Trust and Cybersecurity:
The Threat Landscape Today 

The trends, tactics, and frameworks shaping enterprise cybersecurity in 2026. Drawn from the industry’s most cited annual research. 

Updated quarterly

Last review: June 2026

Curated sources

IBM, Crowdstrike, Verizon, ENISA

Reading time

12 minutes

KEY NUMBERS THAT ARE SHAPING STRATEGY NOW

4.44M

global average cost of a data breach in 2025; down 9% YoY, the first decline in five years. Driven by faster AI-assisted detection.

IBM, Cost of a Data Breach 2025

82%

of detections in 2024 were malware-free. Adversaries are logging in, not breaking in. Using stolen credentials and legitimate tools. 

CrowdStrike, 2026 Global Threat Report

30% 

of breaches now involve a third party; double the prior year. Supply chain risk has moved from peripheral to central.

Verizon, 2025 DBIR

80%

of observed phishing campaigns by early 2025 used AI generated or AI enhanced content. Social engineering has scaled with generative models.

ENISA, Threat Landscape 2025

What’s Driving Enterprise Risk in 2026? 

Credentials Are the New Perimeter 

For the third year running, stolen credentials top the initial-access charts. The Verizon DBIR found credential abuse responsible for 22% of breaches; CrowdStrike’s 2026 report observed that 82% of detections in 2025 were malware-free, with adversaries using valid accounts to log in rather than malware to break in. The shift puts privileged access (how it’s granted, monitored, and revoked) at the center of every enterprise security conversation.

29 mins

The average breakout time between initial access and lateral movement in 2025, down 65% from the prior year. The fastest observed was 27 seconds.

Learn More About Identity and Access

Blog | The Cyber Guild | Gartner Research

» admin by request
Person wearing a hoodie sits at a desk in a dark room, surrounded by glowing holographic screens with charts and diagrams (cyber/control room scene). » admin by request

AI is Reshaping Both Sides of the Line

IBM’s 2025 report described it as an arms race: organisations using AI extensively in security saved an average of $1.9M per breach, while attackers in turn used AI in roughly one in six breaches; most commonly for phishing (37%) and deepfake impersonation (35%). CrowdStrike’s 2026 report observed an 89% year-on-year increase in attacks by AI-enabled adversaries; ENISA went further, estimating that more than 80% of phishing campaigns observed in early 2025 already used AI-generated or AI-enhanced content.

But the more interesting story is shadow AI: unsanctioned generative tools in use across the business without security oversight.

97 %

of organizations that suffered AI related breaches lacked proper AI access controls, costing an additional average of $670,000USD.

Learn More About AI as an Attack Surface 

Blog | Blog | Gartner On-Demand Webinar

Breaches Don’t Always Start in Your Network

Third-party involvement in breaches doubled in a single year, from approximately 15% to 30%, according to the 2025 DBIR. ENISA’s data corroborates the trend, with supply chain compromise emerging as a dominant vector for state-aligned operations against EU infrastructure. The exploitation of edge devices (VPNs, firewalls, management interfaces) tells the same story from a different angle

ZERO

For new critical vulnerabilities affecting edge devices in 2024, the median time between public disclosure and mass exploitation was zero days.

Learn More About AI as an Attack Surface 

Blog | Gartner Guide | Verizon Report

Futuristic data center: a glowing mesh humanoid at a workstation connected by neon lines to cloud icons and server racks in the background. » admin by request

Frameworks Worth Knowing

EU.DIRECTIVE

NIS2

Expanded EU directive covering essential and important entities. Mandates risk management, incident reporting, and supply chain controls. 

US.DIRECTIVE

NIST CSF 2.0 

The 2024 update added Govern as a core function. Widely adopted as a structuring framework even outside US-regulated industries.

International.standard

ISO 27001 

The international standard for information security management systems. Often the baseline expected in enterprise procurement.

EU.Regulation

DORA

Digital Operational Resilience Act. Mandatory for EU financial entities since January 2025, with significant ICT and third-party risk requirements. 

US.Audit Standard

SOC 2

AICPA-defined criteria for service organizations. Frequently demanded by US enterprise buyers as part of vendor due diligence. 

Sector.Healthcare

HIPAA

US healthcare privacy and security rule. Critical for any vendor handling protected health information (PHI), directly or via a business associate agreement. 

Trusted Industry Sources

NIS2

Global threat Report. An annual review of adversary tradecraft, breakout times, and the shifting balance between malware and identity-based attacks.

Annual . Threat Intelligence

IBM

Cost of a Data Breach Report. 20-year Ponemon Institute analysis series quantifying breach economics, including financial impact, root causes, and security failures.

Annual . Breach Economics

Verizon 

Data Breach Investigations Report. 18+ years of incident pattern analysis, drawn from a global contributor network.

Annual . Incident Patterns

ENISA 

Threat Landscape Report. The European Union Agency for Cybersecurity’s annual EU-focused threat assessment.

Annual . EU regulatory context

Microsoft 

Digital Defense Report. Annual summary across Microsoft’s threat intelligence, including nation-state activity and identity attacks.

Annual . Platform Intelligence

CISA

Cybersecurity Advisories. Ongoing US-government advisories on active threats, vulnerabilities, and recommended defensive actions.

Continuous . US guidelines

What’s Next?

We have a range of resources available for enterprise security teams. Continue exploring at your own pace, or speak to one of our experts if you’d prefer a conversation.