Over 25 years, the threat has moved from self-spreading worms to criminal and state-backed groups that go after identities, suppliers and software. Corporate defence has moved with it, from antivirus and a firewall to EDR, MFA, continuous vulnerability management and round-the-clock monitoring. In Europe, cybersecurity is now also a legal duty of the board.
Most of the controls that NIS2, DORA or ISO 27001 now require can be traced back to a specific incident. Knowing where each one came from makes it easier to explain to a board why it matters, and to decide what to fund first. This article walks through five eras, from 2001 to 2026, with a European lens.
The five eras at a glance
| Era | Dominant threat | Landmarks | What organisations did |
|---|---|---|---|
| 2000-2004 | Mass worms | ILOVEYOU, Code Red, Nimda, SQL Slammer | Perimeter firewalls and antivirus |
| 2005-2012 | Professional crime and APTs | Operation Aurora, Stuxnet | Intrusion detection and SIEM |
| 2013-2019 | Mega-breaches and ransomware | Yahoo, WannaCry, NotPetya, GDPR | Offline backups, CISOs, incident response |
| 2020-2023 | Supply chain and identity | SolarWinds, Log4Shell, MOVEit | EDR/XDR, MFA, Zero Trust, 24/7 SOC |
| 2024-2026 | EU regulation and AI | XZ Utils, NIS2, DORA, CRA, AI Act | Board-level governance and third-party risk |
2000-2004: the age of the worm
Worms needed no attacker at the keyboard. ILOVEYOU arrived by email in May 2000 disguised as a love letter; CERT/CC issued advisory CA-2000-04 on 4 May.
Code Red showed how fast an unpatched server estate could fall. On 19 July 2001 its CRv2 variant infected more than 359,000 Microsoft IIS servers in under 14 hours, according to CAIDA. Nimda followed on 18 September, spreading by email, open network shares and compromised web servers at the same time. Then, on 25 January 2003, SQL Slammer doubled its population every 8.5 seconds and infected more than 90 per cent of vulnerable hosts within ten minutes. No human response could keep pace.
Inside the organisation. Security meant a castle and a moat: a firewall at the edge, antivirus on every desktop and patches when there was a maintenance window. It was an IT matter. Europe's institutional response started here too: ENISA, the EU cybersecurity agency, was set up in 2004.
2005-2012: professional crime and persistent threats
Noise gave way to stealth. Attackers now wanted money or intelligence, and they wanted to stay unnoticed.
On 12 January 2010 Google disclosed that in mid-December it had detected a targeted attack on its corporate infrastructure, originating in China, which led to the theft of intellectual property. At least 20 other large companies had been targeted in the same campaign, later known as Operation Aurora. It fitted what is now called an advanced persistent threat (APT): targeted, quiet and long-running.
In June 2010 the Belarusian firm VirusBlokAda identified Stuxnet, malware built to sabotage the uranium enrichment centrifuges at Natanz, in Iran, by tampering with their industrial control systems. It proved that code could cause physical damage, and put operational technology (OT) on the security agenda.
Inside the organisation. Intrusion detection, the first SIEM platforms and periodic vulnerability scans arrived on the assumption that someone might already be inside. National capabilities grew in parallel; in Spain, for example, the national cryptologic centre set up its CERT, CCN-CERT, in 2006, and the National Security Framework (ENS), mandatory for the public sector, was first adopted in 2010.
2013-2019: mega-breaches, ransomware and the GDPR
Personal data became the prize. In October 2017 Yahoo confirmed that its 2013 breach had affected all of its roughly 3 billion accounts, three times the figure disclosed in December 2016.
2017 was also the year ransomware became a business continuity problem. On 12 May WannaCry combined file encryption with worm-like spreading and, according to Europol, hit more than 200,000 victims in at least 150 countries. On 27 June NotPetya, dressed up as ransomware but built to destroy data, spread from Ukraine to multinationals including Maersk, Merck and Saint-Gobain. In February 2018 the White House attributed it to the Russian military; its damage estimate, confirmed to Wired by former homeland security adviser Tom Bossert, exceeded USD 10 billion.
Regulation arrived in the same period. The first NIS Directive was adopted in 2016, the UK set up its National Cyber Security Centre (NCSC) the same year, and the US created CISA in 2018. On 25 May 2018 the GDPR began to apply, with a 72-hour deadline to report personal data breaches to the supervisory authority and fines of up to EUR 20 million or 4 per cent of global annual turnover, whichever is higher. In 2019 the EU Cybersecurity Act gave ENISA a permanent mandate.
Inside the organisation. Isolated backups with tested restores became the baseline defence against ransomware. Incident response and business continuity plans (ISO 22301), ISO 27001 certification and a CISO reporting to senior management became standard in larger organisations.
2020-2023: supply chain, cloud and identity
With cloud services and remote work, identity became the perimeter. At the 2020 RSA Conference, Microsoft said that 99.9 per cent of the compromised accounts it tracked each month had no multi-factor authentication (MFA) enabled.
SolarWinds, disclosed in December 2020, turned a trusted vendor into the attack vector. Attackers compromised the build system for Orion and shipped trojanised updates between March and June 2020. Around 18,000 customers downloaded them, although follow-on exploitation focused on a much smaller set of high-value targets, including US federal agencies (CISA, GAO).
On 9 December 2021 Log4Shell (CVE-2021-44228) went public: remote code execution in the Apache Log4j library, rated CVSS 10.0. Many organisations simply did not know where they were running it. In 2023, from 27 May, the Cl0p group exploited a then-unknown SQL injection flaw in MOVEit Transfer (CVE-2023-34362) to steal data at scale from organisations using the file transfer tool (CISA advisory AA23-158A).
Inside the organisation. Signature antivirus gave way to EDR and XDR, which detect behaviour rather than known files. A managed 24/7 SOC put continuous monitoring within reach of mid-sized companies that could not staff a night shift. MFA, conditional access and Zero Trust replaced trust based on network location, and vulnerability management moved from an annual scan to a continuous process supported by software bills of materials (SBOMs).
2024-2026: EU regulation, AI and board accountability
On 29 March 2024 engineer Andres Freund found a backdoor in XZ Utils versions 5.6.0 and 5.6.1 (CVE-2024-3094, CVSS 10.0) while investigating why SSH logins were using more CPU than expected. The account behind it had spent more than two years earning the maintainers' trust. Open-source supply chains can be attacked through social engineering, not just code.
Europe's answer has been largely regulatory, and it now forms a single, layered framework:
- NIS2 (Directive (EU) 2022/2555) had to be transposed by 17 October 2024. Article 20 requires management bodies to approve and oversee cyber risk measures and allows them to be held liable for infringements. We cover what that means in practice in NIS2 board accountability.
- DORA (Regulation (EU) 2022/2554) has applied since 17 January 2025 to banks, insurers, investment firms and other financial entities, and brings critical ICT third-party providers under EU-level oversight.
- The Cyber Resilience Act (Regulation (EU) 2024/2847) entered into force on 10 December 2024. Since 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents affecting their products (what the reporting duty involves); the remaining obligations apply from 11 December 2027.
- The AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024. Prohibited practices have applied since 2 February 2025, general-purpose AI model obligations since 2 August 2025 and the Article 50 transparency duties since 2 August 2026. The Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026) pushed the high-risk requirements for Annex III systems back to 2 December 2027, and for Annex I systems to 2 August 2028. It also gave generative AI systems already on the market until 2 December 2026 to meet the Article 50(2) duty to mark their output.
Transposition is uneven. On 8 July 2026 the European Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice of the EU for failing to notify full transposition of NIS2, and asked for financial penalties. For groups with EU subsidiaries this means different national timetables for the same directive. In Spain, the draft cybersecurity coordination and governance law approved by the government on 14 January 2025 has still not been published, and the 2018 decree-law that transposed the first NIS Directive remains in force. We explain the practical consequences in NIS2 without a national law.
Inside the organisation today. Cybersecurity is a corporate governance matter: the board approves risk and answers for it, critical suppliers are assessed and incidents are reported within hours. Many mid-sized companies cover that role with a virtual CISO who connects NIS2, DORA or ISO 27001 compliance with day-to-day operations. AI adds another front. According to ENISA's Threat Landscape 2025, AI-supported campaigns accounted for more than 80 per cent of observed social engineering activity worldwide by early 2025 (our analysis of the report), while organisations also have to govern their own use of AI.
Five lessons that still hold
The actors and the scale have changed since 2001. These patterns have not:
- Known, unpatched vulnerabilities let in Code Red, SQL Slammer and WannaCry, all of which exploited flaws with patches published months earlier.
- Dependence on third parties sits behind SolarWinds, Log4Shell, MOVEit and XZ Utils, which is why NIS2 and DORA both require third-party risk management.
- Identity is the perimeter. Phishing-resistant MFA and conditional access shrink the attack surface.
- Recovery capability decides how a ransomware incident ends: isolated backups and rehearsed plans.
- Board accountability is now a legal obligation in regulated sectors across the EU.
Hard2bit has spent more than a decade helping organisations through this transition, from monitoring and incident response to ISO 27001, ISO 22301, ISO 20000-1 and Spain's ENS at the high (ALTA) level, all of which we are certified against ourselves. To see which regulations apply to you, start with our regulatory assessment; to measure where your organisation stands on this curve, we can run a maturity assessment against the framework that matters most to you.
Sources
- ENISA established in 2004 (Regulation (EC) No 460/2004)
- NIS Directive (EU) 2016/1148
- EU Cybersecurity Act, Regulation (EU) 2019/881 (permanent ENISA mandate)
- UK NCSC, set up in 2016
- CISA, created by the Cybersecurity and Infrastructure Security Agency Act of 2018
- NotPetya victims, Bossert estimate and delivery via M.E.Doc updates
- Digital Omnibus on AI, Regulation (EU) 2026/1744
- NIS2 CJEU referral of four member states (8 July 2026)
- giac.org
- caida.org
- mycert.org.my
- caida.org
- googleblog.blogspot.com
- spectrum.ieee.org
- ccn-cert.cni.es
- incibe.es
- unaaldia.hispasec.com
- boe.es
- money.cnn.com
- washingtonpost.com
- defenseone.com
- eur-lex.europa.eu
- welivesecurity.com
- gao.gov
- cisa.gov
- blog.qualys.com
- cisa.gov
- rapid7.com
- eur-lex.europa.eu
- eiopa.europa.eu
- eur-lex.europa.eu
- digital-strategy.ec.europa.eu
- artificialintelligenceact.eu
- hunton.com
- cuatrecasas.com
- enisa.europa.eu
- angelortegacastro.com
- nisd2.eu
- ec.europa.eu
Frequently asked questions
I'm the CFO of a mid-sized manufacturer and our security still comes down to antivirus and a firewall. Is that enough against today's threats?
▾
That model was built for the worms of the early 2000s. Today's attacks come in through stolen credentials, compromised suppliers or newly published vulnerabilities, and signature-based antivirus does not see that behaviour. A reasonable baseline now is MFA on every account, EDR on every endpoint, isolated backups with tested restores, continuous vulnerability management and 24/7 monitoring, either in-house or through a managed SOC.
We provide IT services to a bank in the EU. Does DORA apply to us even though we are not a financial entity?
▾
DORA applies directly to financial entities, since 17 January 2025, but it requires them to manage ICT third-party risk, keep a register of those contracts (Article 28) and include specific clauses in them (Article 30). In practice your client will pass security, audit, incident reporting and exit requirements on to you. If you are designated a critical ICT third-party provider, you will also come under direct oversight by the European Supervisory Authorities.
I lead IT for a group likely in scope of NIS2, with a key subsidiary in Spain, where the national law is still pending. Should we wait for it there?
▾
Waiting buys little. Your entities in member states that have transposed NIS2 must already manage supply chain security (Article 21(2)(d)), so their customers and group companies can pass those requirements on to you through contracts. The Article 21 measures also overlap heavily with ISO 27001 and, in Spain, with the ENS, so work done now carries over when the national law arrives.
I sit on the board of a European company. Which incident from the last 25 years best explains why cyber risk is now our responsibility?
▾
NotPetya. In 2017 a supply chain compromise of a Ukrainian accounting software package spread to multinationals such as Maersk and Merck, each of which reported nine-figure losses, and the US government estimated total damages above USD 10 billion. Many victims were collateral damage in an attack aimed at Ukraine. It showed that one weak link can halt global operations, which is the logic behind NIS2's Article 20 and DORA's governance rules.