DBIR 2026: Vulnerabilities and Ransomware Shape Incident Readiness
Verizon's latest report reveals exploitation of vulnerabilities and rising ransomware as key challenges. Preparation is crucial.

The 2026 Verizon Data Breach Investigations Report, analyzing over 22,000 confirmed breaches across 145 countries, highlights a stark reality: organizations struggle to patch vulnerabilities quickly enough to prevent incidents. Exploitation has surged to become the leading initial access vector. The median time to fix a critical flaw has climbed to 43 days, with the number of critical vulnerabilities growing by 50% annually.
Even top-performing organizations managed to remediate only 30% to 40% of known exploited vulnerabilities from the CISA catalog within the first week of detection. Despite years of investment, this rate remains static, illustrating the persistent risk of serious incidents.
Ransomware appeared in 48% of confirmed breaches, up from 44% the previous year. Among these, 96% of victims were small and medium-sized businesses. While 69% of victims chose not to pay, the median ransom payout dropped to $139,875. Ransomware operators are now maximizing operational disruption, as seen in the 2025 attacks on Marks & Spencer and Jaguar Land Rover.
Breaches involving third parties rose by 60%, accounting for 48% of incidents. The DBIR identifies three archetypes: vulnerabilities in vendor products, compromised vendors holding client data, and lateral attacks through vendors. Organizations often neglect to simulate these scenarios, leading to poor response when they occur.
Vulnerability exploitation accounted for 31% of breaches, a 55% increase. AI's role is accelerating this trend, with AI-assisted threat actors targeting vulnerabilities as new tools emerge. Anthropic’s research highlights AI’s potential in creating exploit tools and conducting espionage, demonstrated by the VoidLink malware framework.
The DBIR calls for a shift in incident response exercises, advocating for realistic technical tabletop exercises to refine triage and containment strategies. Organizations must practice under pressure to close the gap between attackers and defenders.



