Skip to content
The Cyber Security Place

Orientation

Cyber security in 2026: where the risk actually sits

The most quoted ranking of how attackers get in changes its answer depending on how the categories were drawn — and almost nobody quoting it says so.

Last reviewed August 29, 2026

Exploiting a flaw is now the largest single way in, near 31% of initial access and up from about 20%. Regroup the same figures by what is attacked and identity leads: phishing around 16%, stolen credentials 13% and pretexting 6% total some 35%. The human element appears in about 62% of breaches, marginally up. Breaches run roughly 183 days before anyone notices and 64 more to contain, a lifecycle near 247 days; crossing 200 days costs about $5.65m against $4.32m. The global average landed near $4.99m, up 12%, and the United States average sits far above it. Ransomware reached 39% of breached organisations, from 24% in 2023, while the share of victims paying fell to a record low near 28–31% from 49% two years earlier.
  • The leading vector depends on the categories. By technique, software flaws win; by target, identity does. The incidents are the same.
  • Noticing is the slow half. Detection runs near three times containment, and it usually gets the smaller budget.
  • 200 days is worth about $1.33m. One of the few security figures that converts directly into a spending case.
  • Refusal became the majority. Roughly two thirds now decline to pay, and extortion moved toward publishing data rather than encrypting it.
  • Training has not moved the human share down in twenty years, which is a finding about system design rather than about people.

The leading way in depends on where you draw the lines

Both bars below describe the same breaches. The first groups them the way the reports do, by technique. The second groups them by what the attacker was actually going after. Only the boundaries move.

Grouped by technique — software flaws lead31%16%13%6%34%Grouped by what is attacked — identity leadsIdentity 35%Software flaws 31%Everything else 34%

A four-point lead is not a rout, and that is the useful part. Anyone telling you that patching has decisively overtaken identity, or the reverse, has chosen a cut and left the choice out of the sentence. The honest version is that two families of weakness are running close to level, and which one matters more in a given organisation is a question about that organisation rather than about the industry.

How well calibrated are you?

6 questions, two answers each. Most of them run against the intuition, which is the reason they are here: the figures that surprise you are the ones worth remembering.

Six questions. The answers are shown below each one.

Which single route into an organisation is now the most common?

Exploitation accounts for roughly 31% of initial access, up from about 20% a year earlier. Stolen credentials sit near 13%.

The headline is true and the conclusion drawn from it usually is not. Group the routes by what they attack rather than by technique and identity — phishing at about 16%, credential abuse at 13%, pretexting at 6% — comes to some 35%, ahead of exploitation. Whether patching or identity is the bigger problem depends on how the categories were drawn, not on what attackers did.

Which takes longer: noticing a breach, or shutting it down once noticed?

Around 183 days to identify against 64 days to contain, for a mean lifecycle near 247 days.

Detection is close to three times containment, and it is the half that receives the smaller share of most budgets. Money spent on shortening the response matters, but it is compressing the shorter of the two intervals.

How much does crossing 200 days of breach lifecycle cost?

Lifecycles beyond 200 days average about $5.65m against $4.32m for shorter ones — a gap near $1.33m.

That difference is larger than most detection programmes cost to run, which makes the 200-day line one of the few security numbers that translates directly into a budget argument.

Since 2024, has the share of ransomware victims paying gone up or down?

Payment rates fell to a record low near 28–31%, from about 49% in 2024, with some 64% of organisations now refusing outright.

Refusal became the majority position in roughly two years. Attacks did not stop, which is the point: the pressure moved from encryption toward publishing stolen data, because that is the leverage that survives a good backup.

Is the human element in breaches growing or shrinking?

Present in about 62% of breaches, up from 60% the year before. Identity weaknesses appear in close to 90% of investigations.

Two decades of awareness training have not moved this line down. That is evidence about the design of the systems people are asked to operate, rather than evidence about people.

Among organisations that suffered a breach, how common is ransomware now?

Some 39% of breached organisations reported at least one ransomware incident, against 24% in 2023.

The share rose while payments fell. Extortion is being attempted far more often and succeeding financially far less often, which is a change in the economics rather than in the volume of attacks.

Why does noticing take three times longer than stopping?

The mean breach now runs around 183 days before anyone identifies it and a further 64 before it is contained. Those two numbers describe very different problems. Containment is a project with an owner, a runbook and a visible end. Detection is the absence of an event — nothing happens, repeatedly, until one day something does, and the interval in between is invisible while it is happening.

Spending follows visibility. Response capability can be demonstrated in an exercise and shown to a board; the ability to notice can only be demonstrated by the thing you failed to notice, which arrives as bad news rather than as a result. So the shorter of the two intervals attracts the larger share of the investment, and the longer one is left to whatever logging happened to be switched on.

Detection also degrades quietly. A rule that stops firing looks identical to a rule with nothing to fire about, a log source that silently stops shipping looks like a quiet system, and neither produces an alert about its own absence. The most valuable cheap control here is not another sensor: it is a check that the sensors you already have are still speaking, and a habit of deliberately triggering one to see whether anybody notices.

The 200-day line is a budget argument

Breaches whose lifecycle passed 200 days averaged around $5.65m; those resolved inside it averaged about $4.32m. Roughly $1.33m separates the two, against a global average near $4.99m that rose some 12% year on year, and a United States figure closer to $11.5m.

Most security numbers resist being turned into a case for spending. This one does not, because it names a threshold, attaches a cost to crossing it, and the actions that keep you on the right side of it are the unglamorous ones — log retention long enough to reconstruct what happened, an inventory accurate enough to know what to look at, and someone whose job includes looking. A programme that shortens the median lifecycle from beyond the line to inside it is defensible in a language finance departments already speak.

Averages carry the usual warning. They mix industries, jurisdictions and organisations of wildly different size, and no single company will experience the average. Their use is as a scale check: if an internal estimate of breach cost is an order of magnitude away from these, the estimate is probably the thing that needs revisiting.

What changed when victims stopped paying?

In 2024 something close to half of ransomware victims paid. The figure has since fallen to a record low near 28–31%, with around 64% of organisations now refusing outright. Over the same stretch the share of breached organisations reporting at least one ransomware incident rose from 24% to some 39%. Attempts up, payments down.

Refusal works because backups work. An organisation that can restore does not need a decryption key, and once that became common the encryption half of the business lost most of its leverage. What kept its leverage was the copy of the data. Publishing stolen files, or threatening to, is unaffected by how good the backups are, and it reaches regulators, customers and journalists without the attacker doing anything technically difficult.

The practical consequence is that recovery planning and breach planning have come apart. Being able to restore quickly answers the operational question and leaves the disclosure question entirely open. A tested restore is necessary and no longer sufficient, and the second half — who decides what to say, to whom, within what deadline — is the part most plans still leave to the moment.

There is a second-order effect worth watching. As payment rates fall, the value of any individual victim drops, and the response to a thinner margin is usually more volume rather than less. That is consistent with attempts rising while receipts fall, and it suggests the population being targeted is broadening downward toward organisations that were previously too small to be worth the effort. Anyone assuming obscurity as a control is relying on an economic assumption that has already moved.

Two decades of training, and the human share went up

People feature in about 62% of breaches, a shade above the previous year, and identity weaknesses turn up in close to 90% of investigations. Both figures have been broadly stable through twenty years of mandatory training, simulated phishing and posters by the lifts.

Read as a finding about people, this is bleak and useless. Read as a finding about design, it is neither. It says that systems asking a distracted person to distinguish a genuine message from a good forgery, several times a day, at speed, will produce a predictable rate of error — and that the rate is a property of the arrangement rather than of the individuals in it. The engineering response is to remove the decision where possible: authentication that cannot be handed to a stranger, approvals that cannot be granted by a convincing message alone, defaults that fail closed.

Training keeps a role in this account, and it is a narrower one than it is usually sold with. It is good at teaching people how to report, and what happens when they do, which shortens the interval between the first person suspecting something and the first person qualified to check. Given that detection is the slow half, that is a substantial contribution. It is a different claim from expecting training to stop the click.

Where should a small team start?

Two things address most of what is above, and neither requires a platform purchase. The first is phishing-resistant authentication on everything reachable from the internet, which cuts across the whole identity family rather than one technique within it. The second is a known, tested route to notice that something is wrong: a short list of sources that must keep reporting, a check that they still do, and a named person who looks.

After those, an accurate inventory earns its keep more than any additional detection product, because every subsequent decision — what to patch first, what to isolate, what the blast radius of a compromised credential actually is — depends on knowing what exists. Teams that skip this step end up buying tools to answer questions an up-to-date list would have answered for nothing.

What can wait is most of what gets advertised. The gap between an organisation with those three foundations and one without them is far larger than the gap between two organisations with them running different products on top.

Inheriting an environment where none of this exists calls for a different opening move: find out what is reachable from the internet before deciding anything else. External exposure is the one thing an attacker can enumerate without any access at all, which makes it the only part of the estate where your view and theirs can be compared directly. Teams that start there routinely find a forgotten administrative interface, a service standing up long after the project that needed it ended, or a certificate quietly expired. Closing those buys more risk reduction per week of effort than any purchase available, and it produces the beginnings of the inventory as a side effect.

How do notification deadlines survive a 183-day detection gap?

Disclosure regimes are written in hours and days. Data protection law across much of Europe expects notification to a regulator within 72 hours; listed companies in the United States work to a window of four business days once an incident is judged material; sector rules for finance, health and critical infrastructure add their own clocks, most of them shorter than a week. Set those against a mean of roughly 183 days to identification and the arithmetic looks impossible.

It is not, because nearly all of these clocks start at awareness rather than at occurrence. The six months an intruder spent undetected does not consume the deadline. That resolves the arithmetic and creates a stranger incentive: the moment of discovery is the moment a legal timer begins, and everything before it is untimed. An organisation that improves its detection is, in the narrowest sense, volunteering to start clocks earlier and more often.

Nobody sensible argues against noticing sooner on those grounds, but the incentive shapes behaviour in quieter ways. It rewards ambiguity about when awareness began, which is why the record of who knew what and when matters more than most teams expect, and why that record is usually assembled retrospectively from chat logs and ticket timestamps under conditions of considerable stress. Deciding in advance what constitutes awareness — which alert, reviewed by whom, at what confidence — is cheap, dull, and the single preparation most often skipped.

The related trap is materiality. A deadline that begins when an incident is judged material invites the judgement to be deferred, and a deferral that looks prudent internally reads very differently in an enforcement action reconstructing the timeline afterwards. The workable posture is to fix the criteria while nothing is happening, write down who applies them, and accept that some disclosures will look premature in hindsight. That is a far cheaper error than the alternative.

The three questions a board asks

Boards do not ask about vectors. They ask whether the organisation would survive the thing that happened to somebody else in the news, how much of the budget is buying that survival, and whether anyone would tell them early. Each of those maps onto the figures above, and each has an answer that can be prepared in advance rather than improvised in a meeting.

Would we survive it? The honest answer is a restore time and a scope, both measured rather than estimated. When did we last restore a production system from backup, how long did it take, and what was still missing afterwards. An organisation with recent numbers for that has answered the question; one that describes its backup policy has changed the subject.

Is the money well spent? The comparison worth making is not between products but between the two halves of the lifecycle. If detection is roughly three times the length of containment and receives a fraction of the attention, that imbalance is the finding, and shifting it has a price tag against the $1.33m that crossing 200 days appears to cost.

Would we know early? This is the one most often answered with a tool name. A better answer is the date of the last deliberate test — someone triggering an alert on purpose to see whether it arrived, at whose desk, and how long it sat there. Without that date the detection capability is a purchase rather than a measurement.

Reading the numbers you will be shown this year

Every figure on this page came from an annual study with a method, and the methods differ. Sources put exploitation between 31% and 33%, and stolen credentials between 13% and 16%, depending on what counts as which. Those gaps are not errors; they are the visible edge of a taxonomy decision.

Three questions get most of the way to reading any such report. What population did the sample come from — a supplier's telemetry describes the organisations that bought that supplier's product. Over what window, and is it the same window as last year's edition. And what is the denominator behind the percentage, because a share without one is doing rhetorical work rather than empirical work.

Where credible sources disagree, the disagreement is worth keeping rather than averaging away. Two studies differing by two points on the same question usually means the question was cut differently, and knowing which cut you are looking at is more useful than a tidier number would have been.

One last habit saves more embarrassment than any of the above: never perform arithmetic across two reports. Subtracting one study's quarter from another's year, or expressing one house's figure as a percentage of another's, produces a number that describes nothing at all, and it happens constantly in slide decks because the result looks like analysis. If two figures are to be compared, they need to have come from the same method, and if they did not, the comparison is the finding.

What do these numbers leave out?

Everything above is built on incidents that became known, were investigated, and were counted. Each of those three steps filters, and the filtering runs in a consistent direction.

Incidents that nobody noticed are, by construction, absent. Given a mean of some 183 days to identification, the population of compromises currently underway and not yet discovered is not a hypothetical — it is a certainty of unknown size, and today's figures describe the subset that surfaced. Small organisations are thin on the ground for a different reason: below the thresholds that trigger regulatory notification, and below the size that justifies engaging an incident response firm, an event can be absorbed and never reported. The datasets are consequently weighted toward organisations large enough to have someone to call.

The near-miss is missing too, and it is the category with the most to teach. A credential that was phished but never used, an exposed service found by the owner an hour before anyone else, a restore that worked — none of these become an incident, so none appear in any annual study, though they are the evidence that a control did its job. Organisations that track their own near-misses end up with a picture of their exposure that no published report can supply, because the published reports are made of the cases where something failed.

None of this makes the figures unusable. It means they describe discovered breaches at organisations with the means to investigate them, which is a real and narrower thing than breaches in general. Reading them with that sentence attached costs nothing and prevents the most common error made with them: treating an industry average as a forecast for a particular company.

Common questions

What is the most common way attackers get in?

Exploiting a vulnerability is the largest single route, at roughly 31% of initial access and up from about 20% the year before. Grouped differently the answer changes: phishing, stolen credentials and pretexting together come to some 35%, all of them attacks on identity rather than on code.

Should we prioritise patching or identity?

Both, and the published rankings will not settle the argument for you because they answer a question about technique rather than about target. A more useful test is which of the two your own last five incidents involved, and which of the two you could measurably improve within a quarter.

How long do breaches go unnoticed?

Around 183 days to identify on average, with a further 64 to contain, for a mean lifecycle near 247 days. Detection is close to three times containment, which is worth holding in mind when spending is weighted toward response.

Does faster containment actually save money?

Materially. Breaches with lifecycles beyond 200 days average about $5.65m against $4.32m for shorter ones. The roughly $1.33m difference is larger than many detection programmes cost to operate for a year.

What does a data breach cost on average?

The 2026 global average landed near $4.99m, about 12% higher than the previous year, with the United States average considerably above that at around $11.5m. Averages across industries and jurisdictions are blunt instruments, and they are most useful as a scale check rather than as a forecast.

Are companies still paying ransoms?

Fewer of them. Payment rates fell to a record low around 28–31%, down from roughly 49% in 2024, and about 64% of organisations now refuse. Extortion attempts did not fall with them, which is why leaked-data pressure has grown relative to encryption.

Is ransomware getting more or less common?

More common as an event and less profitable as a business. Some 39% of breached organisations reported at least one ransomware incident, against 24% in 2023, over a period in which the share of victims paying dropped by roughly a third.

Why has security awareness training not reduced human-caused breaches?

The human element appears in about 62% of breaches, slightly up on the previous year, after two decades of training programmes. The reasonable reading is that the failure is in the design of systems that require people to make security decisions under time pressure, not in the people making them.

Where should a small team start?

With the two controls that touch the largest share of the data above: phishing-resistant authentication on everything reachable from the internet, and a known, tested path to notice that something is wrong. Those address the identity family and the 183-day detection gap respectively, and neither depends on buying a platform.

How should I read the statistics vendors publish?

Ask what population the sample came from before reading the percentage. A supplier's telemetry reflects the organisations that bought that supplier's product, which is a real population and a narrow one. Reports that state their sample size, window and population can be reasoned about; reports that give percentages with no denominator cannot.

Do the numbers on this page come from one source?

No, and where credible sources disagree the disagreement is stated rather than averaged away. Initial access shares, breach costs, lifecycle lengths and ransom payment rates come from different annual studies with different methods, and small differences between them are usually methodological rather than substantive.

What is the fastest way to find something specific here?

The search page covers every entry by title and source, section pages group them by subject, and the glossary defines the terms that get used inconsistently across the industry.

Latest from the archive

Also