EU Business Cybersecurity
18 verified facts tracked for this market — each with its source, reporting period and evidence tier. Tier 1 = primary institutions (central banks, statistical offices); tier 2 = disclosed industry panels.
| Metric | Value | Geo | Period | Tier | Source |
|---|---|---|---|---|---|
| UK micro businesses citing external consultants or providers for cyber security information and guidance | 24percent | UK | 2025/2026 | T1 | gov.uk |
| UK businesses without cyber insurance citing lack of budgetary priority as a reason for non-coverage | 34percent | UK | 2025/2026 | T1 | gov.uk |
| EU enterprises that applied at least 1 ICT security measure | 93% of enterprises | EU27 | 2024 | T1 | ec.europa.eu |
| EU enterprises making staff aware of ICT security obligations | 59.97% of enterprises | EU27_2020 | 2024 | T1 | ec.europa.eu |
| Share of EU enterprises that defined or most recently reviewed their ICT security policy within the last 12 months | 21.82% of EU27 enterprises | EU27 | 2024 | T1 | ec.europa.eu |
| EU organisations' median share of IT investment allocated to information security | 9percent of IT investment | EU27 | 2024 | T1 | enisa.europa.eu |
| EU organisations planning to raise their information security budgets | 80percent of respondents | EU27 | 2024 | T1 | enisa.europa.eu |
| EU organisations needing more cybersecurity staff to comply with NIS 2 | 89percent of organisations | EU27 | 2024 | T1 | enisa.europa.eu |
| EU organisations expecting an increase in cyberattacks in the coming year | 90percent of entities | EU27 | 2024 | T1 | enisa.europa.eu |
| EU cybersecurity-role employees lacking formal qualifications or certified training | 76percent of cybersecurity employees | EU27 | 2024 | T1 | enisa.europa.eu |
| EU organisations that have not audited third-party vendors for AI-related vulnerabilities | 80percent of organisations | EU27 | 2024 | T1 | enisa.europa.eu |
| EU surveyed organisations reporting no measurable improvements from cybersecurity investment | 4% | EU27 | 2024 | T1 | enisa.europa.eu |
| EU surveyed organisations reporting faster incident detection after cybersecurity investment | 35% | EU27 | 2024 | T1 | enisa.europa.eu |
| EU surveyed organisations reporting improved incident response and recovery after cybersecurity investment | 26% | EU27 | 2024 | T1 | enisa.europa.eu |
| EU enterprises experienced any ICT security related incident (unavailability of ICT services, destruction/corruption of data, or disclosure of confidential data) | 21.54% of enterprises (EU27; enterprises with 10+ employees; NACE Rev.2 sections C-J, L-N and group 95.1, excl. financial sector) | EU27 | 2024 | T1 | ec.europa.eu |
| Enterprises hit by unavailability of ICT services from a security incident, European Union | 19.26percent of enterprises | EU27 | 2024 | T1 | ec.europa.eu |
| How EU enterprises source their ICT security activities: own employees vs external suppliers | 68.03% of EU enterprises | EU27 | 2022 | T1 | ec.europa.eu |
| EU enterprises having insurance against ICT security incidents | 19.81% in 2019; 24.97% in 2022% of EU27 enterprises with 10+ persons e | EU27 | 2019-2022 | T1 | ec.europa.eu |
Connected markets
Same geography, other verticals
- EU HR & Recruiting Tech · 20 facts
- EU PropTech · 20 facts
- EU Business AI Adoption · 20 facts
- EU Digital Health & Wellness · 20 facts
- EU Cloud & IT Operations · 18 facts
Related benchmarks
Building in this market?
Validate your idea against this data inside God of Startups. Your idea is checked against the market, never shared with it.