Data report

92.8% of European companies use some ICT security measure, but only 35.5% have written any of it down

Almost every European enterprise takes at least one ICT security measure: Eurostat puts it at 92.8% in 2024. Depth is where it thins out. Only 5.5% use the full set of measures Eurostat asks about, 35.5% have a documented security policy, and 38.1% do nothing to make staff aware of their security obligations.

Key takeaways

5 findings
  1. 0192.8% of EU enterprises with 10 or more employees use at least one ICT security measure.
  2. 0256.9% use five or more, and only 5.5% use all of them.
  3. 03Strong password authentication is the most common measure at 83.7%.
  4. 04Only 35.5% have a document setting out their ICT security measures and procedures.
  5. 0538.1% make no effort to make employees aware of their security obligations.
01

How many measures European companies actually take

Data points 1–5
  1. 01

    92.8% of EU enterprises with 10 or more employees use at least one ICT security measure. (Eurostat, 2024)Verified

  2. 02

    76.5% use at least three. (Eurostat, 2024)Verified

  3. 03

    56.9% use at least five. (Eurostat, 2024)Verified

  4. 04

    38.5% use at least seven. (Eurostat, 2024)Verified

  5. 05

    5.5% use every measure in the Eurostat list, which makes full coverage a rounding error rather than a norm. (Eurostat, 2024)Verified

02

Which measures they use

Data points 6–16
  1. 06

    83.7% of EU enterprises use strong password authentication. (Eurostat, 2024)Verified

  2. 07

    79.2% back data up to a separate location, including to the cloud. (Eurostat, 2024)Verified

  3. 08

    65.4% use network access control. (Eurostat, 2024)Verified

  4. 09

    49.6% use a VPN. (Eurostat, 2024)Verified

  5. 10

    45.2% keep log files for analysis after a security incident. (Eurostat, 2024)Verified

  6. 11

    45.1% run a monitoring system to detect suspicious activity. (Eurostat, 2024)Verified

  7. 12

    39.8% combine at least two authentication mechanisms. (Eurostat, 2024)Verified

  8. 13

    39.7% encrypt data, documents or e-mail. (Eurostat, 2024)Verified

  9. 14

    34.6% carry out ICT security tests. (Eurostat, 2024)Verified

  10. 15

    34.1% periodically assess ICT risk. (Eurostat, 2024)Verified

  11. 16

    18.3% use biometric authentication. (Eurostat, 2024)Verified

03

Policy, and how recently it was reviewed

Data points 17–21
  1. 17

    35.5% of EU enterprises have one or more documents on their ICT security measures, practices or procedures. (Eurostat, 2024)Verified

  2. 18

    21.8% defined or last reviewed that policy within the previous 12 months. (Eurostat, 2024)Verified

  3. 19

    29.4% did so within the previous 24 months. (Eurostat, 2024)Verified

  4. 20

    7.6% last reviewed it more than 12 but less than 24 months earlier. (Eurostat, 2024)Verified

  5. 21

    4.6% last reviewed it more than 24 months earlier. (Eurostat, 2024)Verified

04

What staff are told

Data points 22–27
  1. 22

    60.0% of EU enterprises make employees aware of their ICT security obligations in some way. (Eurostat, 2024)Verified

  2. 23

    42.6% do it through voluntary training or internally available information. (Eurostat, 2024)Verified

  3. 24

    34.2% do it through the employment contract. (Eurostat, 2024)Verified

  4. 25

    24.5% do it through compulsory training or compulsory material. (Eurostat, 2024)Verified

  5. 26

    31.5% both raise awareness and hold a documented policy. (Eurostat, 2024)Verified

  6. 27

    38.1% do none of it. (Eurostat, 2024)Verified

05

Security maturity by company size

Data points 28–36
  1. 28

    99.1% of EU enterprises with 250 or more employees use at least one ICT security measure. (Eurostat, 2024)Verified

  2. 29

    97.2% of EU enterprises with 50 to 249 employees use at least one ICT security measure. (Eurostat, 2024)Verified

  3. 30

    91.8% of EU enterprises with 10 to 49 employees use at least one ICT security measure. (Eurostat, 2024)Verified

  4. 31

    85.5% of EU enterprises with 250 or more employees use at least seven measures. (Eurostat, 2024)Verified

  5. 32

    61.6% of EU enterprises with 50 to 249 employees use at least seven measures. (Eurostat, 2024)Verified

  6. 33

    32.8% of EU enterprises with 10 to 49 employees use at least seven measures. (Eurostat, 2024)Verified

  7. 34

    81.5% of EU enterprises with 250 or more employees hold a documented ICT security policy. (Eurostat, 2024)Verified

  8. 35

    56.2% of EU enterprises with 50 to 249 employees hold a documented ICT security policy. (Eurostat, 2024)Verified

  9. 36

    30.3% of EU enterprises with 10 to 49 employees hold a documented ICT security policy. (Eurostat, 2024)Verified

06

Where documented security policy is most common

Data points 37–46
  1. 37

    Finland: 59.4% of enterprises with 10 or more employees hold a documented ICT security policy. (Eurostat, 2024)Verified

  2. 38

    Denmark: 59.1% of enterprises with 10 or more employees hold a documented ICT security policy. (Eurostat, 2024)Verified

  3. 39

    Portugal: 54.3% of enterprises with 10 or more employees hold a documented ICT security policy. (Eurostat, 2024)Verified

  4. 40

    Serbia: 53.4% of enterprises with 10 or more employees hold a documented ICT security policy. (Eurostat, 2024)Verified

  5. 41

    Romania: 49.5% of enterprises with 10 or more employees hold a documented ICT security policy. (Eurostat, 2024)Verified

  6. 42

    Latvia: 49.4% of enterprises with 10 or more employees hold a documented ICT security policy. (Eurostat, 2024)Verified

  7. 43

    Sweden: 46.6% of enterprises with 10 or more employees hold a documented ICT security policy. (Eurostat, 2024)Verified

  8. 44

    Ireland: 46.2% of enterprises with 10 or more employees hold a documented ICT security policy. (Eurostat, 2024)Verified

  9. 45

    Netherlands: 41.5% of enterprises with 10 or more employees hold a documented ICT security policy. (Eurostat, 2024)Verified

  10. 46

    Belgium: 40.3% of enterprises with 10 or more employees hold a documented ICT security policy. (Eurostat, 2024)Verified

Methodology

Figures come from Eurostat dataset isoc_cisce_ra (Security policy, measures, risks and staff awareness by size class of enterprise), last published 2026-06-15, reference period 2024. The unit is the percentage of enterprises in the stated size class, across all activities except agriculture, forestry, fishing and financial services. Eurostat asks about a fixed list of ICT security measures and three ways of raising staff awareness; enterprises can report several. Nothing on this page is modelled, weighted or adjusted by us: each figure is read straight from the dataset and can be reproduced in the Eurostat data browser.

Every data point carries one of three labels. Verified means the figure was read from the named primary source. Directional means sources agree on the trend but measure it differently. Single source means one publisher reported it and nobody has corroborated it. We would rather label a number honestly than round it into confidence it has not earned.

Sources

  • Eurostat — Security policy, measures, risks and staff awareness by size class of enterprise (isoc_cisce_ra). Period 2024, published 2026-06-15. View the dataset.
    EU statistical office. Annual survey of enterprises; percentages are of enterprises in the stated size class unless noted.

Cite this report

Updated 4 September 2026
APA

The Knowledge Engineers. (2026, 4 September 2026). ICT Security Measures in European Enterprises. https://theknowledgeengineers.com/reports/ict-security-european-enterprises

MLA

The Knowledge Engineers. “ICT Security Measures in European Enterprises.” The Knowledge Engineers, 4 September 2026, https://theknowledgeengineers.com/reports/ict-security-european-enterprises.

Chicago

The Knowledge Engineers. “ICT Security Measures in European Enterprises.” 4 September 2026. https://theknowledgeengineers.com/reports/ict-security-european-enterprises.

This URL is permanent. To cite one figure, use its number: “data point 07”.