The Most Dangerous Cybersecurity Threats Facing Businesses Right Now

By Joseph HarissonPublished August 14, 2023Updated October 1, 202612789 views

Every year we ask IT and cybersecurity practitioners what's actually keeping them up at night, and every year the honest answer is some mix of the same old problems getting worse plus one or two new wrinkles nobody saw coming. 2026 is no exception. What's changed is the balance of power between attack types, and the speed at which AI is letting criminals scale up tactics that used to require real skill.

The 2026 Verizon Data Breach Investigations Report, which analyzed more than 22,000 confirmed breaches across 145 countries, the largest dataset in the report's 19-year history, put a number on something practitioners have felt coming for a while: for the first time ever, exploiting unpatched vulnerabilities has overtaken stolen credentials as the number one way attackers get into a network. Vulnerability exploitation accounted for 31% of breaches, compared to 13% for credential abuse. Meanwhile the human element, phishing, pretexting, and plain old mistakes, still showed up in 62% of breaches. Both things are true at once, and that's exactly why this is hard to defend against with a single tool.

"While the velocity of cyber threats, driven by AI and faster vulnerability exploitation, is increasing, the foundational principles of security and strong risk management remain the most effective defense," said Daniel Lawson, SVP Global Solutions at Verizon Business, in the report's release. That's not a throwaway line. It's the same message practitioners have been repeating for years: basics first, shiny tools second.

Ransomware: fewer victims pay, but the ones who do pay a lot more

Ransomware remains the threat clients ask about most, and the economics of it have shifted in a way that's worth explaining properly because the headline numbers are genuinely confusing if you only read one source.

Chainalysis, which traces actual cryptocurrency flows to ransomware wallets, found the median ransomware payment jumped 368% in a single year, from $12,738 in 2024 to roughly $59,556 in 2025. At the same time, total on-chain ransomware revenue kept falling, down to about $820 million in 2025, the third consecutive annual decline. Put those two numbers side by side and the picture is: fewer organizations are paying, but the ones who still cave are being squeezed for far more than they would have been three years ago. Check Point Research's Q2 2026 data put the payment rate at a multi-year low near 23%, continuing a six year slide from 85% back in 2019.

Sophos's 2026 State of Ransomware survey tells a related but different story because it only surveys organizations that were actually hit and had data encrypted, a narrower and more severely affected group. It found a median ransom payment of $769,000, with 48% of encrypted victims choosing to pay. Both numbers can be correct simultaneously; they're measuring different slices of the same problem, and that's a useful lesson in itself. Whenever a client cites a ransomware statistic, ask what population it's drawn from before treating it as gospel.

In practice this looks like a bifurcated market. Large, well-resourced attackers are going after the targets least able to say no, hospitals facing life-safety risk, manufacturers with idled production lines, municipalities with no real backup strategy, and demanding sums that would have been unthinkable in 2021. Everyone else is getting hit by higher-volume, lower-stakes campaigns where a solid backup and recovery plan means the ransom note becomes background noise rather than an existential decision.

AI has not invented new attacks, it's scaling the old ones

This is the point that gets lost in a lot of AI security coverage: attackers are mostly not doing anything conceptually new. They're doing the same phishing, the same pretexting, the same credential stuffing, just faster and more convincingly. The 2026 DBIR found the median threat actor used AI across 15 documented techniques during an attack, not to invent a novel method but to scale targeting, content generation, and reconnaissance. In some breaches, researchers counted AI use up to 50 times across a single incident.

This tracks with what practitioners on the ground were already flagging before the AI wave fully hit. "AI-enhanced software platforms have led to the weaponization of deepfake audio and video content in social engineering campaigns," said Mike Pedrick of Nuspire, a managed security provider, describing a trend he was watching even as it was just emerging. "Even seasoned professionals and borderline-paranoid experts have fallen victim to such convincing content." That prediction has aged well, unfortunately.

Voice and video deepfakes of executives have gone from novelty to routine enough that CEO-fraud phone calls and even live video calls are genuinely hard to distinguish from the real thing. One documented case this year involved a subsidiary of Capillary Technologies losing roughly 3 million euros to attackers using cloned voices and forged signatures over a single weekend. The FBI has also issued public warnings that AI-generated voice messages are being used to impersonate senior US government officials. This is no longer a "someday" risk; it's something an accounts payable team needs a verification process for today, not a policy to write next quarter.

Shadow AI is a quieter but real problem too. The 2026 DBIR flagged it as the third most common non-malicious insider action detected, a fourfold increase, with 67% of people using non-corporate AI credentials on company devices. Nobody thinks they're doing anything wrong when they paste a client contract into a free chatbot to summarize it. That's exactly the problem.

Third-party and supply chain compromise, the risk you don't control

If there's one number from this year's data that should change how security budgets get allocated, it's this one: breaches involving third parties, vendors, SaaS platforms, OAuth integrations, jumped 60% year over year to account for 48% of all breaches in the 2026 DBIR. Your own patching discipline and security awareness training don't help much if the compromise happens through a vendor you gave API access to eighteen months ago and forgot about.

The DBIR authors point to a specific, fixable pattern behind most of these: lack of multi-factor authentication, improper credential rotation, and absent least-privilege enforcement in the relationships between an organization and its vendors. This is where teams usually trip up, not because the concept is hard to understand but because vendor access reviews are tedious and rarely get prioritized until something goes wrong. If you haven't audited what third parties can touch in your environment in the last twelve months, that's a genuinely useful place to start, more useful in most cases than buying another detection tool.

Only 26% of known exploited vulnerabilities got patched last year

Given that vulnerability exploitation is now the top initial access vector, the patching numbers behind it are sobering. According to the 2026 DBIR, only 26% of known exploited vulnerabilities were remediated in 2025, down from 38% the year before. That gap is widening, not closing, even as the industry talks more than ever about patch management maturity.

Part of the reason is volume. AI-assisted vulnerability discovery is finding flaws faster than security teams can triage and patch them, which creates what the DBIR calls a capacity crisis. The honest takeaway here isn't "patch everything instantly," because that's not realistic for most IT teams juggling production stability against security urgency. It's: prioritize ruthlessly based on what's actually being exploited in the wild rather than what scored highest on a CVSS chart, and accept that perfect patch coverage isn't the goal. Reducing your exposure window on the vulnerabilities attackers are actually using is.

DDoS: shorter attacks, bigger spikes, and a wildly asymmetric cost

DDoS doesn't get the headlines ransomware does, but the numbers are startling. Cloudflare blocked 20.5 million DDoS attacks in the first quarter of 2025 alone, 96% of its entire 2024 total. Network-layer attacks surged 509% year over year in that same period. The largest single attack ever recorded hit 31.4 Tbps, set by the Aisuru botnet in December 2025, and it lasted just 35 seconds. In fact, 89% of DDoS attacks now last under 10 minutes, hit-and-run has become the default pattern rather than the exception.

The cost asymmetry is what makes this particularly frustrating to explain to clients who think of DDoS as a minor nuisance. A DDoS-for-hire service costs as little as $38 an hour. Every minute of resulting downtime costs an average of $22,000, or about $1.32 million an hour, according to MazeBolt's tracking. The average SMB recovery cost from a DDoS incident runs around $120,000. That's an attacker-to-defender cost ratio north of 3,000 to 1. It's a genuinely lopsided economic setup, and it's a good argument for why DDoS mitigation belongs in a basic security stack even for organizations that feel too small to be a target.

What this actually means day to day

None of this is meant to be doom and gloom for its own sake. A few non-obvious things worth taking away:

  • Vendor risk management is now arguably as important as endpoint security, given that nearly half of breaches route through a third party. Most SMBs still treat this as a checkbox exercise rather than an ongoing process.
  • Backup and recovery maturity has become the single biggest lever an organization has over ransomware economics. It's not exciting to talk about and it doesn't sell well as a service, but the data is unambiguous: the organizations driving down the payment rate are the ones who can restore without negotiating.

The uncomfortable truth is that none of this is solvable with a single product purchase. A next-gen firewall helps. Multi-factor authentication helps a lot more than most people give it credit for. But the fundamentals Daniel Lawson referenced, patching what actually matters, knowing what your vendors can touch, training people to recognize a convincing fake, and having a recovery plan that doesn't depend on paying a criminal, are still doing more work than any individual security product. That's not a satisfying answer if you're looking for a silver bullet. It's also the accurate one.

If you're evaluating providers to help close these gaps, our cybersecurity services directory is a reasonable place to start comparing vendors who specialize in the areas above.

Joseph Harisson

Joseph Harisson

Founder of IT Companies Network

Joseph Harisson is the founder of IT Companies Network, a web-based platform that connects IT companies with each other, potential clients, and indust...

277 articles by this author