Trust and Cybersecurity:
The Threat Landscape Today
The trends, tactics, and frameworks shaping enterprise cybersecurity in 2026. Drawn from the industry’s most cited annual research.
Updated quarterly
Last review: June 2026
Curated sources
IBM, Crowdstrike, Verizon, ENISA
Reading time
12 minutes
4.44M
global average cost of a data breach in 2025; down 9% YoY, the first decline in five years. Driven by faster AI-assisted detection.
82%
of detections in 2024 were malware-free. Adversaries are logging in, not breaking in. Using stolen credentials and legitimate tools.
30%
of breaches now involve a third party; double the prior year. Supply chain risk has moved from peripheral to central.
80%
of observed phishing campaigns by early 2025 used AI generated or AI enhanced content. Social engineering has scaled with generative models.
What’s Driving Enterprise Risk in 2026?
Credentials Are the New Perimeter
For the third year running, stolen credentials top the initial-access charts. The Verizon DBIR found credential abuse responsible for 22% of breaches; CrowdStrike’s 2026 report observed that 82% of detections in 2025 were malware-free, with adversaries using valid accounts to log in rather than malware to break in. The shift puts privileged access (how it’s granted, monitored, and revoked) at the center of every enterprise security conversation.
29 mins
The average breakout time between initial access and lateral movement in 2025, down 65% from the prior year. The fastest observed was 27 seconds.
Learn More About Identity and Access


AI is Reshaping Both Sides of the Line
IBM’s 2025 report described it as an arms race: organisations using AI extensively in security saved an average of $1.9M per breach, while attackers in turn used AI in roughly one in six breaches; most commonly for phishing (37%) and deepfake impersonation (35%). CrowdStrike’s 2026 report observed an 89% year-on-year increase in attacks by AI-enabled adversaries; ENISA went further, estimating that more than 80% of phishing campaigns observed in early 2025 already used AI-generated or AI-enhanced content.
But the more interesting story is shadow AI: unsanctioned generative tools in use across the business without security oversight.
97 %
of organizations that suffered AI related breaches lacked proper AI access controls, costing an additional average of $670,000USD.
Learn More About AI as an Attack Surface
Breaches Don’t Always Start in Your Network
Third-party involvement in breaches doubled in a single year, from approximately 15% to 30%, according to the 2025 DBIR. ENISA’s data corroborates the trend, with supply chain compromise emerging as a dominant vector for state-aligned operations against EU infrastructure. The exploitation of edge devices (VPNs, firewalls, management interfaces) tells the same story from a different angle
ZERO
For new critical vulnerabilities affecting edge devices in 2024, the median time between public disclosure and mass exploitation was zero days.
Learn More About AI as an Attack Surface

Frameworks Worth Knowing
NIS2
Expanded EU directive covering essential and important entities. Mandates risk management, incident reporting, and supply chain controls.
NIST CSF 2.0
The 2024 update added Govern as a core function. Widely adopted as a structuring framework even outside US-regulated industries.
ISO 27001
The international standard for information security management systems. Often the baseline expected in enterprise procurement.
DORA
Digital Operational Resilience Act. Mandatory for EU financial entities since January 2025, with significant ICT and third-party risk requirements.
SOC 2
AICPA-defined criteria for service organizations. Frequently demanded by US enterprise buyers as part of vendor due diligence.
HIPAA
US healthcare privacy and security rule. Critical for any vendor handling protected health information (PHI), directly or via a business associate agreement.
Trusted Industry Sources
NIS2
Global threat Report. An annual review of adversary tradecraft, breakout times, and the shifting balance between malware and identity-based attacks.
IBM
Cost of a Data Breach Report. 20-year Ponemon Institute analysis series quantifying breach economics, including financial impact, root causes, and security failures.
Verizon
Data Breach Investigations Report. 18+ years of incident pattern analysis, drawn from a global contributor network.
ENISA
Threat Landscape Report. The European Union Agency for Cybersecurity’s annual EU-focused threat assessment.
Microsoft
Digital Defense Report. Annual summary across Microsoft’s threat intelligence, including nation-state activity and identity attacks.
CISA
Cybersecurity Advisories. Ongoing US-government advisories on active threats, vulnerabilities, and recommended defensive actions.
What’s Next?
We have a range of resources available for enterprise security teams. Continue exploring at your own pace, or speak to one of our experts if you’d prefer a conversation.

