Europe's attack surface: 2.85M exposed services
Point a scanner at the EU's public internet and you don't see companies — you see reachable services. A March 2026 study across the EU-27 and 14 protocols counted 2.85 million publicly reachable services, including 47,945 MongoDB and 41,258 Redis instances, many with no authentication. Attackers scan the whole internet in hours and let exposed services raise their hand. The durable move is to stop appearing in the scan at all: cloak your services so they answer only a verified identity — EU-resident and audited.
Frequently asked questions
How big is Europe's internet attack surface?
A March 2026 exposure study across the 27 EU member states and 14 protocols found roughly 2.85 million publicly reachable services — including tens of thousands of unauthenticated databases. Every reachable service is a door an attacker can knock on from anywhere.
How does cloaking help with NIS2?
NIS2 pushes toward measurable access control and attack-surface reduction. 'That service is not reachable from the internet — access requires a verified identity, and every session is logged' is a control you can evidence. Veil supports those obligations; it is not a certification.
Is Veil EU-sovereign?
Yes. Processing and storage stay on EU-based infrastructure with no US CLOUD Act exposure. Cloaking your services keeps their access path EU-resident and audited.
Sources: CyberLeveling — EU internet exposure research (14 protocols) · Censys — Databases Exposed (Redis)