Read this first — every region is measured with a different ruler. This is the single most important caveat on the page. Each regional ranking comes from a different methodology, so cross-region comparison is directional, not quantitative. A sector ranking higher in one region than another may reflect what was counted, not a real difference in threat.
Methodology — What Each Region's Number Actually Counts
No single source ranks sectors consistently across all four regions. This synthesis stitches the best available data per region — but the lenses differ, and that difference is the headline.
| Region | Primary source(s) | What is actually counted |
|---|---|---|
| Benelux | Eye Security BEC 2026; Northwave GTL 2026 | Dutch MDR / IR caseloads (BEC-heavy) + leak-site listings |
| DACH | Yarix, Acronis, Check Point, BSI | German leak-site + ransomware telemetry. BSI counts by org size, not sector |
| UK | NCC Group, NCSC, Gov Breaches Survey | Leak-site victim counts vs self-reported breach prevalence — these two contradict |
| Nordics | SOCRadar; Danish CFCS, Finnish NCSC-FI | Dark-web / leak-site listings — skews to data-extortion + credential trade |
Why it matters: two Dutch MDR vendors (Eye, Northwave) agreeing is correlated visibility, not independent corroboration — both look at NL/Benelux-heavy, M365-concentrated midmarket. The load-bearing confirmation comes from the non-Dutch, broader-telemetry sources (Verizon DBIR EMEA, Mandiant, NCC Group, SOCRadar).
Per-Region Top 5 Most-Targeted Sectors (2025–2026)
⭐ marks the highest-confidence finding in each region (multi-source agreement). UK shown through the leak-site / extortion lens for comparability.
| # | Benelux | DACH | UK (leak-site) | Nordics |
|---|---|---|---|---|
| 1 | Manufacturing Eye 25% | Manufacturing ⭐ | Industrials / Mfg & OT 28% ⭐ | Finance & Insurance 20% |
| 2 | Construction / Real Estate Eye 17% | Retail & e-commerce | Retail / Consumer (M&S, Co-op, JLR) | Retail / Wholesale |
| 3 | Business / IT / professional svcs | Government / public admin | Professional & technical svcs | Public administration |
| 4 | Financial services Eye 9% | Technology / IT & MSP / telecom | Healthcare | Crypto / NFT (dark-web artifact) |
| 5 | Government & healthcare | Healthcare | Public sector / CNI | ICT / Telecom |
UK has two contradicting datasets. The leak-site lens (above) makes retail a headline target (the 2025 brand wave). The Gov Breaches Survey ranks differently by self-reported prevalence: Information & communication 63%, Professional/scientific/technical 54% — with retail below average. Both are correct at their own scope: large-brand extortion vs broad SME prevalence.
Pan-Regional Robust Core
Sectors appearing in the top 5 of three or more regions — the de-biased core that survives the methodology differences.
| # | Sector | Coverage | Note |
|---|---|---|---|
| 1 | Manufacturing / Industrials | 3 of 4 | Anomaly: absent from the Nordic top 5 — likely a real economic-mix difference, partly a SOCRadar dark-web artifact (low confidence on the absence) |
| 2 | Retail / Consumer Discretionary | 4 of 4 | Defining UK story of 2025 |
| 3 | Government / Public administration | 4 of 4 | Nordics reinforced by the Miljödata hit (~80% of Swedish municipalities) |
| 4 | IT / Technology / Telecom service providers | 4 of 4 | Supply-chain / MSP leverage; Danish CFCS raised the telecom threat level Nov 2025 |
| 5 | Healthcare | 3 of 4 | Top 5 in UK, DACH, Benelux; present in Nordics |
The Wild Card: Financial Services
Finance is #1 in the Nordics, mid-pack in Benelux and DACH, but low in UK leak-site data. UK finance is breached often but rarely publicly extorted — it is large, well-defended, and does not pay on leak sites. Where finance ranks tells you which lens you are looking through more than which region you are in. If you are pitching a financial-services prospect, lead with the regional lens that matches their actual exposure, not the headline number.
Confidence & Honest Gaps
Highest-confidence single finding: Manufacturing / Industrials is #1 by leak-site / extortion volume in Benelux, DACH and the UK — corroborated by Eye, Northwave, Yarix, Acronis, Check Point, NCC Group (every monthly pulse) and Sophos AAR (19.8% global). Solid. Everything below position 1, and the entire Nordic ranking, rests on thinner or methodologically-divergent ground.
- Austria is a genuine data gap — no public sector-ranked breakdown surfaced; available Austrian data is attack-type, not sector-ranked.
- UK retail contradiction is real — leak-site (headline target) vs survey (below average). Both correct at their own scope.
- Nordic ranking rests on one ranked dataset (SOCRadar dark-web/leak-site aggregate); national CERTs publish threat levels and sector elevations, not victim-count rankings.
- Vendor visibility bias throughout — MDR/leak-site lenses over-represent sectors with high availability dependence (manufacturing, healthcare) that pay ransoms, and under-count sectors that under-report.
Sources
- Benelux: Eye Security — The State of BEC 2026; Northwave — Global Threat Landscape 2026 (both Dutch MDR/IR; NL/Benelux-heavy).
- DACH: Yarix/Var Group Germany Country Report 2025; Acronis Germany 2025; Check Point DACH 2025; BSI Lagebericht 2025; Swiss NCSC/BACS Annual 2025.
- UK: NCC Group Annual CTI Report 2025 + Monthly Threat Pulse; UK NCSC Annual Review 2025; UK Gov Cyber Security Breaches Survey 2025/2026.
- Nordics: SOCRadar Nordic Threat Landscape Report 2025; Truesec TIR 2026; Danish CFCS / DDIS 2025; Finnish NCSC-FI / Supo 2025.
- Cross-region anchors: Sophos Active Adversary Report 2026; Verizon DBIR 2026 (EMEA cut); Mandiant M-Trends 2026.