In Focus Security

The Research & Education (R&E) Threat Landscape 2026: What security leaders need to know

Threat landscape report diagram
R&E Threat Landscape 2026

The European R&E sector has long prided itself on openness, collaboration, and the unrestricted flow of ideas. But in 2026, that very culture of openness, coupled with decentralised infrastructure, external dependencies and valuable intellectual property, has made it a prime target for cyber adversaries. At the same time, recently emerged threats are disrupting the security landscape at an unprecedented pace.

Following GÉANT’s landmark Threat Landscape Workshop in March 2026, the community has released its first-ever dedicated security forecast: the R&E Threat Landscape 2026 report.

We sat down with Roderick Mooi, Principal Security Engineer at GÉANT, to discuss why the R&E sector is under attack, the accelerating influence of AI, and what institutions must do right now to defend their networks, data and people.

Roderick, this is the first dedicated threat landscape report specifically for the European R&E community. Why now? What makes our sector so uniquely vulnerable compared to corporate enterprises?

For years, R&E operated under a bit of a protective umbrella, and people assumed academic networks weren’t primary targets. But in recent years that has changed, with multiple universities falling victim to ransomware and other cyberattacks plaguing the sector. Geopolitical developments and supply chain dependencies complicated the environment, and then AI entered the picture. Now existing cyber threats are enhanced and accelerated by LLMs and GPTs, almost gaining superpowers; and let’s not forget the looming threat of quantum computers being used to break/weaken encryption. Yet, essential cyber hygiene practices, and our resources to implement these, have not matured as rapidly. Our adversaries are constantly innovating, faster than ever before, and so must we.

Balancing cutting-edge security practices with the freedom that our students and researchers need to collaborate globally is key. The report highlights that we need a tailored defence strategy built by the community, for the community so that we can be more resilient, together.

The report highlights Artificial Intelligence, not just as a standalone threat, but also as an accelerator. How is AI changing the game?

AI is essentially a force multiplier for bad actors. It lowers the barrier to entry, allowing attackers to scale up social engineering campaigns with highly convincing and personalised messaging enhanced by deepfakes and other novel techniques. What was once the playing field of only the most advanced, best resourced adversaries, has become accessible to everyone. Custom malware development has become trivial, and attacks are increasingly automated, significantly reducing time to compromise. AI has also been used for vulnerability discovery by both attackers and defenders, significantly impacting patch cycles.

The use of AI itself also presents new risks. We’re seeing an explosion of ‘vibe coding’ – where LLMs and AI agents are used to generate code without the user fully understanding the security implications – alongside ungoverned AI (chat) use that can result in sensitive data leakage. We are therefore urging organisations to mandate AI usage policies and utilise AI impact assessments to help mitigate these threats while encouraging the responsible use of AI.

One surprising takeaway from the report is that “weak cyber hygiene” is now the leading route for attackers to gain initial access. Why is this and what does it mean?

The report emphasises that weak cyber hygiene is driven by under-resourced, over-stretched security teams, not negligence. When teams are understaffed, unpatched systems pile up, shadow IT creeps in, and credential management slips through the cracks. We must move away from blaming users and shift toward user-centred security practices (including appropriate training and awareness) as well as secure-by-design zero-trust architectures. We need to fund our defenders so that they have the bandwidth to manage vulnerabilities and effectively secure our people, networks and data, while empowering organisations to achieve their goals and objectives.

Geopolitical tensions are at an all-time high, and the report mentions Internet Service Providers (ISPs) being targeted as well as politically motivated denial-of-service attacks. How is the physical geopolitical landscape flowing into NRENs?

Physical conflicts and supply shortages – from devastating wars to oil supplies – directly affect NRENs and R&E organisations. The AI race has resulted in GPU and memory shortages; severely restricting IT equipment supplies and inflating prices. And as you mentioned, ISPs and communications networks are increasingly seen as critical infrastructure and targeted accordingly (this also ties into regulatory developments, such as NIS2). Lastly, certain politically contentious opinions/support initiatives have been linked to hacktivism and attacks from “sympathisers”. Together, all of these illustrate how important it is to monitor global geopolitical developments and adjust our responses accordingly.

There is a mention of Quantum Computing and the concept of “store-now, decrypt-later” attacks. Should we be panicking about quantum today?

Panic isn’t helpful, but proactive action is mandatory. Cryptographically relevant quantum computers are on the horizon, with some recent claims of this being practical in 5-10 years, if not sooner. Threat actors know this, so they are stealing and storing encrypted data right now with the hope that they can decrypt it in the (near) future and thereby access sensitive information.

Thus, we need to ask ourselves – which encrypted data, transported via our networks and stored in our datacentres/systems today, presents a risk if decrypted in, say, 3–5 years? We must inventory all our cryptographic assets now and prioritise the migration of those most at risk to post-quantum (safer) algorithms, without neglecting the rest. When Q-Day comes, it will be too late.

Finally, Roderick, the report points out a cultural hurdle: a persistent reluctance to share threat data across the community due to reputational and legal fears. How do we overcome this?

This is perhaps our biggest challenge. Keeping quiet out of fear of reputational damage only helps the attackers; it leaves the rest of the sector blind and reactive. In fact, transparent disclosures and good communications have repeatedly placed victim organisations in a positive light, reassuring customers and investors, versus the negative press that can result from silence/sparse information. But the challenge is not so much sharing data between NRENs – we are making good, ongoing progress in that regard; it’s getting the data from constituents to the NRENs in the first place. There is a general reluctance to share, at times for lack of reporting channels/communities and perhaps even trust, but in other instances, the lack of clear processes, time pressures or legal uncertainty hinder effective sharing.

We must build a culture of collective defence. Technical barriers aren’t the issue – the tools exist. We need leadership to champion participation in intelligence-sharing initiatives, such as the R&E Security Intelligence Hub and the Security Policy Alliance, crisis exercises, and to ensure timely sharing of data within the community.

Explore the GÉANT R&E Threat Landscape 2026

The GÉANT R&E Threat Landscape 2026 brings together the collective expertise and experience of the European R&E security community to identify the ten highest-priority cyber threats facing NRENs and the wider sector, alongside practical recommendations for reducing and remediating the risks. We would like to thank all the contributors that made the workshop and report possible!

The report is TLP:GREEN and available to GÉANT project participants through the shared online space.

NRENs and R&E organisations that would like to learn more about the report can contact Roderick Mooi.

Skip to content