Panop Research’s State of Security 2026 (July edition, compiled August 2026) pulls together the public datasets that actually moved this year: IBM / Ponemon, Verizon’s DBIR, ENISA, the World Economic Forum, Swiss NCSC reporting, and the first documented AI-orchestrated espionage campaign.
The full PDF is available via Download PDF above. What follows is the argument, not a reprint of the charts.
The year in numbers
- $4.99M — global average cost of a data breach, a record, up 12% (IBM / Ponemon, 2026)
- 1 in 4 malicious breaches were AI-enabled, up 56% (IBM / Ponemon, 2026)
- 48% of confirmed breaches involved a third party, up 60% (Verizon DBIR, 2026)
- 31% of initial access came from vulnerability exploitation (Verizon DBIR, 2026)
- 94% of leaders named AI the top driver of change (WEF, 2026)
- 69% of ransomware victims did not pay (Verizon DBIR, 2026)
Three shifts sit behind those numbers. The entry point moved from stolen credentials to unpatched exposure. The perimeter moved outward into the supply chain, now in nearly half of confirmed breaches. And AI risk acquired a measurable price: AI-enabled breaches cost roughly a million dollars more than the average, while defenders who have deployed AI save close to two million.
How attacks begin
Verizon’s 2026 DBIR is the first edition in which exploitation of vulnerabilities overtook credential abuse as the leading initial access vector. Exploitation rose 55% year on year, to 31%. Credential abuse fell to 13%.
Ransomware is more frequent and less profitable. 69% of victims did not pay; the median payment fell to $139,875 from $150,000. Better backups and rehearsed recovery are working, so operators have shifted to volume. ENISA counted 82 distinct ransomware variants against EU organisations in a single reporting year.
The practical reading: vulnerability management is now a capacity problem, not a diligence problem. Exposure reduction and segmentation matter more than faster patching alone. A tested restore is now a quantified control: two thirds of victims used one instead of paying.
AI has a price tag
Until 2026 the AI threat conversation ran on anecdote. This year it is in the breach datasets.
- 1 in 4 malicious breaches were AI-enabled (up 56% year on year)
- AI-enabled malicious breaches cost about $6.00M versus a $4.99M global average
- Organisations that used AI in defence saved about $1.90M
- 1 in 4 organisations still use no AI or automation in security operations
- Shadow AI accounts for 43% of AI-related incidents
- ENISA assessed that by early 2025, AI-supported phishing was more than 80% of observed social engineering worldwide
In November 2025 Anthropic reported disrupting the first documented AI-orchestrated cyber espionage campaign (GTG-1002). Around 30 organisations were targeted; Anthropic assessed that the model executed 80% to 90% of the tactical work.
What changed is tempo, not technique. Reconnaissance, exploitation and lateral movement now run at machine speed, in parallel, across many targets. The window between exposure and impact is shorter.
Half of breaches arrive through somebody else
Third-party involvement in confirmed breaches went from 15% (2024 edition) to 30% (2025) to 48% (2026). Only 23% of third-party organisations fully remediated missing or improperly secured MFA on cloud accounts. Median time for third parties to resolve half of weak-password and permission findings is eight months.
That is why DORA put a critical third-party provider regime in place, and why NIS2 Article 21 talks about supply-chain risk. For most programmes the gap is not policy but evidence: which vendors hold which access, when it was last reviewed, and what still functions if a supplier stops answering.
Volume is not impact
ENISA curated 4,875 EU incidents from July 2024 to June 2025. 77% were DDoS; only 2% caused any service disruption. Hacktivism drove 79% of the volume. Ransomware remains the most impactful threat.
Switzerland’s NCSC picture is similar in kind: 64,733 voluntary reports in 2025, 222 mandatory reports from critical infrastructure, ransomware reports up to 104. The cases that breach data and halt services are a small share of the total. They still arrive through phishing, exposed vulnerabilities and stolen credentials.
2026 is the year the rules start collecting
Four European instruments and one Swiss obligation move from transposition to enforcement inside eighteen months. The overlap is the difficulty: the same incident can trigger separate notifications to separate authorities on separate clocks.
- DORA — applicable since 17 January 2025
- Swiss ISA duty — in force 1 April 2025 (24-hour initial report, 14-day follow-up)
- NIS2 — transposition continuing through 2026
- Cyber Resilience Act — reporting from 11 September 2026; main obligations 11 December 2027
- EU AI Act — further obligations from August 2026
A supervised Swiss financial institution that is also critical infrastructure can owe notices to the NCSC, FINMA and the FDPIC for one event. Satisfying one clock does not satisfy the others.
Supervisors keep asking for the same four artefacts: a current register of ICT dependencies, a tested exit path for critical suppliers, incident classification agreed before an incident, and evidence that the management body has actually reviewed the risk position.
Five priorities for the next twelve months
- Exposure management — rank by reachability and business criticality; fix those first.
- Vendor access, on evidence — prove MFA and last review, rather than accepting an attestation.
- Govern the AI you run — inventory agents and tool permissions; classify prompts and retrieval context.
- Verify identity out of band — payment and access changes on a channel the caller cannot choose.
- Rehearse recovery — a tested restore is the single best measured return in this year’s data.
The organisations that absorbed 2025 well were not the ones that avoided being hit. They were the ones that could see what was reachable, who held access, what their models were sending outward, and whether recovery had been tested rather than merely documented.
That is the work Panop is built for. See risk prioritisation, third-party risk and AI-SPM, or book a demo.