I Need IT Support Now
Managed IT Houston Cybersecurity
Shane

Unit 42 Global Incident Response Report 2026: What It Means for Houston Businesses

How Attackers Are Using Stolen Credentials and Why It’s Harder to Catch Them – The Breach Window Shrank 75% Last Year, Your Response Plan Didn’t

2026 Incident Response Report
More Than 90% of Breaches Came From Gaps You Could Have Closed. Unit 42 Investigated 750 of Them.

Palo Alto Networks' Unit 42 spent a year on 750+ real incidents. The attackers were not geniuses - they found soft spots first. Here is what that means for a Houston business running lean.

TL;DR
The Unit 42 Global Incident Response Report 2026 analyzed more than 750 major cyber incidents across 50-plus countries and found that over 90% of breaches traced back to preventable gaps - limited visibility, inconsistent controls, and too much trust in identity systems nobody had cleaned up. Attacks are faster (the quickest quarter reached data theft in 72 minutes, down from 285), identity is the front door (a factor in nearly 90% of cases), vendors and SaaS are a growing attack vector, and ransomware increasingly skips encryption to just steal and extort. For Houston SMBs, almost all of it is fixable with proactive managed IT.

The most important finding in the Unit 42 2026 report is not that attacks are getting worse - it is that more than nine in ten of them walked through a door the business left open.

Palo Alto Networks' Unit 42 team responded to more than 750 major cyber incidents across every major industry and more than 50 countries, and documented it all in its Global Incident Response Report 2026. The headline is not exotic zero-days or nation-state wizardry. In over 90% of breaches, preventable gaps made the intrusion possible - limited visibility, controls applied inconsistently, and identity systems carrying years of unearned trust. For Houston and Katy businesses running with lean IT or none at all, that is not just an inconvenience; the data says it is a direct liability. Here are the four trends that matter most and what to do about each.

The uncomfortable takeaway: the attackers did not need to be brilliant. They just needed your business to have a soft spot they could find before you did.
Chart of the dominant drivers of initial access in the Unit 42 Global Incident Response Report 2026
The dominant drivers of initial access. Source: Unit 42 Global Incident Response Report 2026.

How Is AI Changing the Speed of Attacks?

AI is not making attackers smarter - it is making them faster and more scalable.

The fastest quarter of attacks reached data exfiltration in 72 minutes in 2025, down from 285 minutes a year earlier - a 75% cut in the window you have to detect and respond.

That collapsing timeline is the whole point. Attackers now use AI to write convincing phishing, generate malware scripts, automate reconnaissance, and even run ransom negotiations with no human in the loop - the report documented an unsophisticated actor using an AI chatbot to script a professional extortion demand, deadlines and all. Scanning for newly disclosed vulnerabilities begins within 15 minutes of a CVE announcement, often before defenders have finished reading the advisory, and North Korean operators used AI-generated deepfakes to pass remote-hiring processes at U.S. companies for direct insider access.

UNIT 42 2026, BY THE NUMBERS 90%+ of breaches were preventable 72 min to data theft (was 285 min) 99% of cloud identities over-permissioned $500K median ransom paid (up from $267.5K) CinchOps · cinchops.com · Source: Unit 42 Global Incident Response Report 2026
Key numbers from the Unit 42 Global Incident Response Report 2026.
Chart of the attack surfaces involved in intrusions in the Unit 42 2026 report
Attack surfaces involved in intrusions. Source: Unit 42 Global Incident Response Report 2026.

Why Is Identity the Attacker's Front Door?

Attackers do not need to break in when they can simply log in.

Identity-based attacks were a factor in nearly 90% of Unit 42 investigations, with 65% of all initial access coming through phishing, stolen credentials, brute force, or misconfigured access.

Identity-based phishing alone tied software vulnerabilities for the top initial-access spot at 22%, and previously compromised credentials - old breach passwords sold on dark-web markets - accounted for another 13%. The deeper problem is identity sprawl. Unit 42 analyzed more than 680,000 cloud identities and found 99% had excessive permissions, many unused for 60 days or more. We see this constantly with Houston businesses that grew quickly or changed vendors without a proper access audit: service accounts never cleaned up, former-employee logins never deactivated, third-party integrations still holding admin access from a project that wrapped two years ago. MFA is the floor, not the ceiling - session-token theft and adversary-in-the-middle attacks bypass it, so identity needs governance, not just a second login step.

Chart of nation-state cyber activity in the Unit 42 2026 report
Nation-state cyber activity. Source: Unit 42 Global Incident Response Report 2026.

How Did Your Vendors Become an Attack Vector?

The apps and integrations connected to your systems carry access you forgot you granted.

SaaS data was involved in 23% of cases in 2025, up from just 6% in 2022, as third-party integrations and forgotten OAuth grants became a favored path in.

When you connect a third-party app through OAuth - the "log in with Google" style of permission - it keeps whatever access you first approved, often more than it needs and usually forgotten. Remote monitoring and management tools, the same kind managed IT providers use, showed up in 39% of the command-and-control techniques Unit 42 observed. One case saw attackers compromise a sales-tool integration and use valid OAuth tokens to reach customer data, with traffic that looked like normal automation. More than 60% of vulnerabilities in cloud applications live in transitive libraries - packages pulled in automatically by other packages your team never chose. For any Houston SMB using Microsoft 365, Salesforce, QuickBooks Online, or SaaS add-ons, dormant, over-permissioned connectors are sitting in your environment right now, and most businesses have no idea how many.

Do You Know What's Connected to Your Microsoft 365?

CinchOps inventories your SaaS integrations, removes dormant OAuth grants, and cleans up the over-permissioned identities the Unit 42 report says drive most breaches.

Talk to CinchOps
Chart of extortion tactics used by attackers in the Unit 42 2026 report
Extortion tactics. Source: Unit 42 Global Incident Response Report 2026.

How Has Ransomware Changed - and Why Is It Worse?

Encryption is down, but extortion and data theft are up - and they target your backups.

Only 78% of extortion cases involved encryption in 2025, down from consistently above 90%, because attackers learned they can just steal the data and threaten to publish it.

That decline is not good news. Data theft appeared in more than half of extortion cases and holds steady whether or not encryption happens. Median initial ransom demands rose from $1.25 million to $1.5 million, and median actual payments nearly doubled from $267,500 to $500,000. Most telling for recovery planning: in 26% of extortion cases, attackers targeted and impaired backups specifically to remove the victim's ability to recover without paying, and browser activity was involved in 48% of all investigations. The disruption goes well past the ransom - manufacturing, distribution, and order processing were shut down for extended periods across cases in the report, hitting revenue and customer relationships in ways that are hard to fully quantify.

Chart of ransomware demands and payments in the Unit 42 2026 report
Ransomware demands and payments, 2024 vs 2025. Source: Unit 42 Global Incident Response Report 2026.
100% Free

Know Your Business Security Score

Get a FREE comprehensive security assessment for your Houston area business. Understand vulnerabilities across your network, applications, DNS, and more.

Get Your Free Assessment

The single most useful line in this whole report is that 90% of these breaches were preventable. That is not a doom statistic - it is a to-do list. The businesses that get hurt are not unlucky; they are the ones nobody was auditing, patching, or watching. That part you can change.
Shane Stevens, CEO, CinchOps - LinkedIn

Closing the Preventable Gaps Unit 42 Documented

CinchOps closes exactly the gaps this report names - excessive permissions, unpatched systems, dormant integrations, and limited visibility - with identity audits, automated patching, and continuous monitoring for Houston-area businesses. It is part of our cybersecurity and managed IT services.

Explore CinchOps cybersecurity →

How CinchOps Helps Secure Your Business

CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area, focused on closing the preventable gaps behind 90% of breaches.

CinchOps specializes in cybersecurity, network security, managed IT support, VoIP, and SD-WAN for businesses with 10-200 employees. Almost everything the Unit 42 report describes is fixable with the right proactive partner:

  • Identity and access audits. We clean up excessive permissions, dormant accounts, and stale integrations that create lateral-movement paths.
  • MFA hardening. We go past basic MFA to phishing-resistant methods and conditional-access policies that weigh session risk.
  • Patch management. With attackers scanning within 15 minutes of a CVE, automated patching of internet-facing systems is a core function, not an afterthought.
  • Monitoring and resilient backups. Continuous visibility across endpoints, cloud, and identity, plus isolated, tested backups built to survive the attacks that target recovery.

The gap between a detected threat and a contained breach is now measured in minutes, not days. If you run a business in Houston, Katy, or Sugar Land and are not sure where your exposures are, talk to CinchOps for an honest assessment before an attacker finds them first.

Frequently Asked Questions

What is the Unit 42 Global Incident Response Report 2026?

It is an annual report from Palo Alto Networks' Unit 42 team based on responding to real cyber incidents. The 2026 edition analyzed more than 750 major incidents across over 50 countries and found that more than 90% of breaches came from preventable gaps rather than sophisticated attacks.

How fast do cyberattacks move in 2026?

The fastest quarter of attacks reached full data exfiltration in just 72 minutes, down from 285 minutes the prior year - a 75% reduction. For a Houston SMB without active monitoring, that window is effectively zero, which is why proactive detection matters so much.

What is the most common way attackers get into a small business?

Identity-based attacks were a factor in nearly 90% of Unit 42 investigations, and 65% of initial access was identity-driven. Phishing and software vulnerabilities each accounted for 22%. In most cases attackers logged in with credentials that were not properly protected rather than breaking in.

Does multi-factor authentication stop these attacks?

MFA is necessary but not complete. The report documented session-token theft and adversary-in-the-middle techniques that bypass standard MFA. Closing the gap requires phishing-resistant authentication plus regular identity and access audits to remove excessive permissions and dormant accounts.

Why do attackers target backups during ransomware?

A business with working backups has less reason to pay. Unit 42 found attackers impaired backups in 26% of extortion cases, specifically to remove recovery options before the victim realized an attack was underway. Isolated, tested backups are what keep you from having to pay.

Discover More

Sources

Take Your IT to the Next Level!

Book A Consultation for a Free Managed IT Quote

281-269-6506