Verizon's 2026 report puts credential abuse in 39% of fully traced breach chains. GitGuardian's account of how infostealers work explains why the developer endpoint is the cheapest place to collect them.
Reality
- Evidence45
- Adoption40
- Hype gap+22
- Incentives78
- Confidence42
Verizon's 2026 DBIR puts mobile phishing simulation click rates 40% above email. Most of those attempts never reach a security team, because the report button, the gateway and the triage queue all sit in the inbox.
Reality
- Evidence44
- Adoption9
- Hype gap+37
- Incentives86
- Confidence38
Verizon now puts vulnerability exploitation at 31% of initial access, up from 20%. Arctic Wolf's telemetry says about 17% of assets never appear in legacy vulnerability management at all, which sets a hard ceiling on any patch program.
Reality
- Evidence28
- Adoption18
- Hype gap+34
- Incentives88
- Confidence66
Its review of fiscal 2024 and 2025 says opportunistic scanning of known, internet-exposed flaws drove most compromises. The fix, it argues, belongs to software producers, not to defenders patching faster.
Reality
- Evidence58
- Adoption18
- Hype gap+15
- Incentives55
- Confidence55
The August 2026 calls, reported by Bloomberg and relayed in a CPA trade journal, reached people with credential reset privileges, which makes identity procedure rather than email filtering the surface under test.
Reality
- Evidence33
- Adoption56
- Hype gap+24
- Incentives66
- Confidence41
Essential entities face up to EUR 10 million or 2 percent of global turnover, and management bodies can be barred from executive roles, which makes access control the one Article 21 requirement a team can finish and evidence inside a month.
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+35
- Incentives80
- Confidence45
Verizon's 2026 breach report puts vulnerability exploitation at 31% of breaches, ahead of stolen credentials, which moves the awkward question from access policy toward whether anyone is watching the tools already bought.
Reality
- Evidence26
- Adoption
- Insufficient
- Hype gap+28
- Incentives76
- Confidence32
Verizon's 2026 report puts full resolution of a known vulnerability at a 43-day median, with most of the CISA critical list still open. The remedy on offer speeds triage, not patching.
Reality
- Evidence28
- Adoption
- Insufficient
- Hype gap+58
- Incentives82
- Confidence52
Two years of SIEM ingestion cuts left the data layer that agentic detection will run on, and 24% of security leaders now rank visibility above staffing as their top barrier.
Reality
- Evidence63
- Adoption38
- Hype gap+24
- Incentives76
- Confidence62
CrowdStrike argues AI security evaluations have converged on vulnerability discovery because it is easy to score, while most breaches still start with stolen credentials, phishing and trusted access.
Reality
- Evidence26
- Adoption
- Insufficient
- Hype gap+14
- Incentives78
- Confidence34