Skip to main content
1/19/2026NIS2

Lessons from ENISA’s NIS Investments Research

In December 2025, the European Union Agency for Cybersecurity (ENISA) published the NIS Investments 2025 Survey Data Companion Document, a comprehensive dataset presenting the results of… Read more

In December 2025, the European Union Agency for Cybersecurity (ENISA) published the NIS Investments 2025 Survey Data Companion Document, a comprehensive dataset presenting the results of a large-scale survey among 1,080 European organizations regarding their cybersecurity investments, capabilities, and challenges.

This document offers an in-depth look at how organizations manage their cyber risks in light of the NIS2 directive, thereby serving as a valuable resource for policymakers and security professionals looking to align their cybersecurity strategy with contemporary demands. Below, we analyze the key insights and connect them to how RiskStudio can support organizations in addressing the challenges identified by ENISA.

1. Cybersecurity Investments Continue to Grow, but Focus Shifts

The ENISA study shows that organizations spend an average of 9% of their IT budget on cybersecurity, continuing an upward trend compared to previous years. Interestingly, this budget is less often used to expand internal teams and is more focused on technology, outsourcing, and tooling.

Why this is relevant: Many organizations are looking for scalable solutions to mitigate risks without linearly increasing staff. RiskStudio addresses this by providing a data-driven overview of cyber risks (such as weaknesses and vulnerabilities) without relying on internal tooling or manual processes. This helps RiskStudio to direct investments more effectively and measurably to where risks truly lie.

2. NIS2 Compliance Remains the Biggest Investment Driver

A frequently cited reason for investing (more) in cybersecurity is the need to comply with the NIS2 directive, with approximately 70% of organizations naming this as a significant factor. While compliance is a strong motivator, the data shows that implementing the requirements remains challenging. Issues such as patching, business continuity, and supply chain management continue to be bottlenecks.

How RiskStudio helps: RiskStudio simplifies the identification and management of compliance-related risks by automatically analyzing digital business profiles, mapping external dependencies, and continuously monitoring risk indicators. This supports organizations in the practical application of NIS2 requirements rather than just the theory.

3. Cyber Talent is Scarce: The Human Factor Remains a Challenge

ENISA’s dataset reveals a persistent shortage of cybersecurity professionals: a significant portion of respondents indicate difficulty in attracting and retaining talent. This talent crisis leads organizations to increasingly rely on automation, outsourcing, and technologies to compensate for capacity shortages.

RiskStudio’s Role: By automating repetitive manual tasks, such as identifying digital assets, assessing vulnerabilities, and prioritizing risks, RiskStudio reduces the burden on scarce security professionals. This allows teams to focus on strategic cybersecurity activities instead of operational overhead.

4. Supply Chain Risks Deserve More Attention

Another aspect highlighted by the ENISA dataset is the increasing importance of supply chain risk management. Third parties and suppliers are increasingly cited as sources of potential risks, and future investments are focused on strengthening this chain.

RiskStudio’s approach: RiskStudio makes it possible to analyze not only an organization's own risks but also those of third parties and suppliers. By mapping relationships and dependencies, including digital business profiles, open vulnerabilities, and incident history, RiskStudio helps monitor and assess supply chain risks in real time.

5. Data-Driven Insights Accelerate Risk-Based Decisions

While organizations often struggle with fragmented data and manual reporting, ENISA’s own companion document provides a data-driven basis for insights into cybersecurity practices.

Why this is important: Decisions regarding cybersecurity investments, governance, and compliance increasingly need to be supported by measurable data. RiskStudio is built with this same principle in mind: current and structured data forms the core of analyses, reports, and advice.

Conclusion

The NIS Investments 2025research from ENISA shows that European organizations are making progress in cyber investments, but operational execution, talent shortages, and compliance implementation continue to be real bottlenecks.

RiskStudio closely aligns with these challenges by providing organizations with continuously updated, data-driven risk insights, efficient automation of risk management tasks, and support for compliance reporting and vendor assessments. Whether it's demonstrating NIS2 compliance, prioritizing risks, or monitoring vendors, RiskStudio helps organizations strengthen their cybersecurity strategy with both depth and scale.

Read the report yourself

You can download the publication at the following link: ENISA NIS Investements 2025

FAQ

Questions about this analysis

What does this article explain?

In December 2025, the European Union Agency for Cybersecurity (ENISA) published the NIS Investments 2025 Survey Data Companion Document, a comprehensive dataset presenting the results of… Read more

How is this analysis connected to current intelligence?

Related signal context is selected from current published reporting using the article subject, content and topic tags.

Where can I find related analysis?

Follow the article tags or return to the analysis archive to browse other reporting on connected subjects.