blogs

The hidden risks that quietly improved in 2025 and the ones to watch in 2026

IT Team in room with many red screens

Cybersecurity in 2025 felt different. Breaches still happened, but the tone shifted. Arrests of ransomware operators made headlines. More companies applied zero trust to their daily operations. AI tools, once a security concern, began assisting defenders. Progress is real. Yet under the surface, new risks are forming.

Understanding both sides, what improved and what now demands attention, helps you decide where to focus next.

What got better in 2025

Several key risk areas moved in the right direction this year. That’s worth noting, but it does not mean you can relax.

1. Fewer credential stuffing break-ins as baseline defences improved
Credential-stuffing attacks, where stolen or reused credentials are tested en masse, remain common, but their effective success rate has dropped. According to the Verizon Business 2025 Data Breach Investigations Report (DBIR), compromised credentials were the initial access vector in 22 % of the breaches studied. Meanwhile, industry sources show success rates in credential stuffing are now often between 0.1–4 %, small in percentage but still large in impact, according to Authsignal. This shows organisations are more frequently enabling multi-factor authentication (MFA), improving password hygiene, and raising endpoint visibility—and that is making a difference.

2. Greater endpoint visibility and improved detection
As endpoint detection and response (EDR) and extended detection and response (XDR) tools mature, more organisations are seeing where attacks first land and respond faster. The IBM 2025 Threat Intelligence Index reports that identity-based attacks are now approximately 30 % of intrusions. That shift suggests better visibility into what is happening post-authentication and a move away from purely perimeter-based thinking.

3. Better zero trust and identity-centric adoption among SMBs
Small and medium businesses (SMBs) historically lagged enterprise peers, but this year, more SMBs embraced zero-trust principles, especially around identity and access. The N-able Threat Report 2025 finds that credential abuse features in nine out of ten confirmed web-application breaches in SMBs, with identity now viewed as the frontline perimeter. This means you are less likely to be surprised by simple login-based breaches, provided you have invested in identity and access management (IAM) properly.

4. Ransomware arrests and takedowns are helping reduce some risk exposures
According to Crowe’s “Good News in Cybersecurity: Big Wins in 2025”, global law-enforcement disruptions of ransomware groups have weakened some of the traditional threat-economy vectors. That doesn’t mean ransomware is gone, but it means your adversary landscape is shifting.

Emerging risks you must focus on in 2026

While some things improved, new risks are already rising. Complacency is a danger. Here are what we at Kinetic TG are tracking, and what you must act on early.

AI-generated phishing and deepfake scams
Threat actors are now using generative AI to craft phishing emails, create synthetic identities, and manipulate voice or video to fool access controls. The IBM Threat Intelligence Index notes that threat actors are applying AI to phishing and malicious code. In a TechRadar report, phishing attacks rose to 77 % of all incidents in 2025, up from around 60 % in 2024. This means older phishing training methods are no longer enough. You must simulate AI-driven phishing, test voice and deepfake channels, and refresh incident-response procedures accordingly.

Shadow AI risk and vendor or third-party AI dependencies
Many organisations adopt AI offerings or vendor-AI modules without fully understanding their governance, versioning, or access controls. That creates new attack surfaces. For example, if a vendor’s AI module has default credentials or backdoors, you, as the relying organization, may inherit that risk. According to BrightDefense data, nearly 20 % of breaches in the first half of 2025 stemmed from supply-chain attacks involving third parties. You must ensure your AI-vendor footprint is mapped, governance for AI usage is defined, and your third-party risk programme identifies AI as a distinct category.

Vendor dependencies and complacency in baseline controls
With better baseline controls, many organisations assume the job is done, but this is risky. For example, if you rely entirely on your vendor for MFA configuration without internal verification, you may be exposed. Or if endpoint visibility improved, but you did not maintain granular access control and segmentation, lateral movement still works. Improved controls are not “set and forget” but require continuous improvement. The human-machine identity blur is increasingly recognised as a key risk: a recent Arxiv study showed that treating identities as a continuum of humans and machines can reduce identity-related incidents by 47 %. You must build governance around all identities (service accounts, bots, human users), enforce continuous verification, and segment access.

Complacency risk: “We fixed that, so we’re safe.”
While you may now have fewer successful credential-stuffing breaches or fewer ransomware hits, that does not mean you are secure. Attackers adapt. The improvements of 2025 raise the bar but also shift adversary tactics. For example, credential stuffing may decline in raw volume but become more targeted, or attackers may move to social engineering that bypasses MFA entirely. Authsignal’s 2025 analysis found that even with a 0.1 % success rate, thousands of accounts remain compromised when millions of attempts are made. Treat “better” as the starting point, not the finish line.

How to stay ahead in 2026

At Kinetic, we advise a mindset shift—from “ready for attack” to “resilient in attack.” Here are five practical actions you can take now to sharpen your readiness.

  1. Map your identity attack surface
    • Catalogue all identity types (users, service accounts, bots, vendor accounts).
    • Measure which of those use MFA, which depend on passwords, and which have elevated privileges.
    • Check how many vendor accounts have shared credentials or broad access.
  2. Run adversary-style exercises with current threats
    • Simulate AI-driven phishing or deepfake voice attacks on your staff and vendors.
    • Include tabletop and technical exercises around supply-chain or vendor-AI incidents.
    • Measure time to detect, time to respond, and readiness of escalation paths.
  3. Strengthen adaptive controls, not just baseline rules
    • Use adaptive MFA that triggers extra verification when login behaviour is unusual (device, location, velocity).
    • Monitor for credential reuse and logins from atypical IPs or accounts.
    • Enforce segmentation and zero-trust access patterns (least privilege, micro-segmentation).
  4. Audit AI and third-party dependencies
    • Inventory all third-party AI modules your organisation uses and classify risk.
    • Verify vendor log files, access controls, update policies, and incident-notification obligations.
    • Ensure that third-party credentials are onboarded into your IAM oversight.
  5. Embed resilience into your culture
    • Move from defence to resilience. Accept that a breach may happen, and prepare accordingly.
    • Ensure your incident-response playbooks are current, tested, and visible to leadership and supply-chain partners.
    • Report constantly on detection-time metrics, scope of identity exposures, and vendor-attack readiness.

Why Kinetic TG is a partner you can trust

At Kinetic, we work alongside organisations globally to build cyber-readiness programmes that go beyond checklists. We focus on identity-first defence, vendor risk management, and resilience planning. Whether you are strengthening your IAM, simulating AI-driven threat scenarios, or aligning governance across your supply chain, we bring tested frameworks and hands-on experience. Let us help you ensure you are ready not only for the risks you know but for those quietly emerging.

If you are building your cyber-readiness plan for 2026, schedule a 2026 cyber-readiness consultation with Kinetic TG. The earlier you act, the further ahead you will be.

RELATED BLOGS

Ready to Build Your Technology Plan? 

Contact us at: (214) 269-1200

Jim Harryman

Jim is the fearless leader of the Kinetic team. He founded Kinetic more than two decades ago with one simple purpose – make technology do what it promises to do. He has spent the last 25 years doing just that. Every IT system Jim mans is fully subservient to its owner. When he isn’t reveling in new technology, he spends time with his wife Julia and their two sons who are grown, married, and both expecting babies.

CJ Jackson

Meet CJ Jackson, a technical expert with 12 years in customer service and a tech journey sparked by the Apple Store Genius Bar. Recognized for patient issue resolution, CJ excels in teaching and empowering users. As Kinetic’s Configuration Specialist for 3 months, CJ is passionate about simplifying lives through tech. Beyond work, CJ explores cuisines, enjoys concerts, and embraces RomComs. The motto: Choose what’s right over what’s easy. CJ aspires to be remembered as a happy, eager, and passionate soul, inspired by daily opportunities to make a difference. Expect tech-savviness, culinary adventures, and unwavering commitment to everything done.

Julia Harryman

Julia Harryman, our resident efficiency specialist, has a unique background that is not typical of IT. Armed with a Master’s in Education for Technology Leadership, Julia has been an integral part of our team since 2012. Fueled by a constant supply of (insert current caffeinated beverage here) , she’s is a driving force behind our streamlined operations, ensuring that our company runs seamlessly.

Richie Owen

Richie Owen is an adept IT professional known for his innovative problem-solving. With a strong background in security systems for financial institutions over the past nine years, Richie excels in resolving networking and cabling challenges. Off-duty, he’s a bass-playing musician and a dirt bike enthusiast. In his six months at Kinetic, Richie has demonstrated his expertise, further supported by almost a decade of experience in low-voltage systems. He values human connections, citing music as his perpetual motivation. Richie’s love for limeade with tea and his belief that people make life meaningful reflect his distinctive character.

Chad Thorne

Chad bought his very first Mac as a senior in high school and hasn’t looked back since. To him, pushing the limit involves figuring out just how far he can push the performance on a Mac and testing his own IT knowledge and capabilities at the same time. This Cowtown native is super handy when it comes to configuring and deploying business networks and is one of 14 people on the planet who actually knows where ALL of the wires go.