Get in touch

Journal · Data analysis

Cybersecurity 2024–2026: what three years of the CLUSIT Report really tell us

July 20, 2026 · 5 min read

5,265 Serious incidents in 2025
+48.7% Compared to 2024
+157% Monthly-average growth 2021→2025
84% High / Critical severity

Overview

Every year the CLUSIT Report is one of the most important references for understanding how cybersecurity evolves. It's a snapshot of the state of cyber threats, built by analyzing thousands of real incidents from all over the world. Behind charts, statistics and percentages hides a very simple question: is the security landscape really getting worse, or have we simply learned to detect more attacks?

To answer it, one report isn't enough: you need to compare data over time. So I analyzed the 2024, 2025 and 2026 editions of the CLUSIT Report, trying to understand not only how much incidents grew, but above all how threats, attackers' targets and the impact on organizations have changed.

What emerges is a very clear picture. Cyber attacks are not only growing in number: they are becoming more organized, more frequent and, above all, far more damaging. Cybersecurity is no longer a topic only for specialists: today it's a concrete risk for any organization that uses digital tools.

The growth of attacks is no longer an occasional phenomenon

In recent years we've often heard about the rise in cyber attacks. It's news that now appears regularly and, precisely for that reason, risks going almost unnoticed. Yet, comparing the three reports, an important change stands out: this is no longer gradual growth, but a real acceleration.

The 2024 CLUSIT Report already described a scenario in which cybercrime had taken on an industrial scale. Attacks grew steadily and hit organizations of every size, from large companies to small businesses, through public bodies and critical infrastructure.

The 2025 edition confirmed the trend. The numbers kept rising, but the attackers' profile changed too: more and more incidents were traced to structured groups, able to plan large-scale campaigns and exploit common vulnerabilities to hit hundreds of organizations at once.

But it's the 2026 CLUSIT Report that marks a turning point. During 2025, 5,265 serious cyber incidents were recorded worldwide, up 48.7% on the previous year: the highest increase of recent years, hard to read as a mere statistical fluctuation.

Even more telling is the medium-term trend. In 2021 the average was about 171 serious incidents per month; in 2025 it reached 439: an increase of about 157% in five years, with the 2025 figure standing at roughly 257% of the 2021 one — more than double. Today, on average, a serious incident is disclosed every few hours.

These numbers describe a very different reality from a few years ago. Cybercrime is no longer made only of lone attackers or small isolated groups: it's an organized ecosystem, able to build ever more effective tools, share expertise and hit a growing number of victims. The rise in incidents is therefore the consequence of a structural change in the threat landscape, not a temporary phenomenon.

Serious incidents worldwide · per year
2024 3,541
2025 5,265

+48.7% compared to 2024

Monthly average of serious incidents

From 171 to 439 per month

It's not just the number growing: the impact is too

If the first striking element is the rise in attacks, the second is probably even more important. Comparing the three reports, incidents are becoming not only more frequent, but also far more severe.

In the past a cyber attack could mean the compromise of a single computer or a temporary outage of some services. Today the effects are often much broader: an incident can halt a company's production, stop a hospital, take public services offline or cause the leak of large amounts of confidential data.

This evolution is so evident that the 2026 CLUSIT Report introduces, for the first time, a new severity category called Extreme: some incidents have reached a level of impact that can no longer be described with the traditional categories. In parallel, 84% of attacks fall into the highest severity categories (High/Critical), up from 79% in 2024.

In other words, today the probability that an attack causes significant operational, economic or reputational consequences is much higher than a few years ago. This, even more than the growth in numbers, is the figure that should make companies, public administrations and citizens think.

Severity distribution (2026)
84%High / Critical
  • High / Critical · 84%
  • Other · 16%
High/Critical share over time
2024 79%
2026 84%

+5 percentage points since 2024

The new «Extreme» tier
Extreme · 2.7% — impact beyond the traditional categories

Italy in the crosshairs

Italy remains one of the main targets: in 2025, 507 serious incidents were recorded against Italian targets, versus 357 in 2024 — a 42% year-on-year increase.

The country thus accounts for 9.6% of the global total, ranking fourth worldwide and first in Europe by number of attacks suffered.

Serious incidents in Italy · per year

+42% on 2024

Italy's share of the world total
9.6%2025

4th worldwide · 1st in Europe

Sources: CLUSIT Report, 2024, 2025 and 2026 editions (global and Italian data for the years 2023–2025). clusit.it