Twenty-five security reports published in 2025 and 2026 agree on more than you would expect. This paper reads them together, weighs them with skepticism, and names eight areas of control that reduce the length and cost of a breach more than anything else you might fund this year. The full analysis, "Signal Over Noise," is available as a free PDF download below.
The source set spans incident response caseloads, insurance claims, product telemetry, board-governance research, and practitioner surveys. Each source gets ranked into one of three tiers by evidence quality. Incident and claims data from Verizon, Mandiant, IBM, Sophos, Coalition, NetDiligence, the FBI, and ReliaQuest carries the most weight. Product telemetry from CrowdStrike, Red Canary, Microsoft, Varonis, and others fills in volume. Survey and governance data from the World Economic Forum, NACD, SecurityScorecard, and similar sources explains why boards still under-invest despite the evidence.
Attackers Use Two Doors
Stolen identities open one door, and exposed internet-facing systems open the other. Sophos attributes roughly two-thirds of 2025 incident root causes to identity compromise. Verizon, Mandiant, and IBM each rank exploitation of edge and public-facing systems first among initial access vectors in the same period. No third door comes close in any dataset in this paper.
Losses concentrate in mundane events, not headline ransomware. Business email compromise and funds transfer fraud produced 58 percent of Coalition insurance claims in 2025. Speed has compressed decision windows below human reaction time, and defenders still take a median of 14 days to notice an intrusion already underway. Confidence is not evidence. Most leaders express confidence in their recovery plan, although few have tested it.
No single control substitutes for another. A company with strong identity controls and no recoverable backups still faces a shutdown. The Common Sense Security Framework (CSSF) v2.0 scores this directly. A failed load-bearing control caps reported readiness at 60 percent, no matter what else scores well.
Eight Areas, Ranked by Evidence
CSSF v2.0 organizes 38 controls into eight areas. Ten of those 38 controls are load-bearing, carrying the framework's top weight, and they sit unevenly across the eight areas rather than one per area. Each section below closes with the question to put in front of your security leader, your IT provider, or your managed security partner. A no, or an honest "I do not know," is the signal to act.
1. Govern your risk
Every control in this paper scores against a baseline, and the baseline comes from an asset inventory most companies do not maintain. A coverage percentage against an unknown asset count is a guess dressed as a metric. The World Economic Forum finds CEOs and CISOs rank different threats first: CEOs name fraud, CISOs name ransomware and supply chain. Divergence at the top means no one owns the full risk in terms every executive understands.
NACD's board research puts a number on the governance gap. Only 34 percent of public company directors call it very or extremely important to improve their own cybersecurity expertise, and 40 percent say the same about clarifying which board committee owns cyber oversight. Private company directors report a wider gap, at 45 percent and 49 percent respectively.
2. Protect your identities
Attackers log in more often than they break in. Sophos attributes 67 percent of 2025 incident root causes to identity-related tactics. Session hijacking through adversary-in-the-middle phishing kits bypassed MFA in every successful business email compromise incident Mandiant's analysts investigated in 2024, not most, all. Phishing-resistant authentication answers this directly. Microsoft reports it blocks over 99 percent of unauthorized access attempts.
Cutting standing privilege matters just as much. Verizon's attack-graph data shows that in 16 percent of organizations, an attacker starting from a low-privilege foothold had an 80 percent or better chance of reaching a key administrative account. Sophos measures attackers reaching Active Directory a median of 3.4 hours after initial access.
3. Protect your devices
Coverage, not deployment, is the number that matters. A tool installed on most of the fleet still leaves the uncovered fraction open, and attackers land there. The strongest control finding in the evidence set concerns configuration, not detection: Marsh McLennan's 2025 analysis ranks network hardening first among twelve tracked control categories, correlating with roughly 15 percent fewer breach claims.
Verizon's assessment data on workstation configuration found 97 percent of assessed devices failed the check for limiting failed login attempts before lockout, and 90 percent failed the check requiring 15-character passwords.
4. Protect your networks
Four independent incident datasets now agree the perimeter is where most intrusions start. Verizon places exploitation of vulnerabilities at 31 percent of initial access, up 55 percent year over year. Mandiant ranks exploits first for the sixth consecutive year. IBM recorded a 44 percent rise in exploitation of public-facing applications. Patching every edge device is not achievable, and the data proves the point. Verizon found organizations fully remediated only 26 percent of known-exploited vulnerabilities in 2025, with a median remediation time of 43 days.
Reconnaissance is fast. GreyNoise puts the window between a vulnerability disclosure and active scanning at hours. Compromise waits for a forgotten device. Sophos measures a 322-day median gap between patch release and confirmed exploitation.
5. Protect your data
Offline or immutable backups covering data, systems, identity services, and virtualization management carry the highest weight in CSSF v2.0. Mandiant documents ransomware crews deliberately destroying backup infrastructure before making any demand, which converts a recoverable outage into an existential one.
The most probable loss in your business is financial, not technical. Coalition's 2025 claims data puts business email compromise and funds transfer fraud together at 58 percent of claims. The callback number used to verify a payment request must come from a source independent of the request itself, because a callback fails against a cloned voice if the attacker supplied the number being called.
6. Protect your people
Attackers moved to the phone, the help desk, and now the video interview. Mandiant recorded email phishing falling from 22 percent of initial infection vectors in 2022 to 6 percent in 2025, while voice phishing rose to second place at 11 percent. Simple phishing volume is dropping while sophisticated, evasion-built phishing gains ground.
Rehearsal is the control that speed demands. Marsh McLennan ranks incident response planning fifth among twelve tracked control categories. NACD's board guidance places the same discipline in the boardroom: leading boards participate directly in tabletop and crisis simulations rather than reviewing results after the fact.
7. Protect your partnerships
Third parties multiply exposure faster than most vendor programs can track it. Verizon found third-party involvement in 48 percent of confirmed breaches, up 60 percent year over year. SecurityScorecard reports 78 percent of organizations cover less than half their vendor ecosystem with internal oversight, while 90 percent of leaders remain confident operations would continue seamlessly through a critical vendor incident. That gap between confidence and coverage is the finding, not a reassurance.
8. Protect your uptime
Speed and detection move in opposite directions, and together they compound into the same failure. CrowdStrike reports an average eCrime breakout of 29 minutes in 2025. Mandiant's global median dwell time before detection sits at 14 days. Attackers finish lateral movement in well under an hour, and the median defender takes two weeks to notice.
Confidence and outcome point in opposite directions here too. Veeam finds 90 percent of security leaders confident they will recover within their objectives, yet only 28 percent of organizations hit by ransomware fully recovered their data without paying.
The Eight Questions to Ask This Quarter
Run these eight questions past your security leader, your IT provider, or your managed security partner. A no, or an honest "I do not know," is not a failure. It is the prioritized to-do list this analysis exists to produce.
Score your program with these eight questions
One question per area of the Common Sense Security Framework v2.0.
Govern Your Risk Who owns cyber risk, and when did they last report to the board?
Protect Your Identities What share of admin and remote accounts use phishing-resistant sign-in?
Protect Your Devices What percent of known-exploited vulnerabilities did we fully remediate last quarter?
Protect Your Networks When did we last scan our external footprint rather than rely on memory?
Protect Your Data When did we last restore from an offline copy, and does our payment callback use an independently sourced number?
Protect Your People When did executives last exercise the incident response plan together?
Protect Your Partnerships Which vendor is a single point of failure with no tested fallback?
Protect Your Uptime When did we last prove our recovery time objective by full-scope test?
Where the Numbers Disagree
Not every report in this set agrees, and the disagreements teach as much as the consensus does. Sophos ranks identity compromise as the root cause of two-thirds of incidents. Verizon, Mandiant, and IBM all rank exploitation of internet-facing systems first. The conflict is largely definitional: Sophos measures root cause, while the others measure the first observed access step. Fund identity and the edge together, and stop arbitrating the ranking.
The sharpest disagreement in the evidence set sits between two Tier 1 sources on a single metric. Mandiant reports a global median dwell time of 14 days. Sophos reports a median of three days. Neither number describes your business on its own. The populations behind each report explain the gap, and the useful question is what your own detection time looks like on the intrusion types you actually face.
Coalition's 2025 all-cause claims frequency among policyholders. Ransomware alone ran at 0.32 percent.
Coalition's 2025 average claims severity across all policyholders, down 19 percent year over year.
Median ransom demands tell a different part of the story than average claims severity does. Sophos reports a median ransom payment of 1 million dollars in 2025. Coalition's average claims severity for ransomware runs at 262,000 dollars. Verizon reports a median ransom paid of 139,875 dollars. All three are correct, and the seven-fold spread between Verizon and Sophos on one definition is the clearest evidence in this paper that no single ransom figure should anchor a budget.
Right-Sizing the Program
Spending more does not equal reducing more risk, but the fix is not simply spending less. Coalition's 2026 report names what it calls the cyber protection paradox: security spending projections rose 24 percent in two years while incident likelihood roughly doubled over five, and tool sprawl itself now generates alert fatigue and visibility gaps.
Sophos points to the same root cause from the operator side. Victims most often cite lack of expertise, unknown gaps, and lack of capacity, each near 40 percent, ahead of any missing product. The corrective move is not fewer tools. It is redirecting the budget those redundant tools consume toward the visibility infrastructure that makes existing tools worth having: longer log retention, expanded storage, and the analyst hours to review what the logs show.
Independent validation exists from three directions with no commercial stake in each other. Insurance carriers weight the same controls in underwriting. The FBI's Operation Winter SHIELD named a similar list of ten voluntary defenses in January 2026, and every one maps to a CSSF v2.0 control. NACD's board guidance tells directors to track the same resilience metrics this paper derives from claims and incident data.
How Aetos One Helps
Getting a score is the milestone. Expert operational coverage is the mandate. A scored gap does not close itself, and most mid-market teams do not have the headcount to close it alone.
Named fractional CISO. Owns the governance and identity work behind the first two areas above, with authority to report findings straight to your board.
AI-driven security operations, with named analyst coverage watching your devices, network edge, and uptime around the clock.
Continuous compliance automation, keeping evidence of your data protection, people readiness, and vendor oversight audit-ready.
Ask us how Guardian, Bastion, and Citadel provide named security leadership and expert operational coverage matched to the areas this paper flags, so next quarter's review is a progress update, not a fire drill. Schedule a 30-minute conversation.
Download the Full White Paper
The complete analysis runs 32 pages, with the full evidence table, source quality reference, and the CSSF v2.0 mapping behind every weight in this summary.
White Paper
Signal Over Noise: What Twenty-Five Leading Security Reports Agree On
The full cross-report analysis, including the eight areas at a glance, the source quality reference for all 25 reports, and the complete CSSF v2.0 mapping.
Download the PDF →