enterprise cybersecurity effectiveness. In businesses, cybersecurity controls are now widespread, but they rarely reach an advanced level. An analysis of over 300 companies revealed that approximately 53% manage cyber incidents at an intermediate level, only 7% at an advanced level, and the remaining 40% at a low or initial level, according to data collected in 2025.

62.5% of companies have an inventory of critical services and the systems that support them, but for 21.8%, business continuity plans exist and are applied in a limited way. This gap between having a measure and making it work is also found in small businesses.
enterprise cybersecurity effectiveness: why it matters
The Cyber Index PMI, promoted by Confindustria and Generali with the Politecnico di Milano and ACN, assigned 55 points out of 100 to the security posture of over 1,500 SMEs in March, a score below the passing threshold set at 60. The strategic part rises to 62, while the implementation part remains steady at 57 compared to the previous survey: companies define strategy faster than they implement measures.
The survey is from the EY Cyber Barometer, and the press release does not specify the representativeness of the sample of approximately 300 analyzed companies. The Cyber Index PMI is based on over 1,500 businesses and claims to represent the entire population of SMEs.
The Cyber Index PMI divides businesses into four levels: 16% are mature, 32% aware, 38% informed, and 14% beginner. 70% focus on intermediate levels, where risk knowledge does not yet translate into effective defense.
In the last three years, almost one SME in four has suffered a cyber breach, recalled the director of the Cybersecurity & Data Protection Observatory at Politecnico di Milano. The manufacturing sector is the second most hit and is among the least mature.
In 2025, the Clusit Report recorded 507 severe incidents in Italy, an increase of 42% compared to 357 in 2024, equal to 9.6% of global incidents. The government and military sector suffered over 28%, while manufacturing accounted for 12.6%, placing it second. 16% of global incidents in the manufacturing sector hit Italy.
In the first half of 2026, ransomware claims in Italy were 148, and the manufacturing sector concentrated 59, corresponding to 39.9%. The Clusit count concerns severe and known incidents from 2025, as well as criminal group claims, but the most hit sector remains the same.
According to the Barometer, digital and ICT sectors show maturity between 65% and 67%, while traditional and manufacturing sectors stand between 35% and 50%. Clusit warns that the most targeted sectors may also be less capable of defending themselves and mitigating incidents.
For cybercriminals, it is still possible to achieve significant results by hitting basic technology, present in almost all companies, or using standard attack techniques. The Clusit sample includes only known, successful, and particularly severe incidents, thus representing a part of the overall picture.
Large enterprises (with revenue over 50 million euros and 250 employees) still show an advantage in incident management. In small and medium-sized realities, the approach is often partial, fragmented, or tied to single key figures.
The most mature sectors, at 70%, are consumer goods manufacturing and digital sectors. In industry, the situation is less rosy: an analysis by HWG Sababa on thirty industrial contexts revealed that only 20% have an incident response plan calibrated for industrial systems.
What changes and what are the effects
IBM, in its Cost of a Data Breach Report 2026, calculated that detection, escalation, and business loss together absorb 63% of the total cost of a breach globally. In Italy, the average cost rose to 3.55 million euros from 3.31 million the previous year, with supply chain compromise as the most frequent initial cause (18% of cases).
By October 31, basic security measures must be adopted by most NIS entities listed in 2025: the eighteen months are calculated from the communication received by each entity. Determination 379907/2025 requires 37 measures and 87 requirements for important entities, 43 measures and 116 requirements for essential ones, and after that date, the National Cybersecurity Agency will move from accompaniment to supervision.
The measures must be operational and demonstrable: a measure adopted only on paper and evaded in practice does not meet the requirement. The deadline involves the supply chain as well. NIS entities had to declare their relevant suppliers by May 31, which inherit contractual clauses even if they remain outside the direct perimeter, and a non-compliant company risks being excluded from tenders before receiving a sanction.
The notification of significant incidents, in effect since January 2026 for the same audience, provides for pre-notification within 24 hours of knowledge of the event, complete notification within 72 hours, and a final report within one month. The obligation remains with the NIS entity, while the managed service provider can only support evidence collection.
The ACN has defined four types of significant incidents, three common to all entities and one specific for essential ones. Within the first 24 hours, someone must have established whether the event falls into one of them.
The Barometer evaluates whether a plan exists and how integrated it is in business processes, but does not provide proof of its effectiveness under attack. The 24-hour deadline represents the first external test of the plan: the decision on what constitutes a significant incident belongs to a specific person, who must be prepared.
Source and further reading on enterprise cybersecurity effectiveness: original article.
* Content created with the assistance of artificial intelligence systems.
Hardware Ready Ready to Bench?