The headline-grabbing zero-day is not how most organisations are actually breached. 2026 incident-response data shows attackers overwhelmingly prefer the quiet path: logging in with valid credentials and then moving laterally through environments that grant far more access than anyone needs.
What the data shows
- Credential misuse and brute force account for roughly a fifth of intrusions, with attackers logging directly into VPNs, remote-access gateways and cloud portals.
- Analysis of more than 680,000 identities found 99% of cloud users, roles and services carried excessive permissions.
- Over 90% of breaches were enabled by misconfigurations or gaps in coverage rather than novel exploits.
- Modern ransomware follows a predictable chain: initial access, privilege escalation, lateral movement, then selective encryption of critical systems.
Why it matters
If a stolen password is enough to log in, and every account can reach every system, then one compromised user becomes a path to the entire estate. The two factors that decide how far an intruder gets are how privileged access is controlled and how freely traffic can move east-west between workloads — neither of which the perimeter firewall addresses on its own.
Containing this requires removing standing privilege and shrinking the blast radius, so that even a successful login leads nowhere useful.
