Leadership1 distinct publisher3 min readPublished
Verizon's 2026 breach report puts vulnerability exploitation at 31% of breaches, ahead of stolen credentials, which moves the awkward question from access policy toward whether anyone is watching the tools already bought.
The Board Room · Leadership desk

Compiled by The Board RoomSomething wrong?How this is made
A leading vector at 31% is a weaker statement than the ranking makes it sound. Verizon's 2026 Data Breach Investigations Report puts exploitation of software vulnerabilities at 31% of breaches, ahead of stolen credentials [1], which leaves roughly 69% of breaches starting some other way [1] and places credentials somewhere below 31% themselves [2]. The order of the top two has changed while the spread across routes has not, and that matters for anyone tempted to move an identity budget into vulnerability management on the strength of one table.
The board-deck version of readiness is a list of acquisitions: cyber insurance, an incident response retainer, endpoint detection, backups, and a few more products each year [4]. It is incomplete because acquisition and operation are funded on different clocks. Approval for a tool clears once; the rota that watches it at 3am and the drill that proves a restore is fast enough recur annually, and the half-finished capabilities Ryan Ikeler of MOXFIVE describes are all cases where the second clock was never wound [5].
MOXFIVE is paid by organizations already inside an incident [2], so a claim that executives overestimate their visibility, their response speed and the durability of their controls [3] doubles as a pitch. But the claim is cheap to falsify in-house: a restore drill has a stopwatch, and a round-the-clock monitoring rota has a name against every hour. A firm that runs both and finds its dashboard was accurate has spent an afternoon.
The detection argument is the part that should change how a quarterly review reads. Deloitte's 2025 Cyber Threat Trends Report describes attackers combining credential theft, social engineering, AI-assisted phishing and exploitation of existing vulnerabilities so that malicious activity is hard to separate from normal enterprise operations [8]. Ikeler adds that obfuscation, living-off-the-land technique and slow movement mean many intrusions never announce themselves with a ransom note or a black screen, and that the ones caught early are caught by teams actively looking [9]. If dwell time has always set how bad an incident becomes [10], the line item that governs severity is hunting capacity rather than alert volume, and attacker-side AI compresses the time available without altering the mechanism [11].
On Ikeler's account, investigations rarely trace to a single failure and usually trace to a chain of forgivable ones: a deferred patch, a credential that outlived its purpose, an unverified segmentation boundary, a gap in monitoring [7]. That points away from any single emergency purchase and toward upkeep of what is already in place. Chains break at their cheapest link, which is why his own prescription favours tools that have performed in real incidents over what shows well in a demo [12], and why he treats maturity as how effectively tools are deployed rather than how many exist [6]. The choice this quarter sets up for next year is whose budget absorbs the running cost of what is already owned, because if that lands nowhere, the 31% will still be accurate and the coverage report will still read green.
Ranked by verification strength, evidence, and original report placement.
The 2026 Verizon Data Breach Investigations Report found that exploitation of software vulnerabilities has overtaken stolen credentials as the leading initial access vector, accounting for 31% of breaches.
Ryan Ikeler is president of MOXFIVE, a firm that advances business resilience and technical recovery for organizations navigating cyber incidents.
Deloitte's 2025 Cyber Threat Trends Report notes attackers continue to blend credential theft, social engineering, AI-assisted phishing and exploitation of existing vulnerabilities in ways that make malicious activity more difficult to distinguish from normal enterprise operations.
If vulnerability exploitation accounts for 31% of breaches, about 69% of breaches begin through some route other than vulnerability exploitation.
Because exploitation leads at 31% having overtaken stolen credentials, credential theft now accounts for less than 31% of breaches.
Ikeler writes that across live investigations companies consistently overestimate how much visibility they have, how quickly they can respond and how well their controls will hold under pressure, and that the gap between what leaders believe and what is true is where most incidents live.
Distinct publishers with included, body-backed reporting in this cluster.
forbes.com
1 article · August 28, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
Benchmarking AI On Bug Hunting Scores 31% Of The Breach Problem1 distinct publisher
security
96% confident, 63% breached: the confidence number boards should stop accepting1 distinct publisher
security
43 days, 26 percent, and a pitch that saves you 29 minutes1 distinct publisher
build
Google's legal AI bundle lands a day after a $40M model, and the connector list tells you why2 distinct publishers
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Two borrowed statistics holding up a memoir
Strip out the two citations and nothing here is checkable. The 31% and the ranking flip belong to Verizon; the blended-tradecraft observation belongs to Deloitte; both arrive as sentences in someone else's column, with no link, no methodology and no figure for the credential theft that was supposedly overtaken. The rest — the unmonitored EDR, the backups that would not restore in time, the chain of forgivable gaps — is recalled from investigations no reader can inspect, by the man who ran them. It is plausible and specific, and it is still testimony.
Nobody named, nothing dated
There is no adoption to measure. No organization is named, no product is deployed or dropped, no incident is dated, no restore test is reported as passed or failed. The piece describes patterns across unnamed investigations, which is the opposite of a trackable event, so we leave this blank rather than convert anecdote into a number.
Deflationary advice, inflated foundation
Unusual shape. The advice itself is deliberately unglamorous — finish the deployment, test the restore, stop buying — which is the least hyped thing anyone says about security spending. The overstatement sits underneath it: a single unverified statistic is presented as a settled turn in how breaches begin, 'battle-tested' is offered as a purchasing standard with no test named, and the pattern claims carry the confidence of data while resting on recollection. Modest gap, and it comes from the framing rather than the recommendation.
The remedy is the author's product
Read the closing advice and then the byline. Ikeler tells readers to engage firms that investigate breaches across many industries before they generate their own incident; Ikeler is president of MOXFIVE, which does resilience and technical recovery for companies in incidents. Forbes' council format at least puts that affiliation in the first line, which is more disclosure than most vendor commentary manages, and the piece never names a product to buy. But the argument's destination and the author's business are the same place, and no independent voice in our coverage tests either.
Single voice, single venue
Our confidence is limited by arithmetic more than judgement: one publisher, one interested author, zero corroboration. What we can stand behind is narrow and solid — the disclosure is explicit, and the derivations from the quoted figure (credentials below 31%, non-exploitation routes still the majority) follow with no room for argument. Everything the story is actually about would move a long way on one look at the underlying Verizon report or one vendor-neutral account.