Eurostat (Eurostat)
Macroeconomics  |  October 08, 2025 11:00:00, updated

21.5% of EU enterprises had ICT security incidents in 2023

In 2023, 21.5% of EU enterprises experienced ICT security incidents resulting in different types of consequences such as the unavailability of ICT services, destruction or corruption of data or disclosure of confidential data.

The highest shares of enterprises experiencing ICT security incidents with consequences were found in Finland, with more than two-fifths (42.2%), followed by Poland (32.5%) and Malta (28.7%). At the other end of the scale, the lowest shares were in Austria (11.5%), Slovenia (11.6%) and Bulgaria (12.1%).

Enterprises experiencing any ICT-related incident, 2023. Bar chart - Click below to see full dataset.

Source dataset: isoc_cisce_ic

The enterprises which dealt the most with ICT-related security incidents in 2023 were in the electricity, gas, steam and air conditioning supply sector (28.8%), information and communication (27.9%), professional, scientific and technical activities (26.8%), real estate activities (25.0%) and water supply including sewerage, waste management and remediation activities (24.1%).

Top 5 sectors experiencing ICT-related security incidents, 2013. Bar chart - Click below to see full dataset.

Source dataset: isoc_cisce_icn2

This article marks European Cybersecurity Month, raising awareness of and promoting cybersecurity each year for the entire month of October.

 

For more information

Methodological notes

  • The types of consequences resulting from ICT security incidents are:
    • unavailability of ICT services due to hardware or software failures
    • unavailability of ICT services due to Ransomware attacks and/or Denial of Service attack
    • destruction or corruption of data due to hardware or software failures
    • destruction or corruption of data due to infection of malicious software or unauthorised intrusion
    • disclosure of confidential data due to unintentional actions by own employees
    • disclosure of confidential data due to intrusion, pharming, phishing attack, intentional actions by own employees
  • EU enterprises: at least 10 employees and self-employed persons.
  • Data come from the 2024 Community survey on ICT usage and e-commerce in enterprises and refer to all enterprises with at least 10 employees (in NACE Rev. 2 sections C to J, L to N and group 95.1). Further methodological information related to the survey can be found here.
  • 2024 data on the consequences from ICT security incidents refer to the preceding calendar year (2023).


For information on upcoming releases visit our release calendar. If you have any queries, please visit our contact us page.




Zobrazit sloupec 
Kurzy.cz logo
EUR   BTC   Zlato   ČEZ
USD   DJI   Ropa   Erste