Why consistent application of security principles is the only path to true cyber resilience in 2026
TL;DR:
- The shift: Cybersecurity has to evolve from a project-based thinking to a continuous state of operational resilience.
- The threat: 2025 saw a nearly 60% surge in ransomware and over 45% unmanaged devices with corporate credentials.
- The compliance catalyst: Directives like NIS2 and DORA are no longer just legal burdens; they may provide the essential framework for risk management and board-level accountability.
- The solution: True resilience requires constant application of security principles – specifically centralized control over Privileged Access Management (PAM) to eliminate dormant accounts and unmanaged credentials.
- The goal: It’s not about if you will be attacked, but how fast you can withstand, recover, and adapt.
In their cybersecurity forecasts for 2026, many experts agree – digital security cannot be a silo isolated from the rest of the organization. Audits and regulations are effective triggers for security, but they often lead to reactive rather than sustainable protection. Checklist ticked off, it’s time to move on and return to more pressing matters – in many places, cybersecurity is unfortunately still an afterthought… But the statistics are sounding the alarm.
According to a Cyber Security Report, 2026 by Check Point Software Technologies Ltd., the ransomware landscape reached a critical tipping point in 2025. The number of victims shamed on double-extorsion leak sites surged to over 7,960 - a staggering 53% year-over-year increase. While the overall volume of successful extortions rose, the education sector remained the primary target for cybercriminals.
As developers of Privileged Access Management Software, we constantly ask the same question: Who has privileged access to critical systems, and is that access fully controlled? And considering the trends for 2026, we must also ask: Are organizations resilient against cyberattacks? We will elaborate more on what we mean by the word ‘resilience’ in this article.
Industries in the unwanted spotlight
Educational institutions faced an average of 4,352 attacks per organisation weekly, representing a 22% increase and securing troubling first place as the most targeted industry globally. The vulnerability of the education sector is a global phenomenon; Check Point’s data reveals it was the most targeted industry across every surveyed region, from North America and Latin America to APAC and Europe. This trend is driven by a high concentration of sensitive data and invaluable research, coupled with notoriously open network policies that leave institutions exposed to both sophisticated targeted campaigns and opportunistic exploits.
On a global scale, the unwanted spotlight extended beyond education to other critical sectors. Government institutions faced intense pressure with an average of 2,683 weekly attacks - a 17% increase - while the telecommunications industry followed closely with 2,656 attacks per week, marking a significant 27% year-over-year surge. Interestingly, this hierarchy of vulnerability is mirrored in Europe, where Education, Government, and Telecommunications consistently claim the top three spots on the threat landscape.

What were the attack vectors?
Software vulnerabilities exploitation
Verizon’s Data Breach Investigations Report 2025 points out that threat actors are increasingly bypassing traditional security measures by exploiting software vulnerabilities. This method saw a 34% surge compared to 2024, becoming nearly as common as credential theft which takes infamous first place. Edge devices and VPNs are particularly at risk with an eight-fold increase as the attack target. While organizations struggle to patch these vulnerabilities, the statistics are ruthless: remediating a critical flaw takes a median of 32 days, and nearly half remain unpatched throughout the entire year. This grants cybercriminals a massive window of opportunity to execute successful attacks.
The security gap in third party environments
Verizon’s 2025 report highlights another nightmare of IT departments which is leaked secrets. Developers frequently expose sensitive information such as API keys and tokens, within public GitHub repositories. The median time to remediate these exposed secrets was found to be a staggering 94 days. This three month window of vulnerability provides threat actors with opportunity to reuse these credentials and gain unauthorized access to secure environments.
Work and private life: Keep them apart
Verizon’s researchers emphasize one more dangerous aspect: mixing personal and corporate habits. Analysts of infostealer malware logs reveal that 46% of compromised systems containing corporate logins were unmanaged devices, likely part of BYOD (Bring Your Own Device) programs or policy violations. It means that first a data thief steals passwords from a personal device and sells them to an access broker in a suspicious platform. Verizon’s analysts point out that 54% ransomware victims appeared in credential dumps before the actual breach occurred. It seems that the attack begins long before the corporate infrastructure is even compromised. It’s the final stage of a supply chain which likely began at someone’s home.

Are we making it too easy for hackers?
There is still a prevailing belief that cybersecurity is primarily about software. An installed firewall, active antivirus, and a few documented security policies. Each of these implementations is treated as a separate project. Then, unfortunately, issues such as expiring licenses or ignoring the associated costs often slip through the cracks, because, after all, nothing is happening, so they are not included in the current budget. The absence of incidents pushes system and application patching down the priority list. Nor is much attention paid to tool configuration, since the default settings are deemed sufficient. And since the systems send too many false-positive alerts, let’s just turn them off - they’re an unnecessary distraction.
The anatomy of breach: From Laziness to AI-supported spies
If we look a little deeper, we can also spot mistakes such as granting unrestricted access to a resource or system just to keep someone from bothering. Later, it turns out that access for external employees and subcontractors is too broad, and in the event of an incident, it is often difficult to trace the history of access to areas of particular importance, or there is a lack of centralized information about current permissions.
Industrial environments are often digital time capsules. In many facilities legacy systems are treated like an unexploded bomb - best not to touch it, as its stability is delicate. Add to that missing MFA which is usually more of a myth than a reality.
Offboarding procedures don’t always work well. Dormant, abandoned accounts are an open door for cybercriminals who, depending on the level of privileges assigned to the account, can sneak in and wait for the right moment to strike.
And finally, there are today’s incredibly convincing and nearly flawless phishing emails. A convincing voice on the other end of the line asks for access to a critical system. Add to that a fully AI-generated employee’s face on the computer screen during an online meeting, declaring readiness to perform any task. But that person fails to mention that each assignment is generated by artificial intelligence, and that he is actually spying for the North Korean government, sending his salary to support the regime… And that’s unfortunately true, as the creators of Claude detected a malicious use of their AI tool to create fake employee identities.
There are countless ways a company can be attacked, and cybercriminals are becoming more and more clever, especially through the use of AI (which brings us to the concept of dual-use). Many are probably asking themselves, but what can be done about this? Always be prepared for a potential attack. However, many are surely asking themselves – what does this ‘preparedness’ entail?
Operational Risk Management
Every day, something may – but doesn’t have to – go wrong. People make mistakes. Processes derail under pressure. Systems fail at the worst possible moment. A seemingly minor issue can escalate into a crisis that engulfs the entire organization. Fortunately, there are measures available to bring a critical situation under control in time.
In 1974, the Basel Committee on Banking Supervision developed a definition of Operational Risk Management (ORM), according to which operational risk is “the risk of loss resulting from inadequate or failed internal processes, people, and systems or from external events.” This definition was created primarily for banks and financial institutions to strengthen financial stability by improving global oversight of the banking sector, fostering cooperation, and eliminating gaps in cross-border regulations.
In practice, ORM asks three questions:
- What could go wrong?
- What damage would it cause?
- What actions will be taken?
And the goal is simple: to minimize unforeseen losses and protect business continuity. Initially, ORM focused on ensuring companies had sufficient capital to cover financial risks; however, over the years, the Committee’s definition has evolved, and various standards - such as ISO 31000, ISO 22301, and, unsurprisingly, DORA (Digital Operational Resilience Act) - have drawn upon it.

A helping hand from legislators in building cyber resilience
It might seem that everything has already been said about the NIS2 and DORA directives. For some, the necessity of implementing them (depending on the industry) may seem like a burdensome obligation. Few people would honestly admit to loving compliance. However, these and other directives provide something that organizations urgently need today in terms of security – structure and a shift in mindset regarding cybersecurity, moving from a one-time project-based implementation to an area of continuous improvement.
DORA
DORA (Digital Operational Resilience Act) was first proposed by the European Commission in September 2020 and primarily covers companies in the financial sector, including the regulation of crypto-asset initiatives and the strengthening of the overall digital financial strategy. DORA focuses on managing risks related to information and communication technology (ICT). Its scope also covers the monitoring of cyber threats and incidents, managing relationships with external suppliers, and requirements for testing operational resilience systems.
NIS2 Directive
The NIS2 directive imposes a legal obligation on critical and important entities to implement risk management measures. It addresses areas such as business continuity, incident management, disaster recovery, backup management, access policies, and identity management. Organizations must monitor the security of their suppliers and partners, which necessitates raising standards across the entire IT/OT ecosystem.
Under the regulation, the responsibility for building cyber resilience and implementing cybersecurity measures rests with board members, and thus, they may face consequences for failing to fulfill their obligations. The point here isn’t to scare anyone, but shirking responsibility may simply not be worth it. If an incident occurs at a company resulting in data being stolen, the relevant authority may impose heavy fines, and, according to NIS2 compliance, the person responsible for security may face a temporary ban on holding managerial positions. The organization loses the person responsible for strategic security.
It is important to view regulations as a cohesive groundwork of interconnected elements encompassing the entire organization. Laws provide a framework in which cybersecurity ceases to be a closed system and begins to interact with the entire enterprise risk and security management structure.
Why is cyber resilience important?
At this point, we arrive at the culmination of the above considerations - cyber resilience. It refers to whether organizations have the ability to anticipate, withstand, recover their operational capacity, and adapt to a new reality following a cyber incident. Unlike traditional approaches to security, a cyber resilience strategy focuses on prevention and acknowledges that breaches are inevitable.
Cyber resilience is characterized by a holistic approach to the organization that integrates people, processes, and technologies to create a comprehensive protection strategy that minimizes damage and ensures business continuity.
DORA and NIS2 are pillars of modern cyber resilience, yet they bring undeniable challenges. Many teams struggle with the breadth of these regulations, leading to ambiguity during the rollout phase. To bridge this gap, it is crucial to tailor these standards to local needs and draw on the synergies between NIS2 and ISO 27001 – a standard many companies already have in place.
Few people would honestly admit to loving compliance. However, these and other directives provide something that organizations urgently need today in terms of security – structure and a shift in mindset regarding cybersecurity, moving from a one-time project-based implementation to an area of continuous improvement.
Summary - Think how you’ll respond to cyberattack
Current forecasts indicate that the evolving digital landscape, particularly with the rise of artificial intelligence, demands a strategy of continuous readiness and disciplined security practices. Cybercriminals are adapting quickly, making it essential to focus on how organizations will respond to inevitable attacks.
There are many reasons why cyber resilience should be a priority. Frequent disruptions to business operations caused by cyberattacks – whether motivated by financial gain or carried out on behalf of governments – are a major concern. Furthermore, many companies operate in a hybrid or fully remote model. In this case, the goal of cyber resilience is to ensure that employees can securely and efficiently access company resources from anywhere without disrupting their productivity.
Fudo Enterprise 6.0 can support building the foundation of a modern cyber resilience strategy. In a world where cybersecurity is a structural shift, Fudo ensures that your organization is not only protected but also resilient.
Check out the landing page about the latest version of Fudo Enterprise 6.0 and see how you can respond do current cybersecurity challenges. If you have a question, do not hesitate to contact us!