Skip to main content
BilgeQor

Verified cyberincident context · Jordan / National Cyber Security Center Q1 2026

Jordan NCSC Q1 2026 cyberincident trend, attack categories and severity

Market context — not industry-specific evidence

Jordan National Cyber Security Center Q1 2026 report context, as announced by Petra / Jordan News Agency, states that locally recorded cyber incidents fell 16% during Q1 2026 compared with the same period the previous year. Within the total attacks during Q1 2026, disruption and sabotage operations accounted for 70.7%, cyber intrusions for 18.7%, cyber espionage for 10.4%, and financially motivated attacks for 0.2%. By severity, 89.2% of incidents were medium-risk, 10.3% low-risk, and 0.5% critical. Among handled sectors, industrial and commercial accounted for 27.91%, government institutions for 20.93%, education for 13.95%, telecommunications and IT for 12.79%, and energy for 11.63%. Security flaws accounted for 76% of detected weaknesses within some national institutions in the report context. These figures are Jordan NCSC Q1 2026 report-defined context; they are not total Jordan business incident prevalence, not a national incident census, and not industry-specific evidence.

Jordan · NCSC Q1 2026 cyberincident trend, attack-category, severity, handled-sector and detected-weakness contextQ1 2026 · Announced 19 May 2026

Locally recorded cyber incidents — Q1 2026 versus Q1 2025

Year-on-year decline in locally recorded cyber incidents (Q1 2026 vs Q1 2025)
16%
Unit
percent decline in locally recorded cyber incidents during Q1 2026 compared with the same period the previous year
Period
Jordan NCSC Q1 2026 cyberincident trend, attack-category, severity, handled-sector and detected-weakness context.
Scope
Jordan NCSC Q1 2026 cyberincident trend and context

Jordan NCSC Q1 2026 report context states that locally recorded cyber incidents fell 16% during Q1 2026 compared with the same period the previous year.

Q1 2026 context only. This decline compares Q1 2026 with the same period the previous year in the Jordan NCSC report context and must not be presented as proof that Jordan-wide cyber risk decreased overall, as a full-year conclusion, or as a long-term trend. Not total Jordan business incident prevalence and not industry-specific evidence.

Attack categories — Q1 2026 Jordan NCSC report context

Disruption and sabotage operations — 70.7%
70.7%
Unit
percent of total attacks during Q1 2026 categorised as disruption and sabotage operations
Period
Jordan NCSC Q1 2026 cyberincident trend, attack-category, severity, handled-sector and detected-weakness context.
Scope
Jordan NCSC Q1 2026 cyberincident trend and context
Cyber intrusions — 18.7%
18.7%
Unit
percent of total attacks during Q1 2026 categorised as cyber intrusions
Period
Jordan NCSC Q1 2026 cyberincident trend, attack-category, severity, handled-sector and detected-weakness context.
Scope
Jordan NCSC Q1 2026 cyberincident trend and context
Cyber espionage — 10.4%
10.4%
Unit
percent of total attacks during Q1 2026 categorised as cyber espionage
Period
Jordan NCSC Q1 2026 cyberincident trend, attack-category, severity, handled-sector and detected-weakness context.
Scope
Jordan NCSC Q1 2026 cyberincident trend and context
Financially motivated attacks — 0.2%
0.2%
Unit
percent of total attacks during Q1 2026 categorised as financially motivated attacks
Period
Jordan NCSC Q1 2026 cyberincident trend, attack-category, severity, handled-sector and detected-weakness context.
Scope
Jordan NCSC Q1 2026 cyberincident trend and context

Report-defined shares of total attacks during Q1 2026 in the Jordan NCSC report context. Not all-Jordan attack prevalence or all-business attack prevalence. Not industry-specific evidence for the sector shown on this page.

Incident severity distribution — Q1 2026 Jordan NCSC report context

Medium-risk incidents — 89.2%
89.2%
Unit
percent of incidents during Q1 2026 classified as medium-risk
Period
Jordan NCSC Q1 2026 cyberincident trend, attack-category, severity, handled-sector and detected-weakness context.
Scope
Jordan NCSC Q1 2026 cyberincident trend and context
Low-risk incidents — 10.3%
10.3%
Unit
percent of incidents during Q1 2026 classified as low-risk
Period
Jordan NCSC Q1 2026 cyberincident trend, attack-category, severity, handled-sector and detected-weakness context.
Scope
Jordan NCSC Q1 2026 cyberincident trend and context
Critical incidents — 0.5%
0.5%
Unit
percent of incidents during Q1 2026 classified as critical
Period
Jordan NCSC Q1 2026 cyberincident trend, attack-category, severity, handled-sector and detected-weakness context.
Scope
Jordan NCSC Q1 2026 cyberincident trend and context

Report-defined severity shares during Q1 2026 in the Jordan NCSC report context. Not a full-year severity distribution and not total Jordan business incident prevalence. Not industry-specific evidence.

Selected sectors — share of handled incidents Q1 2026 Jordan NCSC report context

Industrial and commercial — 27.91%
27.91%
Unit
percent of cyber incidents handled during Q1 2026 attributed to the industrial and commercial sector
Period
Jordan NCSC Q1 2026 cyberincident trend, attack-category, severity, handled-sector and detected-weakness context.
Scope
Jordan NCSC Q1 2026 cyberincident trend and context
Government institutions — 20.93%
20.93%
Unit
percent of cyber incidents handled during Q1 2026 attributed to government institutions
Period
Jordan NCSC Q1 2026 cyberincident trend, attack-category, severity, handled-sector and detected-weakness context.
Scope
Jordan NCSC Q1 2026 cyberincident trend and context
Education — 13.95%
13.95%
Unit
percent of cyber incidents handled during Q1 2026 attributed to the education sector
Period
Jordan NCSC Q1 2026 cyberincident trend, attack-category, severity, handled-sector and detected-weakness context.
Scope
Jordan NCSC Q1 2026 cyberincident trend and context
Telecommunications and IT — 12.79%
12.79%
Unit
percent of cyber incidents handled during Q1 2026 attributed to telecommunications and information technology
Period
Jordan NCSC Q1 2026 cyberincident trend, attack-category, severity, handled-sector and detected-weakness context.
Scope
Jordan NCSC Q1 2026 cyberincident trend and context
Energy — 11.63%
11.63%
Unit
percent of cyber incidents handled during Q1 2026 attributed to the energy sector
Period
Jordan NCSC Q1 2026 cyberincident trend, attack-category, severity, handled-sector and detected-weakness context.
Scope
Jordan NCSC Q1 2026 cyberincident trend and context

Selected sectors only. These percentages apply to cyber incidents handled during Q1 2026 in the Jordan NCSC report context. The five sectors shown sum to approximately 87% — additional sectors exist but are not listed in the report context. Not all-Jordan sector incident prevalence, not all-business sector prevalence, and not industry-specific evidence for the sector shown on this page.

Security flaws among detected weaknesses — Jordan NCSC Q1 2026 report context

Share of detected weaknesses within some national institutions categorised as security flaws
76%
Unit
percent of detected weaknesses within some national institutions in the report context categorised as security flaws
Period
Jordan NCSC Q1 2026 cyberincident trend, attack-category, severity, handled-sector and detected-weakness context.
Scope
Jordan NCSC Q1 2026 cyberincident trend and context

Jordan NCSC Q1 2026 report context states that security flaws accounted for 76% of detected weaknesses within some national institutions.

76% applies to detected weaknesses within some national institutions in the Jordan NCSC Q1 2026 report context only. Not all vulnerabilities across all Jordanian systems and not industry-specific evidence.

Source: Jordan NCSC via Petra / Jordan News Agency, Cyber Incidents Fall 16% Despite Escalating AI-Driven Threats, 19 May 2026

Scope: Jordan National Cyber Security Center / NCSC Q1 2026 report context as announced by Petra / Jordan News Agency on 19 May 2026. The 16% decline compares Q1 2026 with the same period the previous year and must not be presented as proof that Jordan-wide cyber risk decreased overall or as a full-year conclusion. All sector percentages (industrial/commercial, government, education, telecommunications/IT, energy) apply only to cyber incidents handled during Q1 2026 in the report context and are not all-Jordan sector incident prevalence, all-business sector prevalence, or industry-specific evidence. Attack-category percentages are report-defined shares of total attacks during Q1 2026 and are not all-Jordan attack prevalence or all-business attack prevalence. Severity percentages describe Q1 2026 severity distribution only and are not full-year severity distribution. The 76% security-flaw figure applies to detected weaknesses within some national institutions in the report context only and is not a measure of all vulnerabilities across all Jordanian systems. Treat as official/authoritative Jordan NCSC report context as announced by Petra; not an independently extracted NCSC PDF, complete national incident registry, or full national incident census. These figures do not measure total Jordan business incident prevalence, hidden incident prevalence, population-wide victimisation rates, annual incident totals, industry-specific evidence, compliance achievement, certification or security outcomes.

Methodology: Official Jordan National Cyber Security Center Q1 2026 report context as announced by Petra / Jordan News Agency on 19 May 2026. The admitted indicators describe Q1 2026 cyberincident trend, attack categories, severity distribution, handled-sector shares, and detected-weakness context only. The 16% decline compares Q1 2026 with the same period the previous year and must not be presented as proof that Jordan-wide cyber risk decreased overall. All sector percentages (industrial/commercial, government, education, telecommunications/IT, energy) apply only to cyber incidents handled during Q1 2026 and must not be presented as all-Jordan sector incident prevalence, all-business sector prevalence, or industry-specific evidence. Attack-category percentages (disruption/sabotage, intrusion, espionage, financially motivated) are report-defined shares of total attacks during Q1 2026 and must not be presented as all-Jordan attack prevalence or all-business prevalence. Severity percentages (medium-risk, low-risk, critical) are report-defined severity shares during Q1 2026 and must not be presented as full-year severity distribution. The 76% security-flaw metric applies to detected weaknesses within some national institutions in the report context only and must not be presented as all vulnerabilities across all Jordanian systems. Treat as official/authoritative Jordan NCSC report context as announced by Petra; do not present as an independently extracted NCSC PDF, complete national incident registry, or full national incident census. The global AI-supported cyberattack figure (89% increase globally) and the advanced espionage automation figure (80-90% automation targeting 30 organisations) are explicitly excluded from this local-market admission.

Accessible data table
Verified Jordan NCSC Q1 2026 cyberincident context data from Jordan NCSC via Petra / Jordan News Agency, Cyber Incidents Fall 16% Despite Escalating AI-Driven Threats, 19 May 2026, reporting period Jordan NCSC Q1 2026 cyberincident trend, attack-category, severity, handled-sector and detected-weakness context..
MetricValueSourceScopeReporting period
Year-on-year decline in locally recorded cyber incidents (Q1 2026 vs Q1 2025)16% percent decline in locally recorded cyber incidents during Q1 2026 compared with the same period the previous yearJordan NCSC via Petra / Jordan News Agency, Cyber Incidents Fall 16% Despite Escalating AI-Driven Threats, 19 May 2026Jordan NCSC Q1 2026 cyberincident trend and contextJordan NCSC Q1 2026 cyberincident trend, attack-category, severity, handled-sector and detected-weakness context.
Disruption and sabotage operations — 70.7%70.7% percent of total attacks during Q1 2026 categorised as disruption and sabotage operationsJordan NCSC via Petra / Jordan News Agency, Cyber Incidents Fall 16% Despite Escalating AI-Driven Threats, 19 May 2026Jordan NCSC Q1 2026 cyberincident trend and contextJordan NCSC Q1 2026 cyberincident trend, attack-category, severity, handled-sector and detected-weakness context.
Cyber intrusions — 18.7%18.7% percent of total attacks during Q1 2026 categorised as cyber intrusionsJordan NCSC via Petra / Jordan News Agency, Cyber Incidents Fall 16% Despite Escalating AI-Driven Threats, 19 May 2026Jordan NCSC Q1 2026 cyberincident trend and contextJordan NCSC Q1 2026 cyberincident trend, attack-category, severity, handled-sector and detected-weakness context.
Cyber espionage — 10.4%10.4% percent of total attacks during Q1 2026 categorised as cyber espionageJordan NCSC via Petra / Jordan News Agency, Cyber Incidents Fall 16% Despite Escalating AI-Driven Threats, 19 May 2026Jordan NCSC Q1 2026 cyberincident trend and contextJordan NCSC Q1 2026 cyberincident trend, attack-category, severity, handled-sector and detected-weakness context.
Financially motivated attacks — 0.2%0.2% percent of total attacks during Q1 2026 categorised as financially motivated attacksJordan NCSC via Petra / Jordan News Agency, Cyber Incidents Fall 16% Despite Escalating AI-Driven Threats, 19 May 2026Jordan NCSC Q1 2026 cyberincident trend and contextJordan NCSC Q1 2026 cyberincident trend, attack-category, severity, handled-sector and detected-weakness context.
Medium-risk incidents — 89.2%89.2% percent of incidents during Q1 2026 classified as medium-riskJordan NCSC via Petra / Jordan News Agency, Cyber Incidents Fall 16% Despite Escalating AI-Driven Threats, 19 May 2026Jordan NCSC Q1 2026 cyberincident trend and contextJordan NCSC Q1 2026 cyberincident trend, attack-category, severity, handled-sector and detected-weakness context.
Low-risk incidents — 10.3%10.3% percent of incidents during Q1 2026 classified as low-riskJordan NCSC via Petra / Jordan News Agency, Cyber Incidents Fall 16% Despite Escalating AI-Driven Threats, 19 May 2026Jordan NCSC Q1 2026 cyberincident trend and contextJordan NCSC Q1 2026 cyberincident trend, attack-category, severity, handled-sector and detected-weakness context.
Critical incidents — 0.5%0.5% percent of incidents during Q1 2026 classified as criticalJordan NCSC via Petra / Jordan News Agency, Cyber Incidents Fall 16% Despite Escalating AI-Driven Threats, 19 May 2026Jordan NCSC Q1 2026 cyberincident trend and contextJordan NCSC Q1 2026 cyberincident trend, attack-category, severity, handled-sector and detected-weakness context.
Industrial and commercial — 27.91%27.91% percent of cyber incidents handled during Q1 2026 attributed to the industrial and commercial sectorJordan NCSC via Petra / Jordan News Agency, Cyber Incidents Fall 16% Despite Escalating AI-Driven Threats, 19 May 2026Jordan NCSC Q1 2026 cyberincident trend and contextJordan NCSC Q1 2026 cyberincident trend, attack-category, severity, handled-sector and detected-weakness context.
Government institutions — 20.93%20.93% percent of cyber incidents handled during Q1 2026 attributed to government institutionsJordan NCSC via Petra / Jordan News Agency, Cyber Incidents Fall 16% Despite Escalating AI-Driven Threats, 19 May 2026Jordan NCSC Q1 2026 cyberincident trend and contextJordan NCSC Q1 2026 cyberincident trend, attack-category, severity, handled-sector and detected-weakness context.
Education — 13.95%13.95% percent of cyber incidents handled during Q1 2026 attributed to the education sectorJordan NCSC via Petra / Jordan News Agency, Cyber Incidents Fall 16% Despite Escalating AI-Driven Threats, 19 May 2026Jordan NCSC Q1 2026 cyberincident trend and contextJordan NCSC Q1 2026 cyberincident trend, attack-category, severity, handled-sector and detected-weakness context.
Telecommunications and IT — 12.79%12.79% percent of cyber incidents handled during Q1 2026 attributed to telecommunications and information technologyJordan NCSC via Petra / Jordan News Agency, Cyber Incidents Fall 16% Despite Escalating AI-Driven Threats, 19 May 2026Jordan NCSC Q1 2026 cyberincident trend and contextJordan NCSC Q1 2026 cyberincident trend, attack-category, severity, handled-sector and detected-weakness context.
Energy — 11.63%11.63% percent of cyber incidents handled during Q1 2026 attributed to the energy sectorJordan NCSC via Petra / Jordan News Agency, Cyber Incidents Fall 16% Despite Escalating AI-Driven Threats, 19 May 2026Jordan NCSC Q1 2026 cyberincident trend and contextJordan NCSC Q1 2026 cyberincident trend, attack-category, severity, handled-sector and detected-weakness context.
Share of detected weaknesses within some national institutions categorised as security flaws76% percent of detected weaknesses within some national institutions in the report context categorised as security flawsJordan NCSC via Petra / Jordan News Agency, Cyber Incidents Fall 16% Despite Escalating AI-Driven Threats, 19 May 2026Jordan NCSC Q1 2026 cyberincident trend and contextJordan NCSC Q1 2026 cyberincident trend, attack-category, severity, handled-sector and detected-weakness context.

Relevant loss and exposure areas

These existing industry scoping prompts help frame a proposal. They do not assert an incident, loss, or market-specific condition.

Industry themes

  • Fraud
  • Data Theft
  • Regulatory Non-Compliance

Digital surfaces in scope

Banking AppsWealth PortalsTrading APIs

What structured security support changes

The Security File turns risk signals into decisions.

Official market data shows where risk exists. The BilgeQor Security File connects that context to your real websites, apps, accounts, payment flows and team responsibilities, so leaders can decide what to fix first.

Why this matters

The file gives your team one place to understand what was reviewed, what matters, what changed, and what still needs a decision.

BilgeQor Method

What the Security File contains

A Security File is not a generic report. It is a structured decision record for the assets, workflows and risks covered by the agreed scope.

01

Market and sector context

We connect official market signals and industry exposure to the business surfaces in scope.

02

Exposure map

We map websites, apps, accounts, payment journeys, admin roles, vendors and customer-facing workflows.

03

Priority register

We separate urgent risks, important improvements and lower-priority findings so the next action is clear.

04

Executive summary

We provide a concise summary that leadership, operations, vendors or insurers can read without needing raw technical detail.

05

Remediation roadmap

We turn findings into a 14 / 30 / 90-day action path with ownership, evidence notes and follow-through guidance.

What it is not

  • Not a guarantee of perfect security.
  • Not a certification or compliance verdict.
  • Not a per-company loss estimate or fear-based claim.