Privileged Access & Microsegmentation · 5 min read

Attackers favour stolen identities and lateral movement over zero-days

2026 incident-response reporting shows intrusions increasingly start with valid credentials, not exotic exploits — then spread through over-permissioned environments. Identity and segmentation, not just the perimeter, decide the outcome.

Digital padlock representing identity and access security

Published 20 May 2026

The headline-grabbing zero-day is not how most organisations are actually breached. 2026 incident-response data shows attackers overwhelmingly prefer the quiet path: logging in with valid credentials and then moving laterally through environments that grant far more access than anyone needs.

What the data shows

  • Credential misuse and brute force account for roughly a fifth of intrusions, with attackers logging directly into VPNs, remote-access gateways and cloud portals.
  • Analysis of more than 680,000 identities found 99% of cloud users, roles and services carried excessive permissions.
  • Over 90% of breaches were enabled by misconfigurations or gaps in coverage rather than novel exploits.
  • Modern ransomware follows a predictable chain: initial access, privilege escalation, lateral movement, then selective encryption of critical systems.

Why it matters

If a stolen password is enough to log in, and every account can reach every system, then one compromised user becomes a path to the entire estate. The two factors that decide how far an intruder gets are how privileged access is controlled and how freely traffic can move east-west between workloads — neither of which the perimeter firewall addresses on its own.

Containing this requires removing standing privilege and shrinking the blast radius, so that even a successful login leads nowhere useful.

How iconnet helps

Contain identity-driven attacks on two fronts. Privileged Access Management (Krontech, JumpServer) vaults credentials, brokers every privileged session through a bastion and records it for audit — removing the standing credentials attackers reuse. Microsegmentation (Illumio) then stops lateral movement by allowing only explicitly permitted east-west traffic, and SecHard hardens posture and enforces least-privilege so misconfigurations don't become open doors.

Talk to a security specialist

Tell us about your environment and goals. Our engineers will help you scope the right solution — no obligation.