

July 2026 recorded 799 confirmed ransomware attacks, a 19% month-on-month increase, with financial services absorbing a 71% spike in that single month alone [1]. The NAIC's PeopleSoft systems were breached as part of what appears to be a broader campaign targeting that platform [2]. Nissan disclosed employee data was compromised through an Oracle zero-day [3]. A supply chain worm propagated across 444 npm packages, reaching a combined 2 billion monthly installs before defenders caught it [4]. These are not isolated failures. They share the same three gaps: unpatched internet-facing infrastructure, no supply chain integrity controls, and identity abuse going undetected.
The speed problem compounds all of it. A 2026 adversary tracking report puts average eCrime breakout time at 29 minutes, with the fastest recorded case at 27 seconds [5]. Global median dwell time, meanwhile, rose to 14 days in 2025, driven by actors operating from unmonitored edge devices [6]. Defenders have 14 days on average to find an intruder who can move laterally in under 30 minutes from first access. That asymmetry is the operating environment for Q3.
Here are the seven controls the evidence says would have changed the outcome.
Credential theft remains the preferred entry point. Voice phishing surged to the second most common initial access vector in 2025 at 11% of investigated incidents, behind only exploits at 32% [6]. The migration away from email phishing (down from 14% to 6% year-over-year) reflects attacker adaptation, not reduced volume [6]. SMS and time-based one-time password (TOTP) MFA fail against device code phishing and real-time proxy attacks. In 2025, 67% of organizations experienced at least one successful account takeover, and 59% of those compromised accounts had MFA enabled [7]. The MFA was present; it was the wrong kind. The New York State Department of Financial Services (NYDFS) made the same diagnosis in May 2026, recommending "phishing-resistant MFA methods such as authenticator applications with number matching or hardware tokens" [8]. FIDO2 hardware tokens and passkeys are operationally deployable now. The question is priority, not feasibility.
82% of detections in 2025 were malware-free, up from 51% in 2020 [5]. Endpoint antivirus is therefore blind to most intrusions. Attackers are using valid credentials, remote monitoring and management (RMM) tools, and built-in system utilities, none of which generate traditional malware signatures. Huntress documented a campaign that used a fake Bank of America email to install an RMM tool and operate undetected through legitimate remote access channels [9]. Identity threat detection and response (ITDR) closes this gap by monitoring authentication infrastructure, detecting impossible travel, token abuse, and privilege escalation that endpoint controls never see. Valid account abuse accounted for 35% of cloud incidents in 2025 [5]. No endpoint agent catches a stolen token used from a known cloud provider IP.
Ransomware operators have explicitly retargeted recovery. A 2026 incident response report stated directly: "Ransomware operators have shifted their primary objective from data theft to deliberate recovery denial, systematically targeting backup infrastructure, identity services, and virtualization management planes." [6] INC Ransom, tracked this quarter, uses Veeam credential dumping for backup destruction prior to encryption [1]. Flat backup environments connected to the production domain are co-encrypted. The operative control is immutable off-network backups with tested restore procedures. NYDFS made this concrete in May 2026: entities "should test the integrity, immutability, and restorability of backups, including validation of recovery time objectives." [8] Tested means the restore was executed, not scheduled. Most organizations conflate backup existence with recovery capability.
The average organization runs 10 AI applications per month, many outside formal approval processes [10]. High-risk generative AI prompts doubled over the past year within enterprise environments [10]. This is an uncontrolled data exfiltration surface. The "Bissa Scanner" campaign stole AI credentials from more than 30,000 exposed .env files, with AI accounts representing the most stolen credential type in that operation [10]. Shadow AI creates two compounding risks: sensitive data entered into unapproved external models, and AI credentials becoming high-value theft targets. The control is a formal AI application inventory, data loss prevention (DLP) policies applied to AI traffic, and prompt governance that classifies what data can enter which tools. This is not speculative future-state work. It is a current gap with current exploitation.
The NAIC breach was described as part of a broader campaign targeting PeopleSoft users [2]. Third-party access and shared platforms create correlated exposure. NYDFS issued prescriptive third-party service provider (TPSP) guidance in October 2025, stating explicitly that "covered entities may not delegate responsibility for compliance with the Cybersecurity Regulation to an affiliate or a TPSP" [11]. The same regulator fined PayPal $2 million in January 2025, the first enforcement action under the revised Part 500, after a misclassified system change bypassed mandatory security reviews and enabled credential stuffing to expose Social Security Numbers [12]. The pattern is consistent: vendor access reviewed at onboarding but not continuously monitored, contracts lacking breach notification requirements, and offboarding that leaves access tokens active. NYDFS signaled in both October 2025 and May 2026 guidance that TPSP deficiencies will be examined and enforced [8], [11]. For regulated entities, this is no longer discretionary.
Cyber espionage actors operated with a 122-day median dwell time in 2025, exploiting unmonitored edge devices as persistent footholds [6]. Zero-day exploitation prior to public disclosure increased 42% year-over-year [5]. The Nissan breach exploited an Oracle zero-day [3]; the NAIC incident compromised PeopleSoft in what appears to be a coordinated campaign against that platform [2]. CVE-2025-31324 in SAP NetWeaver and CVE-2025-61882 in Oracle EBS were among the top exploited vulnerabilities in 2025 incident response investigations [6]. The math is simple: a 122-day espionage dwell time against an adversary who can establish a foothold in 27 seconds [5] means that periodic patch cycles are structurally incompatible with current threat tempo. Continuous vulnerability scanning on internet-facing assets, with defined SLAs tied to CISA's Known Exploited Vulnerabilities (KEV) catalog, is the minimum viable response [13].
74% of cybersecurity teams report AI is already changing team size and role structures [14]. The skills gap now dominates workforce concerns at 60%, a 20-percentage-point differential over headcount shortages [14]. Expert and senior roles represent 72% of reported recruitment difficulties, and 55% of senior hires take 6 months or longer to fill [14]. Detection coverage cannot scale through headcount alone under those conditions. AI-assisted rule generation, triage automation, and detection tuning are compensating controls for the skills gap, not future options. The same threat research that documents 89% year-over-year increases in AI-enabled attacks [5] also shows attackers using AI to iterate tools faster than human developers can respond [15]. Detection engineering that relies entirely on manual analyst output is already outpaced.
The structural explanation has three components. First, the skills gap is real and documented: only 38% of organizations provide comprehensive AI security training despite 54% reporting governance policies exist [14]. The policies exist on paper; the capability to implement them does not. Second, AI-enabled attack volume increased 89% year-over-year [5], compressing the window between vulnerability disclosure and active exploitation. Third, internet crime losses exceeded $16 billion in 2024, a 33% year-over-year increase, with phishing, extortion, and personal data breaches as the top complaint categories [16]. The losses are accumulating faster than control implementation.
Tool sprawl adds operational drag. Organizations with 50-plus security tools often have coverage gaps precisely because integration and tuning require the senior analysts they cannot hire. The result is controls that exist in procurement records but not in active detection coverage.
Sequence matters. Phishing-resistant MFA and backup immutability are the highest-leverage starting points because credential theft and recovery denial appear in the majority of ransomware chains tracked this quarter [1], [6]. Both are implementable without multi-year programs. ITDR and continuous edge device scanning address the 82% malware-free detection problem and the 122-day espionage dwell time, respectively [5], [6]. They require tooling investment but no new architecture.
AI application inventory and third-party access governance are urgent specifically for financial services. NYDFS's May 2026 guidance explicitly cites geopolitical events and frontier AI model releases as triggers for heightened threat environments requiring stronger defensive measures [8]. That language functions as an enforcement signal. Regulated entities should treat the NYDFS guidance as the forcing function it is designed to be, not as advisory reading.
AI-augmented detection engineering is the longest-lead item but cannot be deferred indefinitely. A 2026 workforce survey found only 17% of organizations have a comprehensive AI security and governance framework [14]. Building detection capability on a foundation of manual analyst output, against adversaries iterating with AI tools, is not a stable equilibrium. The quarter's breach record makes that plain.
The seven controls highlighted in these breaches map directly to unified telemetry, pre-built detections, and vulnerability prioritization through curated threat feeds.
Does your current stack provide the seven breach-stopping controls described above?
FEATURED RESOURCES


