1 EP
Tech

DBIR 2026: Patch, Privilege, and AI

A 2-minute evidence-led briefing on what to fix first from Verizon's 2026 DBIR

Episodes

Episode 1
Two minutes: what to do first
Clear, evidence-led priorities from the 2026 DBIR: patching, third parties, and realistic AI risks.
2:22

Transcript

Episode 1 · Two minutes: what to do first

The 2026 DBIR does not call for reinventing security. It calls for fixing the basics faster, and fixing them where attackers are already succeeding. I’m Rhea, and in the next two minutes, here’s where I’d start. First, treat exploited vulnerabilities as an operational priority, not a backlog category. In non-Error, non-Misuse breaches, vulnerability exploitation is now the leading initial-access vector, at 31%. Credential abuse is at 13%. At the same time, only 26% of critical vulnerabilities in CISA’s Known Exploited Vulnerabilities catalog were fully remediated in 2025. That is down from 38%. Median time to full resolution rose from 32 days to 43 days, while the median organization had about 50% more KEV fixes to do. This does not mean every vulnerability deserves the same response. It does mean that known-exploited, exposed systems need a faster path from detection to owner to verified fix. Make that path boring, measured, and hard to defer. Second, extend that same discipline to third parties and cloud identity. Third-party involvement reached 48% of breaches, up from 30% the year before. That does not prove a third party caused every one of those breaches. But it does tell us the boundary around your environment is wider than your own network. And the remediation data is uncomfortable. Only 23% of missing or improperly secured MFA issues in third-party cloud accounts were fully remediated. Weak passwords and permission misconfigurations took nearly eight months for half of findings to be resolved. So, start with the controls closest to access: MFA, privileged permissions, and service accounts. Know which third parties can authenticate into your environment, and which identities can do damage if compromised. One final point: don’t let AI panic distract you. Generative AI is helping attackers scale familiar techniques. The median AI-assisted technique had about 55 known malware examples, and fewer than 2.5% were truly rare. The playbook is still recognizable. Patch faster. Protect identity. Reduce unnecessary privilege. That’s refinement, not reinvention. And it’s where I’d begin. Thanks for listening.