Report · Research Center

Cybersecurity Readiness Report 2026: The Entry Point Changed and Most Programmes Have Not

For the first time, exploiting a software flaw overtook stolen credentials as the way breaches start, third-party involvement rose 60%, and a quarter of malicious breaches now use AI. What that means for a control set built for the last pattern.

Cybersecurity Readiness Updated 2026-08-10 1353 words · about 6 min read
Cybersecurity Readiness Report, 2026 edition

Readiness is usually reported as framework coverage, which measures how much has been written down rather than what would happen. This report tracks where breaches actually begin each year and asks whether the control set still points at it.

Annual, following the Verizon and IBM releases. Next edition August 2027. Written for CISOs and heads of infrastructure defending a budget.

Two things happened in the 2026 data that should change where security budget goes, and neither is the thing most readiness programmes are being measured on.

Exploiting a software vulnerability (31%) overtook stolen credentials as the top way a breach begins, for the first time since the measurement has been taken. And breaches involving a third party rose 60% year on year, to 48% of all breaches. Nearly half of what happens to you now arrives through somebody else's estate.

Meanwhile the average breach cost reached USD 4.99 million, up 12% and a record, and one in four malicious breaches was AI-enabled, a 56% increase in a single year, costing about USD 6 million each.

The uncomfortable reading: most readiness programmes are still organised around phishing awareness and credential hygiene, which addressed the pattern that was true until this year.

What the 2026 data shows#

Measure2026Direction
Top initial access vectorVulnerability exploitation, 31%Overtook credentials, first time
Breaches involving a third party48%Up 60% year on year
Ransomware share of all breaches48%Up from 44%
Ransomware victims who did not pay69%Refusal is now the norm
Median ransom paid$139,875Down from $150,000
Average breach cost$4.99mUp 12%, a record
Malicious breaches that were AI-enabled1 in 4Up 56%
Average cost of an AI-enabled breach$6.0m~$1m above the overall average
Saving where AI and automation used in security operations~$2mPer breach
Where breaches actually start, 2026 Vulnerability exploitation: 31%. Third-party involvement (any vector): 48%. Ransomware present: 48% Vulnerability exploitation31%Third-party involvement (any vector)48%Ransomware present48%
Show the figures as a table
Initial access vectorShare of breaches
Vulnerability exploitation31%
Third-party involvement (any vector)48%
Ransomware present48%
Where breaches actually start, 2026 Vulnerability exploitation overtook stolen credentials for the first time. Most awareness-led programmes are built for the second bar. Source: Verizon 2026 Data Breach Investigations Report. Chart: BvLogic. Reuse with attribution to bvlogic.com.

The finding that should move budget#

Vulnerability exploitation winning is not a story about attackers getting cleverer. It is a story about speed. The DBIR authors are explicit that generative AI is compressing the work of finding and weaponising a flaw from months into hours.

That breaks an assumption underneath almost every patching policy we see. A 30-day remediation SLA for high-severity findings was defensible when weaponisation took longer than 30 days. It is now a policy that guarantees a window rather than closes one.

The practical question for a readiness assessment is no longer "do you patch?" It is: for your internet-facing estate, what is the measured time from a CVE being published to it being remediated in your environment, and can you evidence that number for last quarter? Most organisations cannot produce it, which is itself the finding.

The third-party number is the one nobody owns#

Forty-eight per cent of breaches involved a third party, up 60% in a year. Every organisation we have assessed has a vendor risk process. Almost none of them has a control that would have caught this, because the process is procurement-shaped: a questionnaire at onboarding, a certificate on file, a renewal date.

What the data argues for instead is unglamorous and specific:

  • An inventory of which third parties hold credentials, tokens or network access into your estate, as opposed to which ones you have contracts with. These are different lists and the second one is longer.
  • Time-bound, scoped credentials for integrations, so a supplier breach has an expiry date.
  • A named owner per integration who would notice if it started behaving differently.

Ransomware: the economics turned#

The most encouraging number in the dataset is that 69% of ransomware victims did not pay, and the median payment fell to $139,875. Collective refusal is working, slowly.

Read it carefully though. Ransomware still rose to 48% of breaches. Attackers are being paid less per success and are compensating with volume, which is what you would expect and which does not help you if you are the volume.

Where AI sits, on both sides#

The 2026 data is the first that lets you put a number on AI's effect in either direction.

Against you: a quarter of malicious breaches were AI-enabled, up 56%, and they cost about a million dollars more than average, driven mostly by deepfake impersonation and AI-assisted malware.

For you: organisations using AI and automation in security operations saw breach costs about $2 million lower. That is the single largest cost differential in the IBM dataset.

Both of those are averages across very different organisations, and neither is a promise. But the direction is consistent enough to act on: the return is in detection and response speed, which is also where 63% of breach cost accumulates.

Breach cost, USD millions Average breach: 4.99m. AI-enabled breach: 6m. With AI in security operations: 3m Average breach4.99mAI-enabled breach6mWith AI in security operations3m
Show the figures as a table
CategoryAverage cost
Average breach4.99m
AI-enabled breach6m
With AI in security operations3m
Breach cost, USD millions AI-enabled breaches cost about a million more. Using AI in security operations saves about two. Source: IBM Cost of a Data Breach Report 2026. Chart: BvLogic. Reuse with attribution to bvlogic.com.

What readiness actually means now#

If we were assessing an estate against this data rather than against a framework checklist, these are the five questions we would ask first. None of them is answerable with a policy document.

  1. What is your measured time from CVE publication to remediation on internet-facing systems, for last quarter? Not the SLA. The measurement.
  2. Which third parties hold live credentials or network access into your estate right now, and who owns each one by name?
  3. When did your detection last catch something real, and how do you know it would have? A rule that has never fired is an assumption about a log format.
  4. Can you evidence that a given control operated on a given day against a given asset? The gap between a control existing and a control demonstrably running is where incidents live.
  5. What is your organisation's answer to a deepfake voice authorising a payment? A quarter of malicious breaches now involve AI, and this is the specific one that bypasses every technical control you own.

Our read#

The control set most organisations built between 2020 and 2024 was correct for that period. MFA everywhere, phishing training, credential hygiene: all of it still matters and none of it is where the marginal attack now arrives.

The 2026 shift is toward exploitation speed and inherited exposure, and both are measured in days rather than in policy maturity. A readiness programme that cannot state its remediation time and cannot list its third-party access paths is not ready, whatever its framework coverage says.

Method and limitations#

This report synthesises published 2026 industry datasets. It is not primary research: we did not run a survey, and we say so because a report that overstates its method is not worth citing.

The two anchor sources are the Verizon Data Breach Investigations Report 2026 and the IBM Cost of a Data Breach Report 2026. They study different populations with different methods. Verizon analyses confirmed breaches reported by contributing organisations, which skews toward incidents severe enough to be reported and investigated. IBM's cost figures come from interviews with breached organisations and are averages across wildly different breach sizes, so the mean is pulled by large outliers and should never be read as a typical case.

"AI-enabled" is IBM's classification, not ours, and the boundary is genuinely fuzzy: a phishing email drafted with a language model and a fully autonomous intrusion both land in the same bucket.

Published 2026-08-10. Figures current to that date.

Sources#

Download the data (CSV) Every figure charted above, machine-readable, with its source on each row.

The findings, in one place

Quote these directly. They are the sentences we stand behind, which is not always true of a sentence assembled out of a paragraph.

  • Exploiting a software vulnerability (31%) overtook stolen credentials as the top way a breach begins, for the first time on record.
  • Breaches involving a third party rose 60% in a year, to 48% of all breaches. Nearly half of what happens to you arrives through somebody else's estate.
  • One in four malicious breaches was AI-enabled, up 56%, costing about $6m against a $4.99m average. Organisations using AI in security operations saw costs about $2m lower.
  • 69% of ransomware victims did not pay, and the median payment fell to $139,875. Collective refusal is working, and ransomware still rose to 48% of breaches.

How to cite this

Every report here may be quoted, charted and reproduced, including commercially, with attribution to BvLogic and a link to the report page.

Cybersecurity Readiness Report, 2026 edition. BvLogic Research, 2026-08-10. https://bvlogic.com/research/cybersecurity-readiness/

Every report here may be quoted, charted and reproduced, including commercially, with attribution to BvLogic and a link to the report page. No permission needed and no form to fill in. We would rather be cited widely than control the copy, and a citation policy that requires an email is a citation policy designed to fail.

Use this

Everything below is generated from this report, so no figure appears in them that is not published above. Free, no form, no attribution required beyond a link.

Press and analyst enquiries

Figures, the underlying data, or a named comment for a piece you are writing: hello@bvlogic.com. We answer these properly and we will tell you when a number is weaker than it looks.

What else is coming for Cybersecurity Readiness

Report Ready

The findings, with sources.

Data Not yet

The underlying figures.

Method Not yet

Where each number came from.

Updates Not yet

What changed since publication.