Security

    Phishing Is 60% of Initial Access. ENISA's Data Says Fix the Human Path First

    The ENISA Threat Landscape 2025 puts phishing at around 60% of observed initial access and vulnerability exploitation at 21.3%. Most SME security spend is aimed at the smaller number.

    Written by

    Abdul Mughal

    Co-Founder, CEO & Head of Business Development

    4 May 2026 · 6 min read

    Key figures

    ~60%
    of initial access via phishing
    Source: ENISA
    21.3%
    via vulnerability exploitation
    Source: ENISA
    77%
    of observed attack volume was DDoS
    Source: ENISA

    The ENISA Threat Landscape 2025 assessed incidents across the EU and found phishing responsible for around 60% of observed initial access, with exploitation of vulnerabilities accounting for 21.3%. Nearly three times as many intrusions began with a person as with an unpatched system.

    Compare that with where a typical SME security budget goes: endpoint licences, firewall renewals, and an annual penetration test. All are worth having, and all are aimed primarily at the 21.3%. The path used in three-fifths of cases is addressed by a slide deck once a year.

    The report also notes that AI-assisted social engineering now accounts for the large majority of observed phishing content, which changes the practical defence. The old advice — look for bad grammar, odd formatting, generic greetings — is obsolete. Generated messages are fluent, contextual, and often reference real details scraped from your website and LinkedIn.

    There is a useful nuance in the volume data too: DDoS accounted for roughly 77% of observed attack volume but caused disruption in only about 2% of cases. Volume and impact are different metrics. Reporting that counts blocked events rather than material incidents will systematically misdirect attention toward noisy, low-consequence activity.

    The controls that actually address the dominant vector are unglamorous and mostly free of licensing: phishing-resistant multi-factor authentication on email and finance systems, an out-of-band verification rule for any change of bank details, restricted permissions so a single compromised mailbox cannot reach everything, and short simulated exercises often enough that reporting a suspicious message is normal behaviour.

    For Irish firms in scope of NIS2, this is also becoming a documentation requirement rather than a best-practice suggestion. Either way the sequencing follows the evidence: secure the human path first, because that is where six in ten intrusions start.

    Sources

    1. 1.ENISA Threat Landscape 2025European Union Agency for Cybersecurity · 2025
    2. 2.NIS2 Directive (EU) 2022/2555EUR-Lex · 2022

    Apply it

    Score your growth system

    Ten questions, a stage-by-stage score and your three highest-value priorities.
    Get your free Growth Audit