← All articles

Denmark's Destructive Cyber Threat Level Is High: 5 Endpoint Questions

SAMSIK lists client and software updates as a separate line in its advice. That line lands directly in endpoint operations.

Denmark’s cyber threat level for destructive cyberattacks is now high, and the Danish Resilience Agency (SAMSIK) lists security updates twice in its advice: once for systems anyone can reach from the internet, and once for employees’ clients and software. The second line lands directly in endpoint operations.

SAMSIK raised the level from medium to high on September 24, 2026, after sharpening its assessment within the medium level in June. The agency now considers it likely that Russia will attempt destructive cyberattacks against Denmark, and its threat assessment names wiper attacks and manipulation of operational technology as the forms these attacks most often take. For IT managers, the practical question is narrower than the headline: can the team show where its endpoints stand on that second line today?

What the Higher Threat Level Means

The assessment rests on three signals. Russia has become more willing to take risks, according to Denmark’s foreign intelligence service (FE). Denmark’s security service (PET) has observed concrete Russian planning and preparation of sabotage against Denmark. And destructive cyberattacks have already hit systems in European NATO countries within the past year.

A wiper attack aims to delete or overwrite data until it becomes unavailable or impossible to restore. That is why SAMSIK’s advice includes offline backup of data and critical systems, and a test that the organization can restore from it.

Why the Warning Reaches Beyond Critical Infrastructure

The assessment names energy, water, and transport as examples of sectors where the threat from Russian state actors likely applies most, especially where operations depend on OT systems. It would be easy to read the change as a matter for utilities alone.

SAMSIK says otherwise. Its main assessment states that the raised level applies across Danish society, though especially to organizations responsible for vital societal functions in critical infrastructure. It also assesses that pro-Russian hacker groups likely have relatively limited technical capabilities and therefore go opportunistically after systems with protection so weak that the attackers can find and enter them easily.

One precision matters here. SAMSIK describes the threat from these groups as aimed particularly at equipment and systems with a low level of protection that attackers can reach directly from the internet. The broad reach is real, but the entry point the agency describes for these groups is not the employee laptop.

What SAMSIK Recommends — and Which Part Sits on the Endpoint

SAMSIK groups its guidance on protecting against destructive cyberattacks under three headings: prevent, detect, and handle attacks. The two update items sit side by side under prevention, with no ranking between them.

SAMSIK lists security updates twice SAMSIK's prevention advice on destructive cyberattacks contains two separate security update items with no ranking between them. The first covers internet-facing systems and services, where pro-Russian groups aim in particular. The second covers employees' clients and software, which lands directly in endpoint operations. The rest of the prevention list covers MFA on remote access, strong passwords, network segmentation, firewalls and access control, tested offline backup, and rehearsed incident plans. SAMSIK Lists Security Updates Twice From its prevention advice on destructive cyberattacks Two items, no ranking UPDATE ITEM 1 Internet-facing systems and services Where pro-Russian groups aim in particular UPDATE ITEM 2 Employees' clients and software Endpoint operations THE REST OF THE PREVENTION LIST MFA on remote access Strong passwords Network segmentation Firewalls, access control Tested offline backup Rehearsed incident plans Source: SAMSIK, Beskyt dig mod destruktive cyberangreb. Grouping and labels: CapaOne.

The rest of the prevention list covers multifactor authentication on remote access, password hygiene, network segmentation, firewalls and access control, offline backup, and rehearsed incident response plans. Those controls matter, and most of them sit outside endpoint patching.

The second update item is where endpoint teams carry direct operational responsibility. SAMSIK does not define software further. From an endpoint management perspective, the check should not stop at Windows itself: third-party applications, runtimes, browsers, and utilities all add to client exposure.

Clients return in the agency’s advice on handling an attack. If an organization identifies a potentially destructive attack, such as a wiper, SAMSIK tells it to isolate affected clients and systems from the rest of the network. The employee laptop may not be where the opportunistic attacker enters, but the advice counts it among the machines an attack reaches.

Five Questions to Answer This Week

SAMSIK asks organizations to revisit their existing security measures now, because it may be too late to start work on countermeasures if the threat becomes more pronounced. For the endpoint share of that advice, five questions show where a team stands.

Do We Know What Runs on Our Clients?

A team cannot update software it does not know exists. That is the starting point for a live application inventory that closes the blind spot where exposure grows: Windows updates are easy to see centrally, while application versions usually are not.

Are Third-Party Applications Current?

Knowing the versions answers half the question. The other half is whether updates reach every endpoint without manual packaging, and whether the team can see which endpoints still lag behind. If each release still needs hand packaging, the backlog grows exactly when the threat level rises — the argument for automating Windows and app patching before the next warning. Drivers sit outside SAMSIK’s wording, but they belong to the same endpoint hygiene, because drivers that were right at deployment drift into crashes and support tickets over time.

Which Gaps Close First?

Few teams can patch everything at once, and a higher threat level makes the order matter more. SAMSIK does not rank its two update items. Its assessment describes the threat from pro-Russian groups as aimed particularly at poorly protected systems that attackers can reach from the internet, which argues for putting those first, with clients on the same list rather than after. Within the client fleet, known exploitation, such as a listing in CISA’s Known Exploited Vulnerabilities catalog, is a stronger signal than a CVSS score alone, and ranking by risk rather than working down a list that never clears keeps the effort on the flaws attackers exploit.

What Happens to What We Cannot Patch?

Some endpoints will not take this week’s update: a line-of-business application breaks, or a vendor fix has not shipped. For those machines, compensating controls hold the exposure at an accepted level until the permanent fix lands, and they stay temporary by design.

Can We Show Where We Stand?

When leadership asks what the higher threat level means for the organization, “we patch regularly” does not answer the question. The answer is a current view of patch status across the fleet: which endpoints run current versions, which still carry open exposure, and what the team closes next.

Where CapaOne Endpoint Management Platform Fits

CapaOne Security Monitor, part of the CapaOne Endpoint Management Platform, maps CVE risk across applications, drivers, and configurations to the endpoints it affects, and exports reports the team can hand to leadership or auditors. SAMSIK also asks organizations to close the vulnerabilities an attacker exploited before they restore from backup. Identifying the exploited flaw is incident-response work, but closing it across the fleet requires knowing which endpoints still carry it, and Security Monitor shows that.

For third-party software, Application Manager automates patching across a curated catalog: it skips endpoints that already comply and remediates the ones that do not. Provision Manager keeps manufacturer-approved driver versions current after deployment. For application vulnerabilities, teams trigger updates directly from a Security Monitor finding, so remediation runs through the same platform that found the exposure, which is the approach behind finding every exposure and fixing what matters first.

CapaOne addresses the visibility and third-party patching part of SAMSIK’s client advice. The rest of the list, from multifactor authentication and segmentation to backup and incident response, calls for other controls, and a credible response plan names them separately.

A Higher Threat Level Is a Test of Visibility

The change on September 24 did not change what good endpoint patching looks like. It raised the cost of any patching that has fallen behind. An organization that can answer the five questions quickly and from current data has operational visibility. One that has to assemble the answers by hand across several systems has a visibility problem, and the higher threat level makes that the more urgent gap to close. To see what that view looks like across your own fleet, book a demo of CapaOne Endpoint Management Platform.

Frequently Asked Questions

What Does Denmark's High Cyber Threat Level Mean for IT Teams?

The level that rose is the threat level for destructive cyberattacks. SAMSIK, the Danish Resilience Agency, now considers it likely that Russia will attempt such attacks against Denmark, most often as wiper attacks or manipulation of operational technology. For IT teams, SAMSIK's guidance asks for security updates on internet-facing systems and on employees' clients and software, alongside multifactor authentication, network segmentation, and offline backup.

Does SAMSIK's Warning Apply to Organizations Outside Critical Infrastructure?

Yes. SAMSIK states that the raised level applies across Danish society, though especially to organizations responsible for vital societal functions in critical infrastructure such as energy, water, and transport. It also assesses that pro-Russian groups go opportunistically after poorly protected systems that attackers can reach from the internet.

How Should a Mid-Sized Organization Prioritize Patching After the Threat Level Rose?

Start with what attackers can reach and what they already exploit. SAMSIK's threat assessment describes pro-Russian groups as going after poorly protected systems they can reach directly from the internet, so those systems belong at the front of the queue. Within the client fleet, vulnerabilities with known exploitation, such as those in CISA's Known Exploited Vulnerabilities catalog, come ahead of the rest of the CVE list, and third-party applications belong in the same queue as the operating system, because SAMSIK names clients and software in the same update item.

Should IT Teams Patch Internet-Facing Systems or Employee Laptops First?

SAMSIK does not rank them. Its guidance lists security updates for internet-facing systems and for employees' clients and software as two separate prevention items, both part of the same list. Its threat assessment describes the threat from pro-Russian groups as aimed particularly at poorly protected systems that attackers can reach directly from the internet.

How Does CapaOne Help With Patching After the Threat Level Rose?

CapaOne Endpoint Management Platform addresses the visibility and third-party software part of SAMSIK's client advice. Security Monitor maps CVE risk across applications, drivers, and configurations to the endpoints they affect, Application Manager automates third-party patching, and Provision Manager keeps drivers current after deployment. SAMSIK's other recommendations, such as multifactor authentication, network segmentation, and backup, call for other controls.

Rikke Borup

Written by

Rikke Borup

CMO, CapaSystems

Rikke is Chief Marketing Officer at CapaSystems, where she has led marketing and communications since 2009. With more than 17 years of experience in the IT sector — including cybersecurity, endpoint management software and IT services — she brings long-standing, practical insight into the challenges facing modern enterprise IT environments.

Trained as a journalist, Rikke specializes in translating complex technical concepts into clear, easy-to-understand communications for IT decision-makers.

Book a Demo →