Large European companies struggle to keep pace with rising cyber threats

Large European companies struggle to keep pace with rising cyber threats

16 June 2026 Consultancy.eu
Large European companies struggle to keep pace with rising cyber threats

Cybersecurity maturity among large organisations in Europe has continued to improve, albeit at a gradual pace, according to a new benchmark report from Wavestone. However, the rate of progress appears to be slowing, suggesting that further gains may become increasingly difficult to achieve.

With threats on the rise and the severity of cyber attacks growing quickly as bad actors make use of AI, companies around the world are having to take a hard look at their cybersecurity readiness. The added pressure of stricter regulations, especially in the EU, means some organizations are left scrambling to stay resilient.

The Cyber Benchmark of Wavestone, now in its seventh year, assessed more than 200 organizations against international cybersecurity standards and found that average maturity levels among large companies – those with revenues exceeding €1 billion – reached 55.3% this year, a modest gain of 1.3 points over 2025.

Despite these gains in maturity, researchers warn that the annual rate of improvement has been slowing, suggesting many organizations have hit a ceiling that will be difficult to break through without major structural changes or new investment.

Financial sector is well ahead in overall maturity

Source: Wavestone

Regulated sectors pull ahead

The financial services sector continues to lead all industries, reaching an average maturity score of 67.6%, up 5.1 points from 2025. Wavestone attributes this to sustained investment and the pressure of European regulation, particularly the Digital Operational Resilience Act, known as DORA. Some financial institutions have pushed their scores above 89%.

But meanwhile, the gap between regulated and unregulated sectors is widening. Regulated industries improved by 2.1 points on average, while unregulated companies saw no meaningful progress, leaving an 8.8-point divide between the two groups.

Cybersecurity budgets are also growing. Companies now allocate an average of 6.7% of their total budgets to cybersecurity, up from 6.4% the previous year, though still toward the lower end of the recommended range of 5% to 10%.

Staffing ratios have improved slightly, with organizations now employing one cybersecurity expert for every 979 employees, compared to one for every 1,016 last year. The best financial sector performers employ roughly one expert for every 83 employees.

either just graph on left, or whole thing together

Source: Wavestone

Ransomware threat remains uneven

Progress against ransomware has been notable at the large-company level but uneven across the broader business landscape. Across 29 ransomware attack vectors tracked by Wavestone, large organizations achieved an average protection level of 58%, up two points from 2025.

Among smaller and mid-sized companies, 25% are still considered to be in a critical situation regarding ransomware exposure, though this marks an improvement from 36% the year before. Researchers credit growing momentum from the rollout of the European NIS2 Directive as a driver of improvement, though they caution that sustaining this progress will need to be monitored in the years ahead.

While most areas of the NIST Cybersecurity Framework showed maturity levels of 56% to 57%, recovery capabilities lagged significantly at just 44%. This gap points to widespread difficulty in maintaining business continuity following a major incident. Only the financial sector performed better in this area, reaching 58%.

AI creates both opportunity and risk

The cybersecurity landscape has been transformed by AI and Gen AI in two directions simultaneously. On the one hand, organizations are beginning to deploy AI to automate routine tasks such as filtering spam and triaging security alerts. On the other, attackers are using AI to make phishing campaigns more convincing, produce deepfakes, and develop early-stage malware with evasion capabilities.

Large European companies struggle to keep pace with rising cyber threats

Source: Wavestone

Despite the urgency, organizational readiness remains limited. While 76% of large organizations now have a dedicated AI security policy in place, overall AI security maturity sits at just 38%. Only 10% have implemented defenses against AI-specific threats such as prompt injection attacks.

Large organizations have reached roughly 60% maturity in meeting the requirements of the NIS2 Directive, which is currently being transposed into law across European Union member states. No company assessed by Wavestone has yet achieved full compliance.

There are still significant gaps in third-party risk management, asset mapping, and resilience planning. The study notes that French organizations are behind their international peers, many of whom have benefited from operating in countries where NIS2 enforcement has already begun.

More on: Wavestone
Europe
Company profile
Wavestone is not a Europe partner of Consultancy.org
Partnership information »
Partnership information

Consultancy.org works with three partnership levels: Local, Regional and Global.

Wavestone is a not a partner of Consultancy.org.

Upgrade or more information? Get in touch with our team for details.