Skip to content
SECURITYSQUAD
Back to the blog

Cyber threats 2026: what companies should prepare for now

2026-08-07 · by SECURITYSQUAD

Cyber threats 2026: what companies should prepare for now

Threats are easy to speculate about. More useful is a look at what incident investigations actually count. The figures below come from the BSI's 2025 situation report and from Mandiant's M-Trends 2026, which evaluates over 500,000 hours of incident response from 2025. Some of it contradicts the received wisdom – including what we ourselves would have written two years ago.

1 · The way in is the vulnerability, not the email

The most common initial infection vector is, for the sixth consecutive year, exploitation of a vulnerability: 32 per cent of investigated incidents. Email phishing sits at 6 per cent – down markedly, because automated controls have improved.

That is notable, because security budgets are often allocated the other way round: much attention on awareness, little on promptly patching what is reachable from the internet. The figures suggest the opposite order.

What helps: know what is externally reachable – and patch that first. Vulnerability management that continuously checks the outside view addresses by far the largest single vector.

2 · Calls instead of emails

The second most common way in is now voice phishing at 11 per cent – a marked rise. The target is typically the help desk: somebody poses as an employee and asks for a password reset or for registration of a new second factor. With synthetic voices this is now convincing enough.

What helps: a defined identity check at the help desk that does not rely on recognising a voice – call back on the number on file, confirmation by the line manager, verification on video with ID. Plus a clear message to the help desk team that refusing is never a mistake.

3 · Hand-off takes 22 seconds

Perhaps the most uncomfortable figure: between initial access and hand-off to a second threat group, the 2025 median was 22 seconds. In 2022 it was over eight hours.

Behind this is division of labour. Specialised groups obtain access and pass it on; the follow-on group's tooling is staged during the initial break-in. The idea that you have hours to respond after an intrusion no longer holds.

What helps: automated response rather than manual. Disable compromised accounts, terminate sessions, isolate devices – if that only happens after an email to an on-call rota, it is too late.

4 · Ransomware arrives on purchased access

The most common entry route specifically for ransomware is prior compromise: 30 per cent, up from 15 per cent the year before. Translated: the extortionists do not break in themselves. They buy access from somebody already inside – sometimes for months.

What helps: finding old, unnoticed compromises rather than only repelling new ones. That is the purpose of attack detection and of reviewing what accounts and access actually exist.

5 · Extortion runs on data, not encryption

For its reporting period the BSI describes falling willingness to pay for encryption alone – and at the same time the highest average payments ever recorded in connection with data leaks. For exfiltrated data, on average almost three times as much was paid as for encrypted data. Around 80 per cent of reported attacks hit small and mid-sized companies.

What helps: backups remain mandatory but are no longer sufficient – they restore systems but do not undo a publication. Against exfiltration, access restriction, segmentation and the ability to notice the outflow are what count. More in our ransomware guide.

6 · Some sit inside for a very long time

Median dwell time across all incidents is 14 days, up from 11. The median hides the spread, though: for espionage cases it is 122 days, and for one particularly persistent backdoor nearly 400 days were measured.

Anyone looking only at loud incidents misses this category entirely. It does not stand out, because nothing breaks.

What this means for your priorities

None of these developments calls for exotic technology. They call for a different order than the one usually chosen:

  1. Know and patch the external surface – the largest single vector at 32 per cent.
  2. Secure identity processes, especially at the help desk – the second largest vector.
  3. Detect and respond automatically – because 22 seconds leaves no room for manual work.
  4. Address data exfiltration, not just encryption.
  5. Awareness – important, but demonstrably no substitute for the four points above. Why, in our phishing guide.

If you do not know where you stand, an honest overview is the cheapest place to begin.

As at August 2026. Figures from Mandiant M-Trends 2026 (published March 2026, based on 2025 data) and the BSI report "Die Lage der IT-Sicherheit in Deutschland 2025" (reporting period 1 July 2024 to 30 June 2025).

Read more: Vulnerability Management · Ransomware protection · GUARDIANVIEW – Managed SIEM · Cyber Risk Check