Cybersecurity: what are the biggest challenges now?

Last updated: 11 September 2026
market research pitch 2026 statistics cybersecurity market

In our cybersecurity market deck, you will find everything you need to understand the market

SUMMARY

Cybersecurity: what are the biggest challenges now? The biggest challenges are exposed software, compromised identities and third-party access, with ransomware, attack speed and AI making those weaknesses harder to contain and more expensive when they fail.

Vulnerability exploitation has moved to the front of several major breach datasets. The important shift is timing: attackers can weaponize exposed flaws within days, while critical remediation inside companies can still take weeks.

Identity security is also moving beyond passwords. Sessions, tokens, OAuth permissions, MFA enrollment, account recovery and machine credentials now give attackers several ways to stay inside legitimate access without looking like a traditional intrusion.

Third-party risk has become a structural problem rather than an edge case. A company can secure its own employees and endpoints well and still lose data through a trusted SaaS integration, supplier or connected application with excessive reach.

Ransomware is becoming more fragmented even as payment resistance improves. More victims are refusing to pay and aggregate ransom revenue has fallen, yet claimed attacks, specialist groups and data-theft extortion keep expanding.

The clock has changed dramatically. Some criminal access handoffs now happen in seconds and some intrusions begin moving laterally or stealing data within minutes, which makes slow manual escalation a real defensive weakness.

Cloud attacks increasingly look like legitimate business activity. Attackers are abusing real accounts, approved APIs and normal SaaS functions, so detecting bad behavior now depends heavily on context rather than simply finding malware.

Leaked secrets are becoming an identity problem of their own. API keys, repository tokens and other machine credentials can remain active for years, and one exposed secret can open the path to several more.

AI is already changing the economics of cyberattacks more than the basic mechanics. It makes reconnaissance, phishing, code adaptation and data processing faster, while enterprise AI agents create new high-permission identities that can reach sensitive systems.

The hardest environments are the ones with weak visibility or limited room to patch. Industrial networks and internet-facing edge devices combine operational constraints with high impact, which is why failures there can become unusually costly.

The broad pattern is that modern cybersecurity is now a trust-management problem spread across software, people, cloud platforms, suppliers and AI systems. Attackers only need one relationship to be exposed, overpowered or poorly monitored; defenders have to understand all of them well enough to respond fast.

Market map chart showing top companies and startups in the cybersecurity market

This market map, featured in our cybersecurity market deck, highlights top companies and startups in the cybersecurity market

Why is cybersecurity getting harder even after years of bigger security budgets?

Cybersecurity is getting harder today because companies have connected far more systems, identities and suppliers than their security teams can consistently control, while attackers have become much faster at exploiting the gaps between them.

The speed difference is especially striking. CrowdStrike's latest Global Threat Report measured an average eCrime breakout time of 29 minutes, down sharply from the previous year. Its fastest case reached another system only 27 seconds after the initial compromise. In a separate intrusion, attackers started taking data within four minutes.

At the other end, Mandiant found that some espionage and insider intrusions were still hiding for months. Its global median dwell time rose from 11 to 14 days. Defenders currently face criminals who move almost immediately and sophisticated intruders who are happy to stay quiet.

The environment they have to protect keeps getting bigger too. Verizon analyzed more than 22,000 confirmed breaches in its latest DBIR and found third parties involved in 48% of them. GitGuardian found about 29 million new secrets exposed in public GitHub commits during 2025. Google has meanwhile seen attackers move through cloud identities, SaaS applications and trusted integrations rather than staying inside a single compromised computer.

Security teams also need more specialized knowledge than they used to. ISC2 stopped publishing its familiar global "cybersecurity workforce gap" number because its latest research found that organizations increasingly care more about missing skills than raw headcount. AI security, cloud, application security, risk and governance were among the areas where practitioners said expertise was lacking.

The common problem is that every new SaaS app, API, contractor, cloud service and AI agent creates another trusted connection that someone has to understand and police.

Have software vulnerabilities become the easiest way for hackers to get in — and can companies patch them fast enough?

Software vulnerabilities have become the leading breach entry point in the latest broad datasets, and many organizations are still patching critical exposed systems too slowly to beat attackers.

Verizon's latest DBIR found vulnerability exploitation in 31% of breaches. For the first time in the report's 19-year history, it moved ahead of stolen credentials as the most common initial route into a breached organization. The figure was also 55% higher than in Verizon's previous dataset.

Mandiant has seen the same problem for longer. Exploitation was the initial infection vector in 32% of the incidents it investigated during 2025 and has now ranked first in its data for six consecutive years. IBM X-Force also reported a 44% rise in attacks exploiting public-facing applications.

Google's cloud telemetry shows how quickly the balance can move. Software-based entry accounted for just 2.9% of observed cases in the first half of 2025. In the second half, third-party software exploitation reached 44.5%, overtaking weak credentials. Remote-code-execution exploitation alone rose to 13.6%, nearly five times its earlier share.

The timing makes this much harder. Verizon puts the median time to resolve a critical vulnerability at 43 days, almost two weeks longer than in its previous dataset. Google, meanwhile, says the gap between public disclosure and widespread exploitation has fallen from weeks toward days. When React2Shell became public, it observed cryptocurrency miners being deployed roughly 48 hours later.

Edge devices are especially exposed. CrowdStrike found that 40% of vulnerabilities exploited by China-linked threat actors during 2025 targeted edge devices such as firewalls and VPN appliances. Dragos found a similar remediation problem in industrial systems: 25% of the industrial-security advisories it reviewed had no vendor patch or mitigation, while another 52% required alternative mitigations.

Companies cannot treat every flaw with the same timetable anymore. For exposed, actively exploitable systems, a monthly patch cycle can simply be too slow.

Research source Latest finding What we learn from it
Verizon DBIR Vulnerabilities started 31% of breaches Exploits have overtaken stolen credentials in its broad breach dataset
Mandiant M-Trends Exploits started 32% of investigated intrusions Exploitation has remained its leading entry route for six years
Google Cloud Software-based entry reached 44.5% of observed H2 cases Cloud attackers shifted very quickly toward vulnerable applications
IBM X-Force Public-facing application exploitation rose 44% The rise is visible across another large incident-response dataset

If you want more recent data on this point, please see our latest cybersecurity market report.

Google Trends chart showing rising interest in cybersecurity

As this chart shows, and as featured in our cybersecurity market deck, search interest in cybersecurity has been trending upward

Are stolen passwords still the biggest identity problem, or are hackers finding easier ways around login security?

Stolen passwords remain extremely common, but cybersecurity's identity problem now includes session cookies, MFA enrollment, OAuth permissions, access tokens and social engineering aimed directly at employees and help desks.

Microsoft's latest threat data still shows how much criminal activity relies on basic passwords: password spraying accounted for 97% of the identity attacks it observed. Weak passwords, reuse and large databases of stolen credentials continue to give attackers cheap ways to test accounts at scale.

But many of the more interesting attacks happen after or around login. Google found identity issues behind 83% of the major cloud and SaaS compromises it investigated in the second half of 2025. Attackers were taking over legitimate accounts, stealing tokens or finding ways to keep access after the victim had authenticated.

Voice phishing is becoming part of that playbook. Mandiant saw traditional email phishing fall from 14% of observed initial-access cases in 2024 to 6% in 2025, while voice phishing reached 11% and became its second-most-common initial infection vector. Google's cloud investigations also found vishing in 17% of cases, ahead of email phishing at 12%.

Verizon's phishing simulations help explain the appeal. Mobile entry points such as calls and text messages produced median success rates about 40% higher than email phishing.

Recent campaigns linked with groups using the ShinyHunters name show how this works in practice. Attackers have called employees, impersonated IT support, captured credentials and MFA codes, reused authenticated sessions and then moved into services such as Salesforce, Okta and Microsoft 365. Google also documented Salesforce-focused campaigns in which callers persuaded employees to authorize a connected application through a legitimate interface.

Microsoft has separately documented social-engineering campaigns built around fake passkey enrollment, after which attackers obtained persistent access and searched cloud services through Microsoft Graph.

MFA alone no longer closes the identity problem. Companies also have to control who can register authentication methods, issue tokens, authorize applications, reset accounts and keep sessions alive.

Is ransomware still the biggest cyber threat to companies?

Ransomware remains one of the biggest cybersecurity threats to businesses today because attacks are still rising even as more victims refuse to pay.

Verizon found ransomware in 48% of the breaches in its latest dataset, up from 44%. ENISA also judged ransomware the most impactful cyber threat in its latest EU threat landscape, even though DDoS attacks generated far more recorded incidents.

Industrial companies show what "impactful" means in practice. Dragos tracked around 3,300 industrial organizations hit by ransomware during 2025, while the number of ransomware groups targeting the sector jumped from 80 to 119. Manufacturing accounted for more than two-thirds of the victims.

The encouraging part is the money. Chainalysis estimates identifiable on-chain ransomware payments fell about 8% to roughly $820 million during 2025 while publicly claimed attacks rose around 50%. Verizon separately found 69% of ransomware victims in its dataset did not pay.

Attackers are responding by spreading wider and asking successful victims for more. Chainalysis measured a 368% increase in the median observed ransom payment, to almost $60,000. The ecosystem also relies increasingly on data theft, where attackers threaten to publish sensitive information even if the victim can restore encrypted servers from backup.

The result is a strange market: more claimed attacks and more ransomware groups, but less aggregate ransom revenue.

Ransomware measure Latest result What changed
Verizon breaches involving ransomware 48% Up from 44%
Claimed attacks tracked in Chainalysis research +50% Attack volume rose sharply
Estimated on-chain ransomware payments About $820M Down about 8%
Verizon victims that did not pay 69% Refusing payment is increasingly common
Industrial ransomware groups tracked by Dragos 119 Up from 80
Chart illustrating yearly VC funding for cybersecurity startups

This chart, included in our cybersecurity market deck, illustrates yearly VC funding for cybersecurity startups

Can a company actually protect itself from third-party cyberattacks?

Companies can reduce third-party cyber risk, but they cannot fully control it, which makes suppliers and integrations one of the hardest cybersecurity problems to solve today.

Verizon found third-party involvement in 48% of breaches in its latest DBIR, a 60% increase from the previous dataset. Third parties appeared in 69% of Asia-Pacific breaches, 54% across EMEA and 43% in North America.

Google saw compromised third-party relationships in 21% of the major cloud and SaaS incidents it examined. IBM has taken a longer view and estimates that major supply-chain incidents have increased almost fourfold over five years.

The Salesloft Drift compromise showed how indirect this can become. Attackers obtained OAuth tokens tied to a trusted integration and then queried customer Salesforce environments. A customer could have strong endpoint protection and well-configured employee MFA while still losing data through access previously granted to another service.

Modern companies can easily have hundreds or thousands of these relationships. CRMs connect to sales tools, identity providers connect to SaaS platforms, CI/CD systems hold access to source code and cloud infrastructure, and AI tools increasingly connect to documents, email, databases and APIs.

A vendor's security tells only part of the story. The sharper question is how far that vendor can reach after it gets compromised.

If you want more recent data on this point, please see our latest cybersecurity market report.

Is cloud security getting worse, or are companies giving cloud accounts too much access?

Cloud security problems today are mostly coming from identities, vulnerable applications and trusted SaaS connections, with attackers taking advantage of legitimate access much more often than they break the cloud platform itself.

Google's latest Cloud Threat Horizons research gives us a useful breakdown. Identity issues underpinned 83% of the major cloud and SaaS compromises it investigated, data was targeted in 73%, and third-party or software-supply-chain relationships appeared in 21%. Misconfiguration, often treated as synonymous with cloud security failure, accounted for 7%.

Attackers are also moving across SaaS products once they have a good identity. Google has documented intruders starting with Salesforce access and then trying to reach services such as Okta and Microsoft 365. Its BlackFile research found attackers searching SharePoint, OneDrive, Zendesk and Salesforce for sensitive information before automating data theft.

Single sign-on makes administration easier and usually improves security, but it also creates powerful identities. An employee with access to ten business applications gives an attacker ten potential destinations after one account takeover.

The important cloud-security question is increasingly how much a legitimate identity is allowed to reach, and how quickly unusual use of that access can be spotted.

Chart showing CrowdStrike’s playbook in the cybersecurity market

This chart, included in our cybersecurity market deck, breaks down CrowdStrike’s playbook in cybersecurity

Are leaked API keys becoming a bigger cybersecurity problem than companies realize?

Leaked API keys and other machine credentials are becoming a major cybersecurity problem because software creates them at enormous speed and companies are leaving many of them active for years.

GitGuardian detected about 29 million new secrets in public GitHub commits during 2025. The number was around 11 million in 2021, meaning secret leakage increased by roughly 152%. GitGuardian calculates that secrets have been leaking about 1.6 times faster than the active developer population has been growing.

Private code does not solve the problem. GitGuardian found at least one secret in 32.2% of the internal repositories it scanned, compared with 5.6% of public repositories. Another 28% of secret-sprawl incidents occurred exclusively outside code repositories, in places such as collaboration and productivity tools.

Remediation is painfully slow. GitGuardian retested credentials first found exposed in 2022 and discovered that 64% were still active four years later.

AI-assisted development is adding more pressure. Commits co-authored with Claude Code leaked secrets at roughly twice the public-GitHub baseline in GitGuardian's analysis, while exposure of credentials connected with several AI services grew several-fold.

Attackers can also use one secret to find the next. Microsoft's researchers have recently uncovered malicious npm packages built to steal cloud and CI/CD credentials, while Google has seen stolen GitHub tokens lead attackers into repositories where they discover database keys and application credentials.

For large companies, machine identities can already outnumber employees by a huge margin. Many security programs still control the human side much better than this growing machine-identity layer.

Is AI actually making hackers much more dangerous right now?

AI is already making cyberattacks faster and easier to scale, although the breaches happening today still rely heavily on familiar weaknesses such as vulnerable software, stolen access and social engineering.

CrowdStrike recorded an 89% year-over-year rise in attacks by adversaries it classifies as AI-enabled. Its researchers have seen AI used for reconnaissance, credential theft, social engineering and evasion. Verizon found verifiable generative-AI assistance across a median of 15 separate attacker techniques.

The practical advantage is productivity. An attacker can research a company, translate a convincing message, change malicious code, summarize stolen documents and create dozens of phishing variations much faster than before.

The latest breach data still puts software vulnerabilities, credentials and human manipulation at the front of the attack chain. AI currently makes proven techniques cheaper and easier to repeat.

That can still change the economics sharply. Even if an attack's success rate stays the same, cutting the time and cost required to target each victim lets attackers try it against far more people.

If you want more recent data on this point, please see our latest cybersecurity market report.

Chart showing the projected CAGR of the cybersecurity market

This chart, included in our cybersecurity market deck, illustrates yearly funding for cybersecurity startups

Are companies creating a new cybersecurity problem by connecting AI agents to everything?

Enterprise AI is creating a serious new attack surface because agents are being connected to email, documents, code, databases and business actions before companies fully know how to control those permissions.

CrowdStrike found attackers manipulating legitimate generative-AI tools at more than 90 organizations to generate commands associated with credential theft or cryptocurrency theft. It has also observed attacks against AI development platforms and malicious services impersonating trusted AI infrastructure.

The bigger issue is what AI systems are allowed to do. A chatbot that answers questions from public information has limited reach. An AI agent that can read an executive's email, open internal files, call APIs, edit code and trigger workflows carries much more risk.

Prompt injection becomes more serious in that environment. A malicious instruction hidden in a web page, document or retrieved data source can potentially influence what an agent does next, with the consequences determined by the permissions that agent already has.

Companies clearly recognize the problem. In the World Economic Forum's latest cybersecurity survey, 87% of respondents identified AI-related vulnerabilities as the fastest-growing cyber risk. The share of organizations with a process for assessing AI-system security also jumped from 37% to 64% in one year.

The next security battle will largely come down to permissions: which agents can reach which data, which actions require human approval and how quickly access can be removed.

Are hackers now moving faster than security teams can react?

Some cyberattacks now move so quickly that a normal human escalation process can lose before the first serious response decision is made.

CrowdStrike's 29-minute average eCrime breakout time is already difficult for teams that depend on an analyst reviewing an alert manually. The 27-second fastest case shows the extreme. In another attack from the same dataset, data exfiltration began four minutes after entry.

Mandiant uncovered an even stranger compression in the criminal supply chain. In 2022, the median gap between an initial-access partner obtaining access and handing it to another criminal operator was more than eight hours. During 2025, that median fell to 22 seconds.

That suggests some attackers are coordinating access before the victim is even compromised. Initial-access specialists can prepare malware, tunnels or backdoors for another group rather than breaking in first and looking for a buyer afterward.

Defenders often work on very different clocks. A suspicious login may need analyst review, account suspension may require confirmation, and different teams can own identity, cloud and endpoint response.

For the fastest incidents, at least some containment has to happen automatically.

If you want more recent data on this point, please see our latest cybersecurity market report.

Chart comparing business model options for XDR and MDR cybersecurity vendors

This chart, included in our cybersecurity market deck, compares the main business model options for XDR and MDR cybersecurity vendors

Is looking for malware becoming less useful in modern cyberattacks?

Malware detection still matters, but modern attackers increasingly use legitimate accounts, cloud applications and administrative tools, so security teams have to recognize bad behavior even when every individual action looks allowed.

CrowdStrike says 82% of its detections during 2025 were malware-free. ENISA has also highlighted the spread of "living off the land" and "living off trusted sites" techniques, where attackers use software and web services that defenders already trust.

Recent cloud intrusions make the problem easy to picture. Google has documented attackers using Salesforce's normal bulk-data functions, Microsoft Graph, authenticated web sessions and ordinary HTTP requests to collect information. Some SharePoint and OneDrive activity looked much like legitimate file access in standard logs.

A malicious executable may trigger endpoint defenses immediately. A valid employee session requesting files through an approved API can blend into thousands of normal events.

The difficult part is context. One CRM export may be legitimate; an employee suddenly exporting an entire customer database after enrolling a new authentication method is much harder to dismiss.

Why are factories and critical infrastructure still so hard to secure?

Factories and critical infrastructure remain unusually hard to secure because many industrial environments have poor visibility, old equipment and operational constraints that make normal IT security practices difficult to apply.

Dragos's latest OT research puts numbers on the visibility problem. Only 30% of OT networks in its dataset had adequate visibility, 56% could not see activity below the IT/OT boundary, and 88% struggled with detection and response.

Its field work found problems before an attacker even enters. Poor IT/OT segmentation appeared in 81% of assessments, while compromised VPN or jump-host credentials had been involved in 73% of Dragos's historical incident-response cases.

Attackers are also learning more about the physical processes behind the machines. Dragos says threat groups are mapping control loops, engineering workstations, actuators and gateways to understand how digital commands translate into physical effects.

Ransomware adds another source of pressure. Around 3,300 industrial organizations were affected during 2025, according to Dragos, and attacks rose 64% year over year. A plant can lose production even when ransomware never directly infects an industrial controller because companies often shut operations down when the surrounding IT environment becomes unsafe.

Patching is harder here too. A decades-old production system may need continuous availability, depend on a vendor that no longer supports it or require a planned shutdown before software can be changed.

Chart illustrating revenue distribution by customer segment in the cybersecurity market

This chart, featured in our cybersecurity market deck, illustrates revenue distribution by customer segment in the cybersecurity market

Has cybercrime become a proper business industry?

Cybercrime increasingly works like a specialized business industry, with different groups handling access, malware, infrastructure, extortion and money laundering instead of one hacker doing everything.

The ransomware market provides the clearest example. One operator can steal credentials, another can sell corporate access, another maintains ransomware, affiliates carry out the intrusion, and separate services provide hosting, proxies and laundering infrastructure.

Mandiant's access-handoff data shows how closely those roles can now work together. A process that took a median of more than eight hours a few years ago fell to 22 seconds during 2025.

Blockchain data gives us another glimpse of the supply chain. Chainalysis has found that jumps in payments to initial-access brokers tend to come roughly 30 days before increases in ransomware payments and public victim disclosures. Access itself has become an upstream commodity.

The market is also becoming less concentrated. IBM found the ten largest ransomware groups accounting for a smaller share of overall activity, while Chainalysis recorded record claimed attack levels despite weaker aggregate payment revenue.

That fragmentation makes criminal brands expendable. Shut down one group and experienced affiliates, infrastructure and stolen access can move elsewhere.

Are ordinary companies getting dragged into geopolitical cyber conflicts?

Geopolitical cyber risk is reaching more private companies because telecommunications, cloud services, energy networks, semiconductor supply chains and technology vendors have become useful targets in state competition.

ENISA's latest EU threat landscape found state-aligned groups intensifying espionage against European organizations. It also recorded hacktivism behind almost 80% of incidents, although most of that volume came from relatively low-impact DDoS attacks and only 2% of hacktivist incidents caused service disruption.

State operations aimed at long-term access are much more consequential. CrowdStrike saw a 266% increase in cloud-conscious intrusions by state-linked actors, showing how quickly government-backed groups are adapting to cloud-heavy corporate environments.

Mandiant found a similar shift in the mix of threat actors it investigated. Financially motivated groups fell from 55% of observed clusters in 2024 to 41% in 2025, while espionage-related clusters doubled from 8% to 16%.

Industrial infrastructure is another obvious target. Dragos has documented state-associated groups conducting detailed reconnaissance of control systems and developing the knowledge required to affect physical processes.

Exposure varies enormously by company. Businesses sitting inside strategic technology, telecom, energy or defense supply chains have much more reason to care than an ordinary local business.

Chart showing how identity verification platform technology has evolved over time

This chart, included in our cybersecurity market deck, shows how identity verification platform technology has evolved over time

So what are the biggest cybersecurity challenges right now?

The biggest cybersecurity challenges right now are exposed software, compromised identities and third-party access, with ransomware, attack speed and AI making those weaknesses more painful and harder to contain.

We rank vulnerability management first because several independent datasets have converged on the same problem. As seen above, exploitation now leads Verizon's broad breach dataset and has led Mandiant's incident-response data for six consecutive years. Public exploits can spread within days while organizations may still need weeks to remediate critical systems.

Identity comes immediately after it. Companies have spent years improving passwords and MFA, so attackers are increasingly manipulating sessions, tokens, OAuth permissions, recovery workflows and machine identities. Cloud-heavy businesses now need to treat an authenticated account as potentially hostile.

Third-party access is probably the hardest challenge to eliminate completely. A business can fix its own vulnerabilities and train its own employees, yet still inherit a breach through an integration, supplier or SaaS provider. Verizon's finding that third parties are present in almost half of breaches shows how mainstream that exposure has become.

Ransomware remains the clearest repeatable threat to business operations. More victims refusing to pay is a genuine defensive success, but attack volumes are still climbing and industrial incidents show how quickly a compromise can turn into downtime.

Speed also ranks near the top. Criminal access handoffs measured in seconds and breakout times measured in minutes make slow escalation procedures increasingly dangerous.

AI sits behind those immediate problems as the fastest-moving multiplier. Attackers are using it to scale familiar techniques while companies are simultaneously connecting AI agents to valuable internal systems. Most real compromises today, however, still begin with vulnerabilities, credentials, social engineering or trusted access.

Industrial and edge environments remain a serious blind spot because defenders often have less visibility and fewer practical patching options. Geopolitical operations add another layer for organizations sitting in strategic sectors and supply chains.

Post-quantum cryptography belongs on the long-term agenda rather than near the top of today's breach list. NIST has already finalized its first major post-quantum standards, so large organizations need to begin migration early, especially where encrypted data must remain confidential for many years.

After comparing these datasets, the clearest conclusion is that cybersecurity's hardest problem today comes from the amount of trust modern businesses have created across software, people, suppliers, cloud services and AI systems. Attackers only need one of those relationships to be exposed, overpowered or poorly monitored.

Rank Biggest cybersecurity challenge now Why it belongs near the top
1 Vulnerabilities and exposed software Exploitation is rising while attackers increasingly move within days of disclosure
2 Identity and trusted access Sessions, tokens, OAuth, MFA workflows and machine identities widen the problem beyond passwords
3 Third-party and supply-chain access Companies inherit permissions and vulnerabilities they cannot fully control
4 Ransomware and cybercrime ecosystems More victims resist payment, but attacks and criminal specialization remain high
5 Attack speed and weak visibility Attackers can move in seconds or minutes while legitimate tools help them blend in
6 AI-enabled attacks and AI-agent security AI scales existing attacks and creates new high-permission identities inside companies
7 Industrial and edge security Poor visibility, difficult patching and physical consequences make failures unusually costly
8 Geopolitical cyber operations Strategic companies can become targets because of where they sit in larger supply chains
9 Cybersecurity skills gaps Specialized cloud, AI, application and identity expertise is still unevenly available
10 Post-quantum migration The migration needs to start early, although quantum attacks are not a major breach driver today

If you want more recent data on this point, please see our latest cybersecurity market report.

OUR METHODOLOGY

The question of what the biggest cybersecurity challenges are right now does not have one obvious answer. “Biggest” can mean the most common way attackers get in, the threat causing the most disruption, the weakness spreading fastest, or the problem companies have the least control over, so we broke the question into separate dimensions before ranking them.

For each dimension, we prioritized the freshest and most direct evidence available: broad breach datasets, frontline incident-response investigations, threat telemetry and observed attack activity. We then used specialist research where it gave a sharper view of one part of the problem, such as blockchain analysis for ransomware economics, OT fieldwork for industrial security, developer scanning for secret exposure, workforce research for skills shortages and official standards work for post-quantum migration.

We assessed each challenge mainly through four lenses: how often it appears in real incidents, how much damage it can cause, how quickly the threat is changing, and how difficult the exposure is for organizations to control. Recent evidence carried more weight, especially when several independent sources were moving in the same direction.

Percentages from different reports were used inside the context of the populations they measure. We used them to identify convergence, changes over time and meaningful differences between datasets rather than combining unlike studies into a single synthetic number.

We also kept specialist evidence inside the area it describes best. Dragos carries more weight on operational technology, ENISA on the European threat landscape, GitGuardian on exposed secrets, and Chainalysis on ransomware payments and criminal-market flows. Broad breach and incident-response datasets carried more weight when judging challenges that cut across industries and regions.

The final ranking was formed only after those dimensions had been assessed separately. Challenges already appearing broadly in real breaches and creating immediate operational exposure received the greatest weight. Fast-moving issues such as AI were judged on their demonstrated role in attacks and enterprise security today, while longer-horizon issues were included when the preparation time makes action relevant already.

Key sources used for this analysis include Verizon's 2026 Data Breach Investigations Report, Mandiant / Google Cloud's M-Trends 2026, CrowdStrike's 2026 Global Threat Report, Google Cloud's Cloud Threat Horizons H1 2026, IBM X-Force's 2026 Threat Intelligence Index, ENISA's Threat Landscape, Dragos's 2026 OT Cybersecurity Year in Review, Chainalysis's 2026 ransomware analysis, GitGuardian's State of Secrets Sprawl 2026, ISC2's 2025 Cybersecurity Workforce Study, the World Economic Forum's Global Cybersecurity Outlook 2026, and Microsoft's Digital Defense Report 2025.

Additional case-level evidence came from Microsoft's passkey-themed social-engineering research, Google Threat Intelligence's ShinyHunters SaaS data-theft research, Google's Salesforce voice-phishing investigation, Google's BlackFile vishing research, Salesforce's response to the Salesloft Drift incident, and NIST's Post-Quantum Cryptography project.

Table scoring and prioritizing the main pain points faced by companies in the cybersecurity market

In our cybersecurity market deck, we identify pain points entrepreneurs should prioritize

Who is the author of this content?

NEW MARKET PITCH TEAM

We track new markets so founders and investors can move faster

We build living "market pitch" documents for emerging markets: AI, synthetic biology, new proteins, and more. Instead of outdated PDFs or hallucinated LLM answers, our clients get a clean, visual, always-updated view of what's really happening: key players, deals, regulations, and signals that matter. Learn more about us.

Back to blog