The 2026 annual report from ENISA, the European cybersecurity agency, is no longer read like a technical bulletin but like a state of the world. Ransomware attacks cost global companies over $60 billion in 2025 - including insurance, ransoms, business interruptions, and reconstruction - triple the level of 2020. Beyond the figures, the very nature of the threat has changed.

Ransomware Has Become an Industry

The Ransomware-as-a-Service (RaaS) model—specialized groups renting their attack infrastructure to affiliates for a commission on ransoms—has consolidated. A few families (LockBit in its successive versions, ALPHV/BlackCat, Cl0p, Akira, RansomHub) account for a majority of attacks. Coordinated takedowns by Europol, the FBI, and the UK's NCA (Operations Cronos, Endgame, Morpheus) have temporarily disrupted the ecosystem without extinguishing it: a dismantled group is generally replaced within a few months.

The preferred target has shifted. Alongside large companies traditionally targeted, local authorities, hospitals, and industrial SMEs have become the new weak links. In France, ANSSI recorded over 300 major incidents in 2025 affecting essential service operators or local authorities, compared to 187 in 2022.

Key Cybersecurity Figures 2026

- $60 billion: global annual cost of ransomware in 2025.

- +220%: increase in attacks against hospitals between 2020 and 2025.

- 300+: major incidents recorded by ANSSI in France in 2025.

- NIS2: European directive fully transposed into 26 member states by early 2026.

- Cyber Resilience Act: phased entry into force 2024-2027, with sanctions up to 2% of global turnover.

- 2030: horizon by which a quantum computer could break RSA-2048 according to the most pessimistic projections (vs. 2040 in consensus).

- 3 post-quantum algorithms standardized by NIST in 2024: ML-KEM, ML-DSA, SLH-DSA.

The Quantum Threat: Still Theoretical, Already Operational

The advent of a quantum computer capable of breaking current asymmetric cryptography (RSA, ECC) remains hypothetical by 2030-2040. But the 'harvest now, decrypt later' threat—capturing encrypted data today to decrypt it tomorrow—is pushing governments to anticipate. The United States has mandated a complete migration to post-quantum cryptography for its federal agencies by 2035. Europe, via ENISA, ANSSI, and Germany's BSI, recommends that critical operators build their crypto-agility starting in 2026: the ability to rapidly substitute cryptographic algorithms without rewriting systems.

NIST standardized three post-quantum algorithms in August 2024: ML-KEM (key exchange), ML-DSA, and SLH-DSA (signatures). The first operational deployments (hybrid TLS 1.3, firmware signatures) began in 2025, primarily among major cloud players (Google, AWS, Cloudflare) and sensitive administrations.

NIS2 and Cyber Resilience Act: Europe Regulates, Europe Sanctions

The NIS2 directive, transposed into 26 member states by early 2026, expands the scope of entities subject to cybersecurity obligations: energy, transport, health, banking, digital infrastructure, but also public administration, space, waste management, and certain SMEs. Sanctions can reach €10 million or 2% of global turnover.

The Cyber Resilience Act (CRA), which entered into force in late 2024 with phased implementation until 2027, imposes for the first time cybersecurity-by-design obligations on all connected products sold in the EU—from Wi-Fi routers to connected cars. For software publishers and hardware manufacturers, the compliance effort is massive: technical documentation, vulnerability management, and security updates guaranteed throughout the product's lifespan.

> “Cybersecurity is no longer a technical issue. It is a corporate governance issue, and increasingly a state governance issue.” — *Vincent Strubel, Director General of ANSSI, French Senate hearing, February 2026.*

Key Takeaways

- $60 billion: annual global cost of ransomware.

- RaaS now structures the cyber criminal economy.

- NIS2 fully transposed by early 2026 in 26 member states.

- CRA mandates cybersecurity by design for all connected products.

- Quantum threat: post-quantum migration recommended from 2026 for critical operators.

- Three NIST algorithms standardized: ML-KEM, ML-DSA, SLH-DSA.