6%), followed by SafePay (10.1%) and Qilin (7.5%). None exceeded 12%, illustrating a fragmented rather than concentrated ecosystem.

It is worth noting something that is often overlooked. The number of recorded ransomware incidents in the European Union fell by 11% compared with the previous reporting period. That does not mean the risk has diminished. It means that the number of attacks, by itself, is the least useful indicator. What matters is impact, and impact has not declined.

Tomorrow, some of the names we know today may have disappeared. Others, currently unknown to us, may have taken their place.

That is precisely the point. Identifying perpetrators certainly matters for international cooperation, law enforcement and measures taken at the European level. It cannot, however, form the foundation of our defence.

We do not build resilience around whoever is attacking us today. We build it around what we cannot afford to lose tomorrow.

The threat does not have a single form

Public discussion about cybersecurity often focuses on the most dramatic attacks. A ransomware incident. A major data breach. A website taken offline.

In reality, today’s environment is far more complex. Ransomware, data breaches and theft, phishing, denial-of-service attacks, vulnerability exploitation and supply-chain attacks all have different starting points and different objectives. Yet they lead to the same outcome: operational disruption, financial damage and loss of trust.

ENISA identifies ransomware as the threat with the greatest impact on the European Union. At the same time, in cases where the initial intrusion method was identified, about 60% were linked to phishing, including malicious emails, telephone scams and malvertising, while vulnerability exploitation followed at 21.3%.

This reminds us of something fundamental: a major crisis can begin with something very small.

An email. A password. A vulnerability not patched in time. An external contractor. A click.

That is why cybersecurity can no longer be viewed solely as an effort to keep attackers out. It must equally address what happens if they ultimately succeed in getting in.

The question every organisation should be asking requires a change in mindset. Instead of asking only, “Who might attack us?”, we must ask much more difficult questions.

Which of our services must continue functioning no matter what happens? What data is absolutely critical? What are our most important third-party dependencies?

If a key system is unavailable tomorrow morning, who decides what gets restored first? Do our people know what they need to do?

Do we have backups and, more importantly, do we know we can actually restore them?

Do we have a crisis response plan, or merely a document that has never been tested? And how quickly can we return to an acceptable level of operation?

These are not technical questions. They are management questions.

Cybersecurity is not solely the responsibility of the IT department.

For many years, cybersecurity was treated primarily as a technical issue. Something for the IT department, firewalls, anti-malware software, passwords and specialists.

That era is over.

When a cyberattack can disrupt service delivery, affect employees, customers or citizens, expose data, cause financial loss and within hours evolve into a crisis of confidence, it ceases to be exclusively a technical matter. It becomes an issue of management, corporate governance and leadership.

The technical team will, of course, handle the incident. But who will decide which functions are restored first? Who will assess the operational impact? Who will communicate with employees, partners, customers or citizens?

Who will manage legal and regulatory obligations? And who will take responsibility for decisions that must be made quickly and under pressure?

That is why cyber resilience must begin at the top of an organisation and extend throughout its entire operation.

In Cyprus, this is no longer a recommendation. It is the law.

For Cyprus, NIS2 is not a future obligation. It was transposed into national law through Law 60(I)/2025, which extensively amended the Security of Network and Information Systems Law 89(I)/2020. The competent authority is the Digital Security Authority.

What does this mean in practice?

First, management responsibility is no longer a matter of good practice. The law imposes an explicit obligation on management bodies to approve risk-management measures, oversee their implementation and undergo training themselves. In cases of persistent non-compliance, a temporary ban on exercising managerial duties may even be imposed.

Second, incident-reporting deadlines are short: an early warning within six hours of becoming aware of a significant incident, notification with an initial assessment within 72 hours, and a final report within one month. Six hours is not enough time to start looking for the person responsible for making decisions.

Third, penalties have entered a different order of magnitude: up to €10 million or 2% of global annual turnover for essential entities, and up to €7 million or 1.4% for important entities.

And fourth, perhaps most importantly, the scope has expanded substantially. Sectors that until recently did not consider themselves “critical infrastructure” now fall within its scope: postal and courier services, waste management, food, manufacturing, research, public administration and digital service providers.

For many organisations, therefore, the first step is simple but critical: determine whether they fall within the scope.

From compliance to real readiness

NIS2 is an important step precisely because it shifts the focus beyond narrow technical compliance. Risk management, business continuity, incident response, supply-chain security, training and management accountability can no longer be treated as isolated obligations on a checklist. They must become elements of the same culture.

And this is perhaps where the greatest challenge lies. Compliance is documented through paperwork. Resilience is tested only when something goes wrong.

These are not opposing concepts. Compliance is the minimum threshold set by legislators; it is not the ceiling set by risk. An organisation may have policies, procedures and technological tools and still not be truly prepared.

Readiness requires more: exercises, testing, clearly defined roles, staff training, awareness of dependencies, alternative scenarios and, above all, the ability to make decisions when we do not have all the information we would like.

The human dimension

There is also one factor that no technology can replace: people.

The fact that phishing remains the leading observed method of initial access in the attacks analysed by ENISA should not lead us to the easy conclusion that “people are the weakest link”.

I see it differently. People can become the first line of defence, provided we give them the knowledge, tools and confidence to recognise something suspicious and report it without fear and without delay.

A cybersecurity culture is not built through an annual seminar or a message reminding employees to change their passwords. It is built every day.

From cybersecurity to cyber resilience

The biggest change we need is ultimately the easiest to express. We must stop defining success solely as avoiding an attack.

In an environment where attackers change, their tools evolve and our digital dependencies increase, no responsible organisation can base its strategy on the assumption that nothing will happen.

Prevention remains essential. Alongside it, however, must be the ability to detect, respond, maintain critical operations and recover quickly. That is cyber resilience.

And for that reason, it is not just about large companies or the state. It concerns every organisation that depends on data, digital services, networks, suppliers and people in order to function. In other words, today it concerns almost everyone.

The real question

We do not know the name of the next group that will capture the attention of the international cybersecurity community. We do not know what technique it will use. Nor do we need to know all of that in order to begin preparing.

What we need to know is which services we cannot afford to lose, which data we must protect, which people need to be ready and how quickly we can recover when something goes wrong.

Technology will continue to evolve. Threats will too. So must we.

True cyber resilience is not measured by whether we are ever attacked. It is measured by how prepared we are when that attack comes.

And perhaps, ultimately, that is the most important question:

Not only who will attack. But whether we will be ready.

Sources: ENISA Threat Landscape 2025 (reporting period July 1, 2024 to June 30, 2025) and related ENISA press release; Directive (EU) 2022/2555 (NIS2); Security of Network and Information Systems Law 89(I)/2020, as amended by Law 60(I)/2025.