Statistics

Telecom Cybersecurity Statistics: Incidents, Causes, and User-Hour Losses

ENISA telecom cybersecurity statistics on incidents, causes, and user-hour losses across 2016 to 2024.

Table of contents

At a glance

Telecom cybersecurity statistics from ENISA show a sector that keeps generating a high volume of incidents, with the latest annual summary reporting 188 incidents in 2024 across 26 EU Member States and 2 EFTA countries (ENISA Telecom Security Incidents 2024).

That 2024 total was 20.5% higher than 2023, while ENISA also reported a significant drop in user hours lost compared with 2022 and 2023 (ENISA Telecom Security Incidents 2024).

Fast facts

  • 188 incidents in 2024 from national authorities (ENISA Telecom Security Incidents 2024).
  • 156 incidents in 2023 in the previous annual summary (ENISA Telecom Security Incidents 2024).
  • 168 incidents in 2021 and 170 incidents in 2020 in earlier annual reports (ENISA Telecom Security Incidents 2021; ENISA Telecom Security Incidents 2020 - Annual Report).
  • 5,106 million user hours lost in 2021 (ENISA Telecom & Trust Services Incidents in 2021 press release).
  • 841 million user hours lost in 2020 (ENISA Telecom Security Incidents 2020 - Annual Report).
  • 153 major incidents in 2019 and 157 outages in 2018 (ENISA Telecom Services Security Incidents 2019 Annual Analysis Report; ENISA Telecoms taken by storm press release).

The sector’s headline story is not just incident volume. It is the scale of disruption when failures cascade into user-hour losses.

What the telecom cybersecurity numbers show

The dataset points to a repeating pattern: telecoms face a steady stream of incidents, but the severity of disruption varies sharply by year and by root cause. Some years are defined by incident counts; others are defined by the hours lost when systems fail, updates misfire, or external conditions knock networks offline.

Why it matters Telecom networks sit underneath emergency services, mobile internet, and everyday connectivity. When a telecom security incident spreads, the effects do not stay confined to a single operator or a single technical layer (ENISA annual report on telecom security incidents 2016; ENISA 169 telecom incidents reported, extreme weather major factor).

A few themes repeat across the supplied statistics:

  • National authority reporting spans both EU Member States and EFTA countries in multiple years (ENISA Telecom Security Incidents 2024; ENISA Telecom Security Incidents 2021; ENISA Telecom Security Incidents 2020 - Annual Report; ENISA annual report on telecom security incidents 2016).
  • System failures appear repeatedly as a major cause category across several years (ENISA Telecom Security Incidents 2020 - Annual Report; ENISA annual report on telecom security incidents 2016; ENISA 169 telecom incidents reported, extreme weather major factor; ENISA Telecoms taken by storm press release).
  • Human error and third-party failure remain durable contributors to outage impact, especially when measured in user hours lost or incident shares (ENISA Telecom & Trust Services Incidents in 2021 press release; ENISA Telecom Services Security Incidents 2019 Annual Analysis Report; ENISA 169 telecom incidents reported, extreme weather major factor).

Year-by-year incident counts

The most useful way to read these telecom cybersecurity statistics is as a timeline. Incident counts do not move in a straight line, but they do show that telecom security reporting has been consistently active for years.

YearIncidents or outagesGeographic coverageSource label
2024188 incidents26 EU Member States, 2 EFTA countriesENISA Telecom Security Incidents 2024
2023156 incidents26 EU Member States, 1 EFTA countryENISA Telecom Security Incidents 2024
2021168 incidents26 EU Member States, 2 EFTA countriesENISA Telecom Security Incidents 2021
2020170 incidents26 EU Member States, 2 EFTA countriesENISA Telecom Security Incidents 2020 - Annual Report
2019153 major incidentsNot stated in the supplied datasetENISA Telecom Services Security Incidents 2019 Annual Analysis Report
2018157 outagesEU member states and EFTA countriesENISA Telecoms taken by storm press release
2017169 incidentsNot stated in the supplied datasetENISA 169 telecom incidents reported, extreme weather major factor
2016158 incident reports24 countries, 2 EFTA countriesENISA annual report on telecom security incidents 2016

2024 stands out on count, not necessarily on disruption

The 2024 annual summary is the highest incident total in the supplied data set, at 188 incidents (ENISA Telecom Security Incidents 2024). That is a useful headline, but it does not automatically mean 2024 was the most damaging year.

ENISA said 2024 showed a significant drop in user hours lost compared with 2022 and 2023 (ENISA Telecom Security Incidents 2024). That matters because telecom cybersecurity is not just about how many incidents are reported. It is also about how much disruption each incident creates.

2023 is lower in count, but still part of the same pattern

The 2023 annual total was 156 incidents (ENISA Telecom Security Incidents 2024). That is lower than 2024, but it is still within the same broad range as many other years in the dataset.

The practical takeaway is that telecom cybersecurity risk appears persistent rather than episodic. One year can rise, another can fall, but the reporting baseline remains active across the timeline.

2021 and 2020 show how severity can diverge from count

In 2021, ENISA reported 168 incidents (ENISA Telecom Security Incidents 2021). In 2020, the annual report recorded 170 incidents (ENISA Telecom Security Incidents 2020 - Annual Report). Those totals are similar to each other, yet the user-hour losses are dramatically different, which makes the next section more revealing than the count comparison alone.

User hours lost and impact

If incident counts show frequency, user hours lost show scale. That is where the dataset becomes especially important for telecom cybersecurity statistics.

Big number: 5,106 million user hours lost in 2021 (ENISA Telecom & Trust Services Incidents in 2021 press release).

That figure is far above the 841 million user hours lost in 2020 (ENISA Telecom Security Incidents 2020 - Annual Report). The difference is not a small fluctuation. It is a reminder that the same broad type of sector can produce very different disruption totals depending on what actually goes wrong.

What the loss figures suggest

  • 2021 was a severe disruption year in terms of user hours lost, even though its incident count of 168 was close to 2020’s 170 (ENISA Telecom Security Incidents 2021; ENISA Telecom Security Incidents 2020 - Annual Report).
  • ENISA said human errors accounted for 90% of user hours lost in 2021 (ENISA Telecom & Trust Services Incidents in 2021 press release).
  • ENISA also noted that the 2021 total user-hours loss was more than 4 times higher than 2020 (ENISA Telecom & Trust Services Incidents in 2021 press release).

That combination is the main lesson: the cost of an incident is not proportional only to the number of incidents. A smaller set of errors can generate a much larger service-impact footprint.

2020: a lower disruption year, but still significant

The 2020 report recorded 841 million user hours lost (ENISA Telecom Security Incidents 2020 - Annual Report). ENISA added that faulty software changes and/or updates caused 346 million user hours lost in 2020, which represented 40% of total user hours lost (ENISA Telecom & Trust Services Incidents in 2020 press release).

That is a precise and useful telecom cybersecurity benchmark:

  • software changes can be a major disruption driver,
  • one cause category can account for a very large share of the total,
  • and user-hour totals can stay high even when the number of incidents is not at its peak.

2018 shows another large disruption year

In 2018, ENISA said 157 outages produced 960 million user hours lost, which averaged around 2 hours per subscriber per year (ENISA Telecoms taken by storm press release).

ENISA also said natural phenomena caused 480 million user hours lost in 2018, or 50% of total user hours lost (ENISA Telecoms taken by storm press release). That is important because it shows the sector’s exposure is not only internal. External conditions can have a massive share of the total impact.

Main cause patterns

The dataset includes several different cause categories across the years. The names vary a little by report, but the underlying pattern is consistent: telecom incidents are frequently driven by system issues, human errors, third-party failures, and external events.

System failures keep showing up

System failures recur across the supplied reports:

  • System failures were the most frequent cause of telecom incidents in 2020 (ENISA Telecom & Trust Services Incidents in 2020 press release).
  • System failures caused almost 73% of 2016 incidents (ENISA annual report on telecom security incidents 2016).
  • System failures made up 62% of incidents in 2017 (ENISA 169 telecom incidents reported, extreme weather major factor).
  • System failures made up 67% of incidents in 2018 (ENISA Telecoms taken by storm press release).

These figures are not directly comparable across all years because some are shares of incidents and others are cause summaries, but together they point in one direction: system-level problems remain central to telecom cybersecurity risk.

Human error remains a high-impact issue

Human error appears in two different ways in the dataset.

First, it shows up as a root cause share:

  • Human errors were the root cause of 26% of incidents in 2019 (ENISA Telecom Services Security Incidents 2019 Annual Analysis Report).
  • Human-error incidents increased by 50% versus the previous year in 2019 (ENISA Telecom Services Security Incidents 2019 Annual Analysis Report).

Second, it dominates impact in 2021:

  • Human errors accounted for 90% of user hours lost in 2021 (ENISA Telecom & Trust Services Incidents in 2021 press release).

That combination is striking. Human error does not just contribute to incident frequency. In some years it is the main driver of the hours people lose when telecom systems fail.

Third-party failures are a persistent secondary risk

Third-party failure also appears multiple times:

  • Third-party failures were flagged in 32% of 2019 incidents (ENISA Telecom Services Security Incidents 2019 Annual Analysis Report).
  • Third-party failures caused 21.5% of all 2016 incidents (ENISA annual report on telecom security incidents 2016).
  • Third-party failures caused 21.5% of 2017 incidents (ENISA 169 telecom incidents reported, extreme weather major factor).

A useful way to read this is that telecom cybersecurity risk is not contained entirely within the operator. External dependencies matter, and they can show up repeatedly across years.

Environmental and infrastructure events still matter

The sector is also exposed to non-digital disruption drivers:

  • Natural phenomena caused 17% of 2017 incidents (ENISA 169 telecom incidents reported, extreme weather major factor).
  • Power outages caused 22% of 2017 incidents (ENISA 169 telecom incidents reported, extreme weather major factor).
  • Power cuts were a primary or secondary cause in more than a fifth of 2019 incidents (ENISA Telecom Services Security Incidents 2019 Annual Analysis Report).
  • Natural phenomena caused 50% of user hours lost in 2018 (ENISA Telecoms taken by storm press release).

That means telecom cybersecurity planning cannot be limited to malware or unauthorized access. Physical, environmental, and infrastructure failures still shape the operational picture.

What changed from 2016 to 2024

A decade-scale reading of the statistics shows a sector that has been under steady pressure for years.

A compact comparison of selected milestones

PeriodMain signalNotable figureSource label
2016Broad incident reporting base158 incident reportsENISA annual report on telecom security incidents 2016
2017System failures and external disruptions169 incidentsENISA 169 telecom incidents reported, extreme weather major factor
2018High user-hour disruption960 million user hours lostENISA Telecoms taken by storm press release
2019Mixed causes, heavy operational impact153 major incidentsENISA Telecom Services Security Incidents 2019 Annual Analysis Report
2020Software changes and system failures170 incidents; 841 million user hours lostENISA Telecom Security Incidents 2020 - Annual Report; ENISA Telecom & Trust Services Incidents in 2020 press release
2021Extreme service disruption168 incidents; 5,106 million user hours lostENISA Telecom Security Incidents 2021; ENISA Telecom & Trust Services Incidents in 2021 press release
2023Lower annual count than 2024156 incidentsENISA Telecom Security Incidents 2024
2024Highest incident count in the dataset188 incidentsENISA Telecom Security Incidents 2024

The shape of the trend

From 2016 through 2024, several things stay constant:

  • incident reporting remains active every year in the dataset,
  • the causes are not limited to one technical layer,
  • and the gap between incident count and operational impact can be very wide.

The most important shift is not a clean upward or downward line. It is the changing mix of what drives damage. Some years are defined by system failures, some by human error, some by external events, and some by software change-related losses (ENISA Telecom Security Incidents 2020 - Annual Report; ENISA Telecom & Trust Services Incidents in 2020 press release; ENISA Telecom & Trust Services Incidents in 2021 press release).

The reporting footprint also matters

The dataset repeatedly covers 26 EU Member States and 2 EFTA countries in 2024, 2021, and 2020, while 2016 covered 24 countries plus 2 EFTA countries (ENISA Telecom Security Incidents 2024; ENISA Telecom Security Incidents 2021; ENISA Telecom Security Incidents 2020 - Annual Report; ENISA annual report on telecom security incidents 2016).

That reporting footprint gives the statistics weight. These are not isolated anecdotes from one operator or one market. They reflect multi-country reporting over multiple years.

How to read the telecom cybersecurity statistics

These figures are most useful when read as a set of operational signals rather than as isolated headlines.

Use the data this way

  1. Treat incident counts as the frequency signal. The 2024 total of 188 incidents is the latest high-water mark in the supplied data (ENISA Telecom Security Incidents 2024).
  2. Treat user hours lost as the impact signal. The jump from 841 million in 2020 to 5,106 million in 2021 shows why severity matters more than count alone (ENISA Telecom Security Incidents 2020 - Annual Report; ENISA Telecom & Trust Services Incidents in 2021 press release).
  3. Treat cause shares as resilience clues. The repeated presence of system failures, human errors, third-party failures, and power or natural events shows where telecom defenses need depth (ENISA annual report on telecom security incidents 2016; ENISA 169 telecom incidents reported, extreme weather major factor; ENISA Telecom Services Security Incidents 2019 Annual Analysis Report; ENISA Telecom & Trust Services Incidents in 2020 press release; ENISA Telecom & Trust Services Incidents in 2021 press release).
  4. Treat the country coverage as a sign of breadth. The recurring EU and EFTA reporting base means the issue is regional and structural, not local and isolated (ENISA Telecom Security Incidents 2024; ENISA Telecom Security Incidents 2021; ENISA Telecom Security Incidents 2020 - Annual Report).

For anyone comparing telecom cybersecurity statistics across years, the safest interpretation is this: the sector’s incident volume stays material, but the true operational risk swings with cause type, exposure breadth, and how much service time is lost when a failure spreads.

Written by

harrisstratex.com Editorial Team

Editorial team

Independent editorial coverage of networks & connectivity.