Cyber risks for software companies: the eight that matter and what to do about them
6 min read Last checked on
Most incidents at software and IT companies do not start with a sophisticated attack, but with a compromised account, an unpatched system or a supplier. According to ENISA, phishing was the way in for 60% of the incidents it analysed in 2024-2025. Knowing eight risks, with an owner and a few measures for each, covers most of your exposure.
Most cyber incidents at software and IT companies do not start with a sophisticated attack, but with something ordinary: an employee who clicks a phishing link, a system that has not been updated for months, or a supplier that is hit itself. According to the ENISA Threat Landscape 2025, phishing was the way in for 60% of the incidents analysed and exploiting vulnerabilities for 21.3%. That is good news: getting the basics right covers most of your exposure.
Why a software company is an attractive target
A software or IT company often has access to something worth more than its own data: the environments and data of its customers. An attacker who gets into your systems may also get into theirs. ENISA sees criminals deliberately targeting these dependencies in the digital supply chain, and the Dutch NCSC lists supply chain incidents that affect customers among the threats to Dutch organizations in its 2025 cybersecurity assessment.
That is why customers increasingly ask how you have organized your security, and why some IT suppliers fall under NIS2, directly or through their customers.
The eight risks that matter
1. Account takeover
An attacker gains access to an employee's account, often email or cloud, through phishing, a leaked password or a fake login page. From there they read along, send payment requests or look for access to customer environments.
What helps: strong authentication, preferably phishing-resistant, on every account; a fixed procedure for password resets; awareness that shows what phishing looks like today. In ISO 27001 this comes back in controls 5.17, 6.3 and 8.5, among others.
2. Ransomware
Criminals encrypt systems, often steal data as well, and demand a ransom for both. The Dutch cybersecurity assessment counts at least 121 unique ransomware incidents in the Netherlands in 2024, and ENISA calls ransomware the most impactful threat in the EU.
What helps: the measures against account takeover and vulnerabilities, plus backups kept separate from production that you know you can restore. A rehearsed continuity plan determines how quickly you are running again.
3. Misconfigured access rights
Former employees who still have access, developers with production admin rights they don't need, shared accounts without an owner. Access grows by itself; it only shrinks when someone reviews it.
What helps: role-based access, a fixed process when people join and leave, and a periodic access review in which an owner per system confirms who may do what. In ISO 27001: 5.15, 5.18 and 6.5.
4. Vulnerabilities left open
A known vulnerability in a VPN, a firewall or a web application is exploited within days. The Dutch NCSC sees attackers using edge devices, such as VPN servers and firewalls, to get into a network.
What helps: an up-to-date overview of your systems, an agreement on how quickly critical updates are applied, and someone who follows vendor advisories. In ISO 27001: 5.9, 8.8 and 8.9.
5. Weak suppliers
Your hosting, your support tool, your development platform and your payroll provider all have access to something that matters to you. If one of them is hit, it affects you and your customers.
What helps: knowing which suppliers process which data and how critical they are, security terms in the contract, and a periodic reassessment of the suppliers that matter. In ISO 27001: 5.19 to 5.23. NIS2 explicitly lists supply chain security as part of the duty of care.
6. Lost or stolen devices
A laptop on the train, a phone in a taxi. Without encryption and management, the contents are exposed, including stored sessions to customer environments.
What helps: disk encryption, central management that lets you wipe a device remotely, and a quick way for employees to report a loss. In ISO 27001: 8.1 and 7.9.
7. Backups that don't work
A backup that has never been restored is an assumption. In a ransomware attack, backups on the same network are often encrypted too.
What helps: backups separate from production, a recorded recovery time per service and a restore test at least once a year, with the result as evidence. In ISO 27001: 8.13 and 5.30.
8. Human error with customer data
An export sent to the wrong address, a test environment with real customer data, a folder shared publicly. Not every mistake is an attack, but the consequence for the customer can be the same.
What helps: clear agreements on working with customer data, no production data in test without a reason, and an incident procedure in which reporting is normal rather than punished. In ISO 27001: 5.10, 5.24 to 5.26 and 8.33.
From a list to a risk picture
A list of risks is a start. It becomes a risk picture once you record three things for each risk:
- What it affects. Which systems, data, processes and suppliers.
- How much it weighs. An estimate of likelihood and impact, using a method you apply the same way every time.
- What you do about it and who owns it. The measures that reduce the risk, and who accepts what remains.
Start with the eight risks above and ask for each: does this apply to us, and what would it cost us and our customers? For a company of 30 people this usually produces a useful first picture in an afternoon.
What standards and regulations do with it
Standards and regulations essentially all ask the same thing: know your risks, take appropriate measures and show that you do.
- ISO 27001 asks for repeatable risk assessment and treatment in clauses 6 and 8, and a reasoned choice from the controls in Annex A.
- NIS2, implemented in the Netherlands as the Cyberbeveiligingswet, starts the duty of care with a risk analysis and also covers incident handling, business continuity, supply chain security, cyber hygiene and strong authentication.
- The GDPR asks for appropriate technical and organizational measures, matched to the risk for the people whose data you process.
If you keep your risk picture current, you already have most of the answer for all three.
Keeping it current
Cyber risks change with your organization. Reassess them at least once a year, and whenever something changes: a new system, a new supplier, a growing team or an incident. The Dutch NCSC advises the average organization not to get lost in the complex threat landscape, but to get the basic principles in order and keep them there. Trustbird helps by linking your risks to the systems, suppliers and measures they concern, and lining up a reassessment as soon as a change affects a risk.
Frequently asked questions
What are the biggest cyber risks for a software company?
Account takeover through phishing, ransomware, misconfigured access rights, vulnerabilities in systems that are not updated in time, weak suppliers, lost or stolen devices, backups that cannot be restored and human error with customer data. Together they account for the large majority of incidents at small and mid-sized IT companies.
Do I need a security specialist to map my cyber risks?
No. You can build a first risk picture with the people who know your systems, customers and suppliers. What matters is that for each risk you know what it affects, how likely it is, which measures are in place and who owns it. For specific technical questions you can bring in targeted advice later.
How often should I reassess my cyber risks?
At least once a year, and also after every change that affects a risk, such as a new system, a new supplier, a reorganization or an incident. ISO 27001 asks for risk assessments at planned intervals and when significant changes occur.
Does an ISO 27001 certificate prevent cyber incidents?
No. A certificate shows that you manage risks systematically and that measures are in place. It reduces the likelihood and impact of incidents, but no standard or software can rule them out.
Read next
Incidents and continuity
Business continuity plan for a software company: what it should contain
Read more
Security governance and policy
What an ISMS is, and why a spreadsheet stops at the second standard
Read more
Law and regulation
NIS2 duty of care and incident reporting: what your customers will ask of you
Read more
Customer trust and sales
Answering customer security questionnaires: get it right once, then reuse
Read more
Incidents and continuity
Tabletop exercise: how to test your incident and continuity plan in 90 minutes
Read more
Sources
- ENISA, Threat Landscape 2025
- ENISA, EU consistently targeted by diverse yet convergent threat groups
- NCSC Netherlands, Cybersecuritybeeld 2025 (Dutch)
- NCSC Netherlands, Basisprincipes (Dutch)
- NCSC Netherlands, Duty of care under the Cyberbeveiligingswet (Dutch)
- ISO, ISO/IEC 27001 Information security management systems
Trustbird helps organizations become cyber proof and stay that way, with compliance as the result you can show. It is being built with two certified design partners, and we are looking for more companies to join them.
Become a design partner