Norwegian assessment: familiar methods, greater consequences
Norway's latest cybercrime assessment for 2026 describes gradual but important shifts rather than dramatic change. Phishing and initial access techniques continue to grow, while criminals increasingly exploit supply chains and smaller organisations as entry points. AI and automation make attacks more scalable, targeted and convincing.
What this means for your organisation
The message is uncomfortable precisely because the methods are familiar: risk is driven not by novel attack types but by old ones landing more broadly and more precisely. For a Norwegian organisation, a small subcontractor may be the easiest way in, and fraudulent messages are increasingly hard to spot from language and form alone. This sits at the core of the NIS2 requirements on supply chain security.
Berigo recommends
- Map which suppliers have access to systems or data, and set security requirements proportionate to that access.
- Base training on verifying requests through a separate channel, not on spotting language errors.
- Introduce phishing-resistant authentication on the most important services.
- Bring the threat picture into the board's risk review, with consequences and measures described in business terms.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch