research report

Attack Surface Across Critical National Infrastructure Western Balkans

Continuous discovery scanning across Albania and Kosovo — 224 CNI organizations, two countries, one persistent finding.

224
CNI organizations scanned
Albania · Kosovo
610+
Domains mapped
April 2026
8,662
Live applications discovered
Across both countries
4,006
Fix Now findings
Anonymized · aggregate

Risk doesn't spread evenly — it concentrates

A small fraction of organizations accounts for the majority of critical exposure in both countries. The pattern is consistent, and it's not about security maturity.

Kosovo — 22 CNI organizations
89%
of all Fix Now vulnerabilities
concentrated in just 36% of organizations
8 Critical projects1,043 issues
8
Critical projects
95.5%
Carry Fix Now issues
Resolving the Critical tier alone eliminates 1,043 immediate vulnerabilities — without touching the other 14 organizations.
Albania — 202 CNI organizations
92.6%
of all organizations carry at least 1 Fix Now issue
11 Critical projects (5.4%)881 issues · 31% of total
2,832
Fix Now issues
202
projects evaluated
Albania shows a more distributed risk profile — 64% of organizations fall in the Moderate tier, creating systemic baseline exposure that's harder to remediate at scale.

Severity profile by country

Kosovo shows heavy concentration at the critical end. Albania distributes more broadly, with 64% of projects in the moderate tier — a different kind of problem.

Kosovo | 22 Projects

1,174 Fix Now · 101 Domains · 2,292 Live Apps
Critical
36%
8 projects
High
14%
3 projects
Moderate
45%
10 projects
Clean
5%
1 project
Telecoms and government represent 5 of 8 critical-tier organizations in Kosovo.

Albania | 202 Projects

2,832 Fix Now · 509 Domains · 6,370 Live Apps
Critical
5%
11 projects
High
23%
46 projects
Moderate
64%
130 projects
Clean
5%
11 projects
64% in Moderate tier means systemic baseline exposure — distributed, hard to remediate at scale without coordinated tooling.

The visibility gap is bigger than the vulnerability gap

Across both countries, the discovery phase alone surfaced hundreds of previously untracked domains and live applications. This isn't new infrastructure — it's existing exposure that was never visible.

+3,277
Live apps discovered in a single scan cyclefor one Kosovo government entity
+2,958
New live apps surfaced in one periodfor one Albanian telecoms operator
100%
CNI coverage achieved in Kosovovs. 79% in Albania — gap still being closed
"You cannot remediate assets you don't know exist. For organizations operating at national scale, the gap between assumed scope and actual attack surface is the real problem." All Things Cyber

Episode 5 · Cyberattacks on Critical National Infrastructure

What the data shows by vertical

Four sectors with distinct risk profiles — and distinct implications for security teams and decision-makers.

Telecoms icon — replace with Webflow asset
Telecoms
Consistently the highest-risk vertical. Largest domain footprints, highest live application counts, and the highest concentration of critical-severity findings across both countries. Multiple operators in the critical tier in Kosovo alone.
Highest footprint growth rate of any sector
Banking icon — replace with Webflow asset
Banking
Exposure is real but distributed across severity tiers. The risk is in the tail: moderate-severity institutions carrying a small number of high-impact findings that aggregate scores obscure. Multiple international and regional banks represented across both countries.
Present at every severity tier in both countries
Government icon — replace with Webflow asset
Government & Public Sector
Digital expansion — EU accession, digitization mandates, pandemic-era migration — has been fast. Security visibility hasn't kept pace. Broad, moderate-severity exposure distributed across many institutions. No single focal point, which makes remediation harder, not easier.
Fastest attack surface expansion rate
Energy icon — replace with Webflow asset
Energy & Utilities
Present across all severity tiers in both countries. The combination of critical operational relevance and incomplete digital visibility makes this sector the highest-consequence target in the dataset. Fix Soon backlogs are significant — known work is already substantial.
Highest consequence if exploited

All data anonymized and aggregated. No organization-specific findings disclosed. April 2026