The ENISA Threat Landscape 2025 assessed incidents across the EU and found phishing responsible for around 60% of observed initial access, with exploitation of vulnerabilities accounting for 21.3%. Nearly three times as many intrusions began with a person as with an unpatched system.
Compare that with where a typical SME security budget goes: endpoint licences, firewall renewals, and an annual penetration test. All are worth having, and all are aimed primarily at the 21.3%. The path used in three-fifths of cases is addressed by a slide deck once a year.
The report also notes that AI-assisted social engineering now accounts for the large majority of observed phishing content, which changes the practical defence. The old advice — look for bad grammar, odd formatting, generic greetings — is obsolete. Generated messages are fluent, contextual, and often reference real details scraped from your website and LinkedIn.
There is a useful nuance in the volume data too: DDoS accounted for roughly 77% of observed attack volume but caused disruption in only about 2% of cases. Volume and impact are different metrics. Reporting that counts blocked events rather than material incidents will systematically misdirect attention toward noisy, low-consequence activity.
The controls that actually address the dominant vector are unglamorous and mostly free of licensing: phishing-resistant multi-factor authentication on email and finance systems, an out-of-band verification rule for any change of bank details, restricted permissions so a single compromised mailbox cannot reach everything, and short simulated exercises often enough that reporting a suspicious message is normal behaviour.
For Irish firms in scope of NIS2, this is also becoming a documentation requirement rather than a best-practice suggestion. Either way the sequencing follows the evidence: secure the human path first, because that is where six in ten intrusions start.
Sources
- 1.ENISA Threat Landscape 2025European Union Agency for Cybersecurity · 2025
- 2.NIS2 Directive (EU) 2022/2555EUR-Lex · 2022