
This year’s DBIR hits at a moment of change in the larger security conversation. 2025 was all about securing network infrastructure, but despite those efforts, it’s become clear that preventing breaches altogether is an unattainable goal. That’s why 2026 has brought a new focus: building resilient organizations that can survive attacks.
As Verizon states, “A key takeaway from the latest DBIR is that prevention is only half the battle; resilience is equally critical. To stay ahead, organizations need to evolve their security mindset—accepting that threats will persist while prioritizing the ability to reduce risk, react quickly, and recover effectively.”
Read on to learn what our experts extracted from the 2026 DBIR and how organizations can turn those insights into action. Our experts have highlighted some fascinating insights from the 2026 DBIR that sales partners can use to steer security conversations in the weeks and months ahead.
Adopting the VERIS Framework
When compiling their annual DBIR, Verizon relies on a shared vocabulary called VERIS (Vocabulary for Event Recording and Incident Sharing). Under the VERIS model, all security incidents can be understood according to the “four A’s,” which include:
- Actors. Who perpetrated the attack? Why do they act the way they do? And what tools (like AI) do they have at their disposal?
- Actions. What are these perpetrators doing? Is it hacking? Malware? Physical theft?
- Assets. What organizational assets were impacted, and how?
- Attributes. What approaches did the attackers take?
This framework allows organizations to better understand the threat landscape they’re facing, and Intelisys security experts are here to help. Trusted advisors can also dive deeper into an organization’s security posture by asking the right questions, including the conversation-starters appearing in the sections below.
5 Key Insights From This Year’s DBIR
The Intelisys team has highlighted 5 insights from this year’s DBIR that are especially relevant for sales partners and their customers. By drawing on these insights, sales partners and organizations can have more fruitful security conversations and, eventually, build resilience into the organization’s security framework.
Vulnerability Exploitation is Now the Leading Initial Access Vector.
As recently as 2023, “credential abuse,” or the use of stolen login credentials, represented criminals’ principal method of breaching an organization’s systems. Exploiting vulnerabilities, meanwhile, was responsible for less than 10% of breaches.
Three years later, the situation has been flipped on its head. Now, vulnerability exploitation is the initial access vector for 31% of breaches, while credential abuse’s share has dropped to 13%.
This data represents a fundamental shift in the tactics of threat actors, which should produce a corresponding shift in how organizations defend themselves. Protecting login credentials, while still vital, is no longer the top priority. The main focus for 2026 and beyond should be evaluating IT infrastructures for vulnerabilities.
Generally, a vulnerability assessment is where organizations should start. From there, they can work with trusted advisors to prioritize vulnerabilities based on their level of risk.
Conversation Starter 1: Did you know that gaps in a system are the main cause of hackers getting in? And with that in mind… when was the last time you examined your security posture with a vulnerability assessment?
Remediation Windows are Dangerously Long.
Once a vulnerability has been identified, the next step is to patch it effectively. Unfortunately, this necessary patching often takes far too long. According to the 2026 DBIR, the median time to remediate a vulnerability currently sits at 43 days. Just as concerning is the fact that only 26% of known exploited vulnerabilities are ever fully remediated.
This means organizations are leaving themselves open to attack, even when they know their weak points. It also suggests a fundamental shift is necessary in how stakeholders talk about vulnerability mediation.
For too long, people have spoken of vulnerabilities as a component of data or IT “hygiene.” But this framing undersells the threat. Vulnerabilities aren’t just “messy” – they’re gaping holes that threat actors can walk through. And every minute a vulnerability is left unremediated is another minute that a devastating breach could occur.
Now that vulnerability exploitation is the main access point for cybercriminals, organizations need to (a) identify vulnerabilities sooner and (b) develop a strategy for remediating those vulnerabilities in less than 43 days.
Conversation Starter 2: Did you know that 74% of vulnerabilities are not fully remediated? That means bad actors can easily walk through. Do you have full visibility into where those gaps are?
Ransomware is Now Involved in Nearly Half of All Breaches.
Ransomware, once a relatively small subset of cybercrime, is now involved in 48% of all data breaches. That means organizations can no longer ignore it as a real threat.
There is some apparent good news mixed in: Ransomware payouts are smaller than they used to be. The problem is that paying even these smaller ransoms is still a poor outcome for organizations, because it means the bad actors retain their access to the IT systems they’ve infiltrated. And often, the criminals are more interested in long-term disruption than short-term financial gain, anyway. That’s why the smart play is to avoid making those ransom payments.
But to successfully stare down the criminals and refuse to pay a ransom, an organization has to have a comprehensive recovery plan in place. The more resilient the organization, the easier it is to refuse to pay.
Conversation Starter 3: Do you have an incident response plan in place and have you tested it? And does the company know what to do if you get hit by a ransomware attack?
Attackers are Abusing Legitimate RMM Tools to Evade Detection.
There’s nothing so demoralizing as having your own weapons used against you. But for many organizations, the Remote Monitoring and Management (RMM) tools meant to enhance protection have instead given criminals a way in. The pattern is clear in the data. According to the DBIR, 2025 saw a 240% increase in RMM abuse by criminals.
By abusing RMM tools that have been white-listed in an organization’s security posture, criminals are able to hide their malicious activity amid normal IT traffic. This delays detection and recovery, often with devastating results.
In this environment, organizations need to double down on protecting RMM assets. That requires adhering to a familiar set of security best practices: employing multi-factor authentication (MFA), applying conditional access policies, and training employees to recognize phishing campaigns. Organizations should also consider employing a Managed Detection and Response (MDR) solution that will include core components like SIEM, SOC, and EDR.
Conversation starter 4: Did you know that third-party tools, including those that are meant to enhance security, are now a leading security vulnerability themselves? Are you taking steps to secure those tools?
SMBs are Disproportionately Targeted and Size is No Protection.
In the vast majority of reported data breaches (88%, according to the 2026 DBIR), the victim is a Small or Medium-sized Business (SMB) – which Verizon defines as any business with 1,000 or fewer employees. These are the types of businesses that account for a large portion of Intelisys’s end customers, making this a major trend to follow.
Many SMBs falsely believe that their small size protects them (“Who would bother targeting an organization the size of ours?”). But in reality, a small business’s relatively undeveloped security posture makes it a prime target for criminals. And due to the small size of the operation, attacks can be especially devastating. In the worst cases, the data loss from a breach can account for 7% of an SMB’s revenue.
SMBs need to understand that they’re even more vulnerable than their larger counterparts. Then, they need to work with trusted advisors to make resilience a priority.
Conversation starter 5: Did you know that 88% of all data breaches affect SMBs?
Case Study: A small business faces $80,000 in losses
One Intelisys security specialist worked with a four-employee company that had been alerted to a potential vulnerability. Instead of acting to remediate the problem, the company, perhaps based on the false notion that their small size would protect them, did nothing.
Threat actors eventually breached the company’s systems. From there, they managed to take control of all accounts and email fake banking details to the company’s clients. For two weeks, customers sent money to the criminals’ bank account, producing $80,000 in total losses.
By working to remediate the vulnerability as soon as they were alerted to it, and by recognizing that even small businesses face regular security threats, they could have avoided the financial and reputational damage.
The Sales Partner’s Role
Intelisys sales partners are perfectly placed to interpret the insights in the Verizon DBIR and present them to end customers. This doesn’t require an in-depth knowledge of every security solution but merely demands a focus on the importance of cybersecurity in all business conversations.
Sales partners should feel empowered to pull in Intelisys Solution Engineers (SEs) to support these conversations. The earlier SEs are brought in, the more value they can add to the overall discussion.
Between AI, IoT, and enhanced automation, organizations are modernizing fast. But every advancement widens the surface area for attack. No matter where an organization starts – from cloud solutions to CX – increasing resilience needs to be part of the conversation. Resiliency should be the priority from the beginning.
Conclusion
The era of completely avoiding cyber attacks is over. Now, the mission is to limit vulnerabilities while increasing the ability to recover from an attack. In other words, resilience is king, and recovery is just as important as initial security coverage. This represents a major shift in the ideal security mindset for organizations across industries.
In this moment of widespread transition, sales partners shouldn’t launch their security conversations with a focus on specific solutions. Instead, the discussion could begin with a single question: “What are you doing today to make your organization more resilient?”
That’s the conversation that will lead to a long-term relationship for the sales partner – and a reinvigorated security posture for the organization.
Be sure to leverage the additional resources at your disposal. Download the complete 2026 DBIR and contact your Intelisys representative to schedule a DBIR briefing.