research

Western Balkans CNI Attack Surface Research | ThingsRecon

Research across 224 critical infrastructure organizations in two Western Balkan countries reveals a persistent attack surface finding.

Network visualization representing critical infrastructure attack surface research in the Western Balkans
224
CNI organizations scanned
2 Western Balkan Countries
610+
Domains mapped
April 2026
8,662
Live applications discovered
Across both countries
4,006
Fix Now findings
Anonymized · aggregate

Risk doesn't spread evenly — it concentrates

A small fraction of organizations accounts for the majority of critical exposure in both countries. The pattern is consistent, and it's not about security maturity.

Country B — 22 CNI organizations
89%
of all Fix Now vulnerabilities
concentrated in just 36% of organizations
8 Critical projects1,043 issues
8
Critical projects
95.5%
Carry Fix Now issues
Resolving the Critical tier alone eliminates 1,043 immediate vulnerabilities — without touching the other 14 organizations.
Country A — 202 CNI organizations
92.6%
of all organizations carry at least 1 Fix Now issue
11 Critical projects (5.4%)881 issues · 31% of total
2,832
Fix Now issues
202
projects evaluated
Country A shows a more distributed risk profile — 64% of organizations fall in the Moderate tier, creating systemic baseline exposure that's harder to remediate at scale.

Severity profile by country

Country B shows heavy concentration at the critical end. Country A distributes more broadly, with 64% of projects in the moderate tier — a different kind of problem.

Country B | 22 Projects

1,174 Fix Now · 101 Domains · 2,292 Live Apps
Critical
36%
8 projects
High
14%
3 projects
Moderate
45%
10 projects
Clean
5%
1 project
Telecoms and government represent 5 of 8 critical-tier organizations in Country B.

Country A | 202 Projects

2,832 Fix Now · 509 Domains · 6,370 Live Apps
Critical
5%
11 projects
High
23%
46 projects
Moderate
64%
130 projects
Clean
5%
11 projects
64% in Moderate tier means systemic baseline exposure — distributed, hard to remediate at scale without coordinated tooling.

The visibility gap is bigger than the vulnerability gap

Across both countries, the discovery phase alone surfaced hundreds of previously untracked domains and live applications. This isn't new infrastructure — it's existing exposure that was never visible.

+3,277
Live apps discovered in a single scan cyclefor one Country B government entity
+2,958
New live apps surfaced in one periodfor one Country An telecoms operator
100%
CNI coverage achieved in Country Bvs. 79% in Country A — gap still being closed
"You cannot remediate assets you don't know exist. For organizations operating at national scale, the gap between assumed scope and actual attack surface is the real problem." All Things Cyber

Episode 5 · Cyberattacks on Critical National Infrastructure

What the data shows by vertical

Four sectors with distinct risk profiles — and distinct implications for security teams and decision-makers.

Telecoms icon — replace with Webflow asset
Telecoms
Consistently the highest-risk vertical. Largest domain footprints, highest live application counts, and the highest concentration of critical-severity findings across both countries. Multiple operators in the critical tier in Country B alone.
Highest footprint growth rate of any sector
Banking icon — replace with Webflow asset
Banking
Exposure is real but distributed across severity tiers. The risk is in the tail: moderate-severity institutions carrying a small number of high-impact findings that aggregate scores obscure. Multiple international and regional banks represented across both countries.
Present at every severity tier in both countries
Government icon — replace with Webflow asset
Government & Public Sector
Digital expansion — EU accession, digitization mandates, pandemic-era migration — has been fast. Security visibility hasn't kept pace. Broad, moderate-severity exposure distributed across many institutions. No single focal point, which makes remediation harder, not easier.
Fastest attack surface expansion rate
Energy icon — replace with Webflow asset
Energy & Utilities
Present across all severity tiers in both countries. The combination of critical operational relevance and incomplete digital visibility makes this sector the highest-consequence target in the dataset. Fix Soon backlogs are significant — known work is already substantial.
Highest consequence if exploited

All data anonymized and aggregated. No organization-specific findings disclosed. ThingsRecon Research, April 2026

Save your seat

Sample scan only inspects public, external assets. Results delivered in 48–72 hours. No agents, no install.

For information about how ThingsRecon handles your personal data, please see our Privacy Policy.

Thank you! We’ll be in touch soon.
In the meantime, explore our Resource Center. It’s packed with insights, videos, and practical guides on attack surface discovery and supply chain risk.
Oops! Something went wrong while submitting the form.