October marks European Cybersecurity Month. In 2026, it comes at a time when protecting an organisation has become increasingly complex. Cloud services, suppliers, identities, APIs and Artificial Intelligence have multiplied the systems, access points and dependencies that are part of everyday business operations. As a result, the surface that needs to be protected has expanded.
A cloud application. A supplier with access to an internal system. An account with outdated permissions. An API connecting two platforms. An AI agent authorised to access corporate information.
All of these are part of the attack surface.
The ENISA Threat Landscape 2026published in September, highlights the growing role of these digital dependencies in the security of European organisations.
The figures illustrate the scale of the challenge: more than 48,000 new CVE vulnerabilitieswere published in 2025, a 22% increase compared with the previous year.
Among the financially motivated activity analysed by ENISA, ransomware accounted for 40%, followed by data breaches at 31%, and fraud and impersonation at 19%.
For businesses, the first question comes before an attack occurs: do they really know everything they need to protect?
Corporate infrastructure is distributed across cloud applications, devices, suppliers, SaaS platforms and internal systems.
In this environment, identity has become a central element of security.
A compromised credential can provide access to email, documents and business applications. An account with excessive privileges can significantly increase the impact of that access.
Multi-factor authentication, least privilege, regular permission reviews, segmentation and Zero Trust principles address a clear requirement: ensuring that each identity can access the resources it needs, for as long as that access is required.
Artificial Intelligence adds another dimension to this issue.
Imagine an employee preparing a report. They access three different systems, collect information and cross-reference the data manually.
An AI agent with access to the same systems can perform much of that process in seconds.
The same speed that increases productivity can amplify the consequences of a poorly configured permission.
An agent with excessive privileges can access more information, perform more actions and interact autonomously with multiple systems. ENISA also identifies growing use of AI by malicious actors, including for automation and social engineering.
Enterprise AI adoption should therefore address security from the outset:
What data can it access? Which systems can it use? What actions can it perform? Which identity does it use? Are its actions logged?
These questions will become increasingly important as AI agents gain greater autonomy within organisations.
October is a good opportunity to assess five areas:
Cybersecurity in 2026 requires visibility across an increasingly interconnected infrastructure.
Understanding who can access what, through which system, with which permissions and with what ability to act has become fundamental to reducing exposure and responding faster when something goes
October puts cybersecurity on the agenda. Security is built throughout the year.
Talk to ORBCOM and find out how we can help assess your risks, strengthen your cybersecurity and prepare your organization for new requirements.
Sign up to our newsletter and keep up with the latest insights.
If you would like to get to know ORBCOM better and understand how our products, consulting services and outsourcing, fit your reality, speak to a specialist.