I Need IT Support Now
Managed Service Provider Houston Cybersecurity
Shane

Comcast 2025 Cybersecurity Threat Report: What Houston Businesses Need to Know

From Reconnaissance To Ransomware: Understanding The Four Stages Of Modern Cyber Attacks – How Attackers Use AI, Proxies, And Valid Accounts To Breach Houston Companies

Cybersecurity
The Comcast 2025 Cybersecurity Threat Report Counted 34.6 Billion Attacks. Here Is the Houston SMB Checklist It Should Trigger.

The report's headline numbers are enormous, but the defense they point to is short and specific. This turns the findings into the exact controls a Houston small business should confirm are in place.

TL;DR
The Comcast 2025 Cybersecurity Threat Report tracked 34.6 billion threat events over a year, led by phishing, drive-by compromise, and attacker infrastructure buildup. For a Houston SMB, the takeaway is not the number but the response: a short checklist of controls that closes the exact gaps those attacks depend on.

The Comcast 2025 Cybersecurity Threat Report analyzed 34.6 billion threat events across a year of network traffic and turned them into a picture of how businesses actually get hit - and the defense it points to is a short list of controls, not a bigger budget.

Comcast Business detected those 34.6 billion events between June 1, 2024 and May 31, 2025, the third year it has published this analysis. The biggest categories were 19.5 billion resource development events (attackers building infrastructure before they strike), 9.7 billion drive-by compromise attempts, and 4.7 billion phishing attempts, plus roughly 44,000 distributed denial-of-service attacks. Houston runs on the exact companies these automated campaigns scan for: law offices, CPA practices, construction firms, and clinics with 10 to 200 employees and no dedicated security team. This guide pulls the report's findings into a checklist a Houston SMB can actually work through.

The trap in a number this big: 34.6 billion feels like someone else's problem. It is not. Almost none of that volume is aimed at a specific business - it is automation spraying every reachable target, which means a small Houston company is inside the number, not outside it.

What Did the Comcast 2025 Cybersecurity Threat Report Actually Find?

A year of traffic, sorted into the attack types that reach real businesses - phishing, drive-by compromise, infrastructure buildup, and DDoS.

The Comcast 2025 Cybersecurity Threat Report found 34.6 billion threat events in a single year, dominated by automated, opportunistic attacks - phishing, drive-by web compromise, and attacker infrastructure development - rather than hand-crafted attacks against named targets.

The scale is the headline, but the shape is the useful part. When 19.5 billion of the events are attackers building and testing infrastructure, and another 9.7 billion are drive-by attempts that infect a machine just for loading a bad web page, you are looking at a machine that runs whether or not it knows your company exists. The report also flags a shift in technique that matters more than the raw counts: attackers increasingly use "living off the land," meaning they operate with legitimate accounts and built-in tools instead of malware, which is exactly what slips past a business relying only on antivirus.

  • Phishing is still the front door. 4.7 billion phishing attempts in the report period confirm email remains the number-one way credentials get stolen and malware gets delivered.
  • Drive-by attacks need no click. 9.7 billion drive-by compromise attempts mean an unpatched browser can be enough to get infected from a web page alone.
  • Attackers prepare at scale. 19.5 billion resource development events show reconnaissance and infrastructure buildup happening long before any single business is touched.
Key findings from the 2025 Comcast Business Cybersecurity Threat Report showing threat event counts by category
The report's top threat categories by event volume over the year analyzed. Source: 2025 Comcast Business Cybersecurity Threat Report.

What Should a Houston SMB Actually Do About the Report's Findings?

Each item below maps a finding in the report to a control that closes it. Work down the list and confirm each one is on, not just owned.

The right response to the Comcast 2025 report is a defense checklist that mirrors the attack data: block phishing and credential theft, close the gaps drive-by and scanning attacks hunt for, watch for legitimate-tool abuse, and keep a recovery path when something gets through.

  • Turn on multi-factor authentication everywhere. The 4.7 billion phishing attempts exist to steal passwords. MFA on every account that touches business or client data blocks the stolen-password takeover even after a credential leaks.
  • Patch browsers, operating systems, and applications on a schedule. Drive-by compromise and the scanning behind resource development both hunt for unpatched software. A patch cadence closes the flaws before the automation finds them.
  • Filter email before it reaches the inbox. Phishing is the report's leading credential-theft channel, so a filtering layer that catches malicious messages upstream removes most of the risk before a person has to make a judgment call.
  • Run endpoint detection and response, not just antivirus. The report's "living off the land" trend defeats signature-based tools. EDR watches behavior, so a legitimate account or tool doing something abnormal still raises a flag.
  • Keep tested, offline-capable backups. Follow the 3-2-1 rule - three copies, two media types, one offsite - and prove them by restoring. Backups are what turn a ransomware endgame from a shutdown into a bad afternoon.
  • Watch for identity and account abuse. Because attackers increasingly use valid accounts, monitoring for unusual logins, new mail rules, and privilege changes catches intrusions that never trip a malware alarm.
  • Have DDoS and continuity plans ready. The report counted roughly 44,000 DDoS attacks using short bursts and carpet-bombing. Know who mitigates an attack and how the business keeps running while it is happening.
FROM REPORT FINDING TO SMB CONTROL What each Comcast 2025 finding tells a Houston SMB to do THE FINDING THE CONTROL TO CONFIRM 4.7B phishing attempts Email is the top credential-theft channel MFA + email filtering Blocks stolen-password takeover 9.7B drive-by attempts Infection from a bad web page, no click Patching on a schedule Closes the flaws before scans find them Living off the land Valid accounts, no malware to detect EDR + identity monitoring Flags behavior, not just signatures Ransomware endgame Encryption in minutes once inside Tested 3-2-1 backups Recovery instead of ransom ~44,000 DDoS attacks Short bursts and carpet-bombing DDoS + continuity plan Know who mitigates and how you stay up CinchOps · cinchops.com
Each major finding in the Comcast 2025 report mapped to the control a Houston SMB should confirm is in place.
The four stages of a modern cyber intrusion from the 2025 Comcast Business Cybersecurity Threat Report
How a modern intrusion unfolds across four stages, from probing defenses to the endgame. Source: 2025 Comcast Business Cybersecurity Threat Report.
Chart showing the rising number of Common Vulnerabilities and Exposures over time from the 2025 Comcast Business Cybersecurity Threat Report
The growing count of published vulnerabilities that patching has to keep pace with. Source: 2025 Comcast Business Cybersecurity Threat Report.

Why Does the Report Put People at the Center of the Answer?

Comcast frames 2025 around "The Human Equation" - staff are both the most-attacked surface and the strongest control, if they are trained and not buried in alerts.

The Comcast 2025 report's "Human Equation" is the finding that people sit on both sides of security: employees clicking phishing links create the openings, while trained staff and adequately-supported analysts are what catch attacks that tools miss.

The report ties this to a staffing reality small businesses feel hardest. Comcast cites a global cybersecurity workforce gap around 4.76 million professionals, with about two-thirds of organizations reporting shortages that raise their risk. A Houston law firm or CPA practice with no security hire at all is the extreme version of that gap. That is the honest case for a managed partner: you are not hiring an analyst, you are renting a trained team and the tooling that keeps them from drowning in noise. Awareness training is the cheapest item on the whole checklist and it directly counters the phishing that leads the report.

Recommended defensive actions from the 2025 Comcast Business Cybersecurity Threat Report
The report's own recommended actions for building a layered, people-aware defense. Source: 2025 Comcast Business Cybersecurity Threat Report.

Turn the Report Into a Working Defense

CinchOps runs the full checklist for Houston-area SMBs - MFA, patching, email filtering, EDR with identity monitoring, tested backups, and DDoS protection - configured and watched around the clock, so the controls the report points to are actually on. It is part of our cybersecurity and managed IT services.

Explore CinchOps cybersecurity →
A report counting 34.6 billion attacks can freeze an owner into thinking the problem is too big to touch. It is the opposite. Almost all of that volume is automation, and automation loses to the boring controls - MFA on, patches current, backups tested. Get those on and you drop out of the easy-target pool the whole number is built from.
Shane Stevens, CEO, CinchOps - LinkedIn

How CinchOps Helps Houston SMBs Act on the Report

CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area.

CinchOps specializes in cybersecurity, network security, managed IT support, VoIP, and SD-WAN for businesses with 10-200 employees. For a Houston SMB reading the Comcast 2025 report, that means the checklist above set up and kept running for you:

  • Identity and email defense. MFA enforced on every account, phishing filtered before it lands, and mailbox rules watched for the account-abuse the report highlights.
  • Patching and endpoint protection. Updates on a schedule and EDR on every device, so drive-by attacks and living-off-the-land activity get caught.
  • Backup and recovery. 3-2-1 backups that are actually test-restored, turning a ransomware endgame into a recovery instead of a payout.
  • Continuity and DDoS readiness. A plan for staying operational when an attack or outage hits, not a scramble after it starts.

We serve businesses across the Houston area, including Houston, Katy, and Sugar Land, and we know what a law firm, CPA practice, or construction firm needs covered. A 34.6 billion number is not a reason to panic - it is a reason to check a short list. If you want a second set of eyes on which items you are actually missing, talk to CinchOps for a free assessment.

100% Free

Know Your Business Security Score

Get a FREE comprehensive security assessment for your Houston area business. Understand vulnerabilities across your network, applications, DNS, and more.

Get Your Free Assessment

Frequently Asked Questions

What is the Comcast 2025 Cybersecurity Threat Report?

It is Comcast Business's third annual analysis of cybersecurity threats, drawn from 34.6 billion threat events detected across its network between June 1, 2024 and May 31, 2025. It breaks attacks into categories such as phishing, drive-by compromise, and DDoS, and frames defense around both technology and people.

How many threats did the Comcast 2025 report count?

34.6 billion threat events in one year. The largest categories were 19.5 billion resource development events, 9.7 billion drive-by compromise attempts, and 4.7 billion phishing attempts, plus roughly 44,000 DDoS attacks. Most of this volume is automated, so it reaches small Houston businesses regardless of size.

Do the report's findings apply to a small Houston business?

Yes, and arguably more so. The dominant attacks are automated and opportunistic, scanning every reachable target rather than picking large companies. A Houston SMB with thin defenses is exactly the easy target that automation is built to find, which is why the checklist matters at any size.

What is "living off the land" in the Comcast report?

It means attackers operate using legitimate accounts and built-in system tools instead of malware, so their activity blends in with normal IT work. Signature-based antivirus misses it. Catching it takes endpoint detection and response plus monitoring for unusual account and login behavior.

Which control should a Houston SMB put in place first?

Multi-factor authentication. The report's 4.7 billion phishing attempts exist to steal passwords, and MFA blocks the account takeover even after a password leaks. It is usually included in the Microsoft 365 or Google Workspace plan you already pay for, so it is the fastest high-impact item on the checklist.

Discover More

Sources

Shane Stevens, founder and CEO of CinchOps
About the Author

Shane Stevens

Shane Stevens is the founder and CEO of CinchOps, a managed IT and cybersecurity provider for small and mid-sized businesses across the Greater Houston area, including Katy. He brings more than 35 years of IT experience, including director, VP, and CTO roles at Tidal Software, Cisco, ABB, Delinea, Digital.ai, and NinjaOne, to keeping local businesses secure, efficient, and productive.

Take Your IT to the Next Level!

Book A Consultation for a Free Managed IT Quote

281-269-6506