SME Cybersecurity Plan:
Five Priorities from ENISA 2026
An SME cybersecurity plan needs a defensible order, not a longer checklist. The ENISA Threat Landscape 2026 identifies ransomware as the incident type with the greatest short-term impact, describes phishing as a common enabling tactic, and says exploited vulnerabilities remain a prevalent intrusion route. For a small team, that means making identities, exposed systems, recovery, and dependencies testable first.
The EU evidence is not an individual risk score. It shows recurring attack paths. This 90-day plan translates those signals into five control outcomes, each with an owner, a test, and evidence.
What ENISA 2026 shows—and what it cannot show
ENISA assessed events observed between January and December 2025. The material came from open sources and anonymised information shared by EU Member States and the ENISA Cyber Partnership Programme. That makes it a substantial European threat assessment, but not live telemetry or a representative incident rate for every German SME.
The direction is still operationally useful. Cybercrime accounted for 36% of recorded events. Within financially motivated activity, ransomware represented 40%, data breaches 31%, and fraud or impersonation 19%. ENISA also highlights digital dependencies: supply-chain and third-party attacks can affect many organisations through one shared access path.
The new Eurobarometer adds a workplace view. Three in four EU employees encountered suspicious messages or links at work, and 39% reported phishing. Only 48% believed they could recognise an AI-generated fake video. The answer is not training alone; approval and reporting processes must stay safe when an imitation looks convincing.
Five priorities for an SME cybersecurity plan
| Threat signal | Control outcome | Testable evidence |
|---|---|---|
| Phishing and stolen credentials | Privileged and external access requires a second, phishing-resistant barrier where available | Account list, MFA coverage, two tested access revocations |
| Exploited vulnerabilities | Internet-facing systems have owners and risk-based patch deadlines | External inventory, age report, documented exception |
| Ransomware and data theft | Critical data can be restored from separated protection | Recorded restore with duration and recovery point |
| Supply-chain and third-party access | Every remote path has a purpose, owner, expiry, and shutdown method | Supplier register and successful revocation test |
| Fraud and AI impersonation | Sensitive changes require a second, independent communication channel | Approval test for payment, account, or master-data change |
This table is an ATMAN decision model, not an ENISA requirement. It prioritizes outcomes a small team can test. Organisations with an established information security management system can map the same outcomes to their existing risk and control structure.
Days 1–30: establish visibility and immediate boundaries
- Name critical operations. Select three to five business processes whose disruption directly affects revenue, delivery, safety, or legal duties. Map their applications, data, and accountable people.
- Inventory privileged identities. List administrator, cloud, email, backup, and external support accounts. Remove orphans, separate daily and administrative use, and enforce multi-factor authentication.
- Map exposed systems. Record domains, VPNs, firewalls, remote maintenance, cloud services, and public APIs from the internet's point of view. Give an unknown service an owner before granting it an exception.
- Publish one reporting path. Staff need a familiar channel for suspicious messages and mistaken clicks. Do not punish reports; early visibility improves the response.
Germany's Federal Office for Information Security (BSI) treats information security as a management responsibility and recommends inventories, risk management, tested backups, and regular exercises. Its CyberRiskCheck under DIN SPEC 27076 gives small and micro enterprises a standardized starting point. It is not an audit or certification, but it can expose missing foundations.
Days 31–60: interrupt the recurring attack paths
Turn inventories into operating controls. Set patch deadlines by exposure and impact: a critical weakness on a public gateway deserves a different response from the same score in an isolated test environment. Each exception needs a risk statement, owner, compensating measure, and expiry date.
Annual phishing training is not enough for email and identity risk. Combine short, role-specific exercises with technical protections, a visible reporting route, and independent approvals. A bank-detail change or new administrator, for example, should be confirmed over a known second channel—not contact information supplied by the same message.
Check whether backup administrators are separated from production identities and whether backups resist alteration or deletion. The meaningful test is a restore into a clean environment. Record duration, recovered data point, missing keys, and manual dependencies.
Days 61–90: test suppliers and rehearse the incident
Digital dependencies become manageable when access and responsibility are visible. For each critical supplier, record the service, affected data, technical access, incident contact, notification expectations, and exit option. Sample whether remote access can actually be revoked within the expected time.
Close the cycle with a two-hour tabletop exercise. A realistic scenario might combine a suspicious login, an encrypted file share, an unavailable SaaS provider, and a press inquiry. Management sets priorities while IT, privacy, communications, and operations record missing information or authority.
ENISA's “Awareness Raising in a Box” provides material for programmes, audiences, channels, and metrics. Use it to drive a specific behaviour: report earlier, follow the approval path, or disable suspicious access. Course completion alone is not evidence of resilience.
Four metrics that show outcomes, not activity
- Identity: percentage of privileged and external accounts with strong MFA and a named owner.
- Exposure: percentage of public systems inside the defined patch deadline, with exceptions reported separately.
- Recovery: measured restore time and achieved recovery point for one critical process.
- Response: time from first internal report to triage, plus open actions from the latest exercise.
These outcomes fit a risk-based cybersecurity architecture. When inventories, responsibilities, or operating boundaries are missing, structured IT consulting can establish the decision model. Cloud identities, backups, and recovery also belong in a testable Cloud and DevOps operating model.
Frequently asked questions about SME cybersecurity
Does the ENISA Threat Landscape 2026 apply specifically to SMEs?
No. ENISA analyses EU-wide events across multiple sectors. The report provides a dependable threat orientation, but it does not replace an assessment of an organisation's own business processes, systems, and suppliers.
Which cybersecurity control should an SME implement first?
First make critical business processes, privileged accounts, and internet-facing systems visible. Then prioritize multi-factor authentication, patch deadlines, and recovery where disruption would cause the greatest harm.
Is annual phishing training enough?
No. Training is only one part of the control. Staff also need a simple reporting path, technical safeguards, safe approval workflows, and evidence that suspicious messages are reported promptly.
What evidence should a 90-day cybersecurity plan produce?
Useful evidence includes account and system inventories, MFA coverage, patch reports, a recorded restore test, supplier access with named owners, and an action log from an incident exercise.
Begin with one critical process
Do not start with the whole company. Select one critical process and produce current evidence for all five control outcomes. Then repeat the method for the next process. A useful SME cybersecurity plan grows from verified decisions, not a one-time checklist.
Sources and methodology
This article separates findings published by ENISA, the European Commission, and BSI from ATMAN's 90-day model. The workflow is technical and organisational analysis, not an ENISA or BSI requirement and not legal advice. All sources were accessed on 3 October 2026.
- ENISA: ENISA Threat Landscape 2026, published 22 September 2026; accessed 3 October 2026
- ENISA: How dependencies weaken our digital resilience, press release published 22 September 2026; accessed 3 October 2026
- European Commission: Three in four EU employees faced cyber threats at work, published 30 September 2026 and updated 1 October 2026; accessed 3 October 2026
- ENISA: Custom-made Awareness Raising to enhance Cybersecurity Culture, published 10 April 2024; accessed 3 October 2026
- BSI: 10 Tips for Cyber Security for Companies (German), continuously maintained guidance with no stated publication date; accessed 3 October 2026