Denmark’s cyber threat level for destructive cyberattacks is now high, and the Danish Resilience Agency (SAMSIK) lists security updates twice in its advice: once for systems anyone can reach from the internet, and once for employees’ clients and software. The second line lands directly in endpoint operations.
SAMSIK raised the level from medium to high on September 24, 2026, after sharpening its assessment within the medium level in June. The agency now considers it likely that Russia will attempt destructive cyberattacks against Denmark, and its threat assessment names wiper attacks and manipulation of operational technology as the forms these attacks most often take. For IT managers, the practical question is narrower than the headline: can the team show where its endpoints stand on that second line today?
What the Higher Threat Level Means
The assessment rests on three signals. Russia has become more willing to take risks, according to Denmark’s foreign intelligence service (FE). Denmark’s security service (PET) has observed concrete Russian planning and preparation of sabotage against Denmark. And destructive cyberattacks have already hit systems in European NATO countries within the past year.
A wiper attack aims to delete or overwrite data until it becomes unavailable or impossible to restore. That is why SAMSIK’s advice includes offline backup of data and critical systems, and a test that the organization can restore from it.
Why the Warning Reaches Beyond Critical Infrastructure
The assessment names energy, water, and transport as examples of sectors where the threat from Russian state actors likely applies most, especially where operations depend on OT systems. It would be easy to read the change as a matter for utilities alone.
SAMSIK says otherwise. Its main assessment states that the raised level applies across Danish society, though especially to organizations responsible for vital societal functions in critical infrastructure. It also assesses that pro-Russian hacker groups likely have relatively limited technical capabilities and therefore go opportunistically after systems with protection so weak that the attackers can find and enter them easily.
One precision matters here. SAMSIK describes the threat from these groups as aimed particularly at equipment and systems with a low level of protection that attackers can reach directly from the internet. The broad reach is real, but the entry point the agency describes for these groups is not the employee laptop.
What SAMSIK Recommends — and Which Part Sits on the Endpoint
SAMSIK groups its guidance on protecting against destructive cyberattacks under three headings: prevent, detect, and handle attacks. The two update items sit side by side under prevention, with no ranking between them.
The rest of the prevention list covers multifactor authentication on remote access, password hygiene, network segmentation, firewalls and access control, offline backup, and rehearsed incident response plans. Those controls matter, and most of them sit outside endpoint patching.
The second update item is where endpoint teams carry direct operational responsibility. SAMSIK does not define software further. From an endpoint management perspective, the check should not stop at Windows itself: third-party applications, runtimes, browsers, and utilities all add to client exposure.
Clients return in the agency’s advice on handling an attack. If an organization identifies a potentially destructive attack, such as a wiper, SAMSIK tells it to isolate affected clients and systems from the rest of the network. The employee laptop may not be where the opportunistic attacker enters, but the advice counts it among the machines an attack reaches.
Five Questions to Answer This Week
SAMSIK asks organizations to revisit their existing security measures now, because it may be too late to start work on countermeasures if the threat becomes more pronounced. For the endpoint share of that advice, five questions show where a team stands.
Do We Know What Runs on Our Clients?
A team cannot update software it does not know exists. That is the starting point for a live application inventory that closes the blind spot where exposure grows: Windows updates are easy to see centrally, while application versions usually are not.
Are Third-Party Applications Current?
Knowing the versions answers half the question. The other half is whether updates reach every endpoint without manual packaging, and whether the team can see which endpoints still lag behind. If each release still needs hand packaging, the backlog grows exactly when the threat level rises — the argument for automating Windows and app patching before the next warning. Drivers sit outside SAMSIK’s wording, but they belong to the same endpoint hygiene, because drivers that were right at deployment drift into crashes and support tickets over time.
Which Gaps Close First?
Few teams can patch everything at once, and a higher threat level makes the order matter more. SAMSIK does not rank its two update items. Its assessment describes the threat from pro-Russian groups as aimed particularly at poorly protected systems that attackers can reach from the internet, which argues for putting those first, with clients on the same list rather than after. Within the client fleet, known exploitation, such as a listing in CISA’s Known Exploited Vulnerabilities catalog, is a stronger signal than a CVSS score alone, and ranking by risk rather than working down a list that never clears keeps the effort on the flaws attackers exploit.
What Happens to What We Cannot Patch?
Some endpoints will not take this week’s update: a line-of-business application breaks, or a vendor fix has not shipped. For those machines, compensating controls hold the exposure at an accepted level until the permanent fix lands, and they stay temporary by design.
Can We Show Where We Stand?
When leadership asks what the higher threat level means for the organization, “we patch regularly” does not answer the question. The answer is a current view of patch status across the fleet: which endpoints run current versions, which still carry open exposure, and what the team closes next.
Where CapaOne Endpoint Management Platform Fits
CapaOne Security Monitor, part of the CapaOne Endpoint Management Platform, maps CVE risk across applications, drivers, and configurations to the endpoints it affects, and exports reports the team can hand to leadership or auditors. SAMSIK also asks organizations to close the vulnerabilities an attacker exploited before they restore from backup. Identifying the exploited flaw is incident-response work, but closing it across the fleet requires knowing which endpoints still carry it, and Security Monitor shows that.
For third-party software, Application Manager automates patching across a curated catalog: it skips endpoints that already comply and remediates the ones that do not. Provision Manager keeps manufacturer-approved driver versions current after deployment. For application vulnerabilities, teams trigger updates directly from a Security Monitor finding, so remediation runs through the same platform that found the exposure, which is the approach behind finding every exposure and fixing what matters first.
CapaOne addresses the visibility and third-party patching part of SAMSIK’s client advice. The rest of the list, from multifactor authentication and segmentation to backup and incident response, calls for other controls, and a credible response plan names them separately.
A Higher Threat Level Is a Test of Visibility
The change on September 24 did not change what good endpoint patching looks like. It raised the cost of any patching that has fallen behind. An organization that can answer the five questions quickly and from current data has operational visibility. One that has to assemble the answers by hand across several systems has a visibility problem, and the higher threat level makes that the more urgent gap to close. To see what that view looks like across your own fleet, book a demo of CapaOne Endpoint Management Platform.
