ICT Security Incidents: The Reality of Cyberthreats for EU Enterprises

In today’s digital age, the security of information and communication technologies (ICT) is crucial for businesses of all sizes. However, despite the growing awareness of ICT security issues, a significant number of European Union (EU) enterprises still experience security incidents.

According to Eurostat, in 2021, over 22% of enterprises with 10 or more employees and self-employed persons in the EU experienced ICT security incidents resulting in various consequences, such as unavailability of ICT services, destruction or corruption of data, or disclosure of confidential data.

The most common consequence reported was the unavailability of ICT services due to hardware or software failures, which affected 18.7% of the affected enterprises. Attacks from outside sources, such as ransomware and denial of service attacks, were less common, affecting only 3.5% of the affected enterprises.

Additionally, 3.9% of enterprises reported the destruction or corruption of data due to hardware or software failures, while 2.1% reported such incidents due to infection by malicious software or unauthorized intrusion. The disclosure of confidential data was the least frequent consequence of ICT security incidents, with 1.1% of incidents caused by intrusion, pharming, phishing attacks, or intentional actions by own employees, and 1.0% caused by unintentional actions by own employees.

EU countries with the highest and lowest incidence of ICT security incidents

Among EU countries, Finland had the highest percentage of enterprises experiencing ICT security incidents leading to unavailability of ICT services, destruction or corruption of data, or disclosure of confidential data, with over two-fifths (43.8%) of enterprises affected. The Netherlands and Poland followed closely behind, with 30.1% and 29.7% of enterprises affected, respectively. Other countries with high percentages of affected enterprises include Czechia (29.3%) and Denmark (26.4%).

On the other hand, the countries with the lowest percentages of affected enterprises were Bulgaria (11.0%), Portugal (11.5%), Slovakia (12.3%), Hungary (13.4%), and Cyprus (14.3%).

Why ICT security is important for businesses

The increasing use of digital technologies has made ICT security a major concern for businesses of all sizes. Cyberattacks and security incidents can result in the loss of critical data, disruption of business operations, financial losses, and reputational damage.

As a result, businesses need to take proactive steps to protect their ICT infrastructure from security threats. This includes implementing strong security policies, ensuring regular software updates and patches, using antivirus and anti-malware software, and conducting regular security audits and vulnerability assessments.

In addition, businesses can benefit from partnering with reputable ICT security providers who can offer tailored solutions to address their specific security needs.


ICT security incidents are a growing concern for businesses across the EU, with a significant number of enterprises experiencing various consequences due to security breaches. While certain countries, such as Finland, have higher rates of incidents, all businesses need to take proactive steps to protect their ICT infrastructure from security threats. By partnering with trusted ICT security providers and implementing best practices for security, businesses can safeguard their data, operations, and reputation from potential harm.

