TL;DR: The 2026 Verizon DBIR covers more than 22,000 confirmed breaches across 145 countries and shows a faster, more automated threat landscape where ransomware, third-party exposure, vulnerability exploitation, and Shadow AI all converge on sensitive data, according to Sentra. The lesson is that data context now determines whether security teams can prioritise, contain, and limit real breach impact.
At a glance
What this is: The 2026 DBIR says breaches are increasingly driven by data exposure across ransomware, third parties, vulnerabilities, and Shadow AI.
Why it matters: For IAM, NHI, and broader security teams, the report shows that access scope and data visibility are now inseparable from breach prevention and response.
By the numbers:
- The 2026 Verizon DBIR analyzed more than 22,000 confirmed data breaches across 145 countries.
- Ransomware now accounts for 48% of all breaches, up from 44% the previous year.
- 60% year over year and now account for, r over year and now account for 48% of total breaches.
- The human element was present in 62% of breaches, showing that social engineering still remains a core access path.
👉 Read Sentra's analysis of the 2026 DBIR data security findings
Context
The core governance problem in the 2026 DBIR is not that attackers discovered entirely new tactics, but that familiar tactics are now landing faster and reaching data more easily. When ransomware, third-party access, vulnerability exploitation, social engineering, and Shadow AI all converge on the same sensitive records, security teams need continuous visibility into who or what can reach data, not just whether a control exists.
For identity programmes, the report reinforces a familiar but often under-enforced point: access scope is a data security issue. Service accounts, third-party connections, overpermissioned users, and AI tools that touch corporate data can all widen the breach blast radius even when perimeter controls look sound. That makes data context and identity governance part of the same operating model.
Key questions
A: Start with what each finding can actually reach. A high-severity vulnerability that touches empty or low-value data is a different business risk from a medium-severity issue exposing regulated records. Use data classification, entitlement scope, and identity context together so remediation is driven by blast radius, not by infrastructure severity alone.
A: Because access usually outlives the project that justified it. If vendors, partners, or SaaS integrations keep permissions after the original need ends, their identities become durable entry points. Continuous review, offboarding, and MFA enforcement matter more than one-time due diligence.
Q: What do organisations get wrong about shadow AI governance?
A: They often try to block unsanctioned tools at the network layer without changing employee behaviour or providing an approved alternative. That pushes use to personal devices and leaves the enterprise blind. Discovery and policy-guided redirection are more useful than simple denial if the goal is control rather than displacement.
Q: What should teams do immediately after discovering ransomware access?
A: Contain the identity path before focusing on payload cleanup. Disable exposed credentials, revoke active sessions, isolate privileged accounts, and protect backup and security-tool access so the attacker cannot continue moving or block recovery. The urgent goal is to stop further use of legitimate access.
Technical breakdown
Why data context changes breach prioritisation
A vulnerability, shared account, or third-party connection only becomes a material risk when it can reach sensitive data. Data context answers the question infrastructure tooling cannot: what is exposed if this control fails? That is why data security posture management is increasingly paired with cloud and vulnerability tooling. It lets teams distinguish between a misconfigured resource that contains regulated records and one that contains no material data. In breach programs, this shifts remediation from abstract severity scoring to business-impact scoring grounded in reachable data.
Practical implication: attach data classification to exposure findings so remediation priority reflects actual breach impact.
How third-party access expands the attack surface
Third-party risk is no longer limited to questionnaire status or audit reports. Once a vendor, partner, or SaaS integration can access data, the real question becomes whether that access is correctly scoped, continuously monitored, and promptly removed when it is no longer needed. In practice, many organisations still manage third-party identity as a one-time onboarding event instead of a lifecycle. That creates a persistent exposure window, especially where shared credentials, weak MFA, or permission drift remain unresolved for months.
Practical implication: treat third-party accounts and integrations as governed identities with lifecycle controls, not static vendor records.
Shadow AI and machine identity governance
Shadow AI is an identity and data problem, not only a usage-policy issue. Employees often use non-corporate AI accounts from corporate devices because the tools are convenient and the data is already available to them. That means corporate data can flow into unmanaged systems through legitimate user access paths. The same logic applies to machine identities and service accounts that feed AI pipelines. If those identities are over-permissioned, the AI system inherits access it should never have had.
Practical implication: classify and restrict the data reachable by AI-facing identities before focusing on blocking endpoints.
Threat narrative
Attacker objective: The attacker wants access to sensitive data that can be stolen, monetised, or used to maximise extortion leverage.
- Entry typically begins through vulnerability exploitation, third-party compromise, social engineering, or unauthorized AI usage that grants access to sensitive systems.
- Escalation occurs when the attacker moves from initial foothold to reachable data through overpermissioned accounts, exposed credentials, or misconfigured access paths.
- Impact follows when the attacker exfiltrates sensitive data, encrypts systems for extortion, or abuses the retrieved data for follow-on fraud and persistence.
NHI Mgmt Group analysis
Data context has become the decisive control plane for breach response. The 2026 DBIR shows that the same breach patterns keep recurring, but the organisations that recover fastest are those that know what data is reachable before an incident occurs. Infrastructure controls alone cannot answer that question. Security teams should treat data reachability as a first-class governance signal, not a post-breach forensic afterthought.
Third-party access is now a lifecycle problem, not a procurement problem. The report's third-party breach increase reflects the fact that access persists long after contracts are signed. Missing MFA, permission misconfigurations, and slow remediation turn vendors into durable exposure points. Practitioners should stop treating vendor onboarding as the end of security review and start managing third-party identities through continuous entitlement and offboarding controls.
Shadow AI exposes a governance gap between user intent and data permissioning. Employees adopt AI tools because their work already depends on the data those tools can process. That means data governance must follow the identity path, not just the application list. For identity and AI security teams, this is a clear signal that AI-facing identities, whether human or machine, need enforced data boundaries and monitored usage.
Blast-radius reduction is now the practical measure of security maturity. The report makes clear that organisations cannot prevent every initial access event, especially with vulnerability exploitation and social engineering rising. What separates resilient programmes is how quickly they can contain access, limit reachable data, and reduce the value of any compromised identity. That is a governance model aligned to reality, not optimism.
What this signals
Data Security Posture Management now needs identity-aware inputs. When a breach path runs through third-party access, overpermissioned users, or AI-facing identities, the programme cannot rely on asset inventory alone. Teams should combine data classification with entitlement mapping and anchor the workflow in NIST SP 800-53 Rev 5 Security and Privacy Controls and Ultimate Guide to NHIs , Key Challenges and Risks so exposure is measured by reach, not assumption.
Third-party identity governance is becoming a continuous assurance problem. The report's breach patterns suggest that periodic attestation is too slow for modern partner ecosystems. Practitioners should expect more pressure to prove MFA coverage, entitlement hygiene, and offboarding discipline across external identities, especially where data access is involved.
Shadow AI will keep expanding until data controls move closer to the identity layer. Blocking approved domains is not enough when corporate users can move data into consumer accounts or unmanaged services from trusted devices. Programme owners should prepare for more explicit monitoring of data flows, service-account access, and policy enforcement across AI channels.
For practitioners
- Build data-reachability maps for critical systems Map which identities, service accounts, partners, and AI tools can reach regulated or sensitive datasets, then update those maps continuously as permissions change.
- Rework third-party access reviews around actual entitlement scope Check whether vendors and integrations still need the data they can reach, whether MFA is enforced, and whether dormant access has been removed after project completion.
- Add identity review to ransomware containment playbooks When ransomware is detected, immediately assess which accounts, tokens, and service identities were used before encryption so you can limit lateral movement and data exfiltration.
- Govern Shadow AI through data classification and access boundaries Identify which corporate datasets are reachable by approved and unapproved AI services, then apply classification-based controls to reduce accidental or unmanaged disclosure.
Key takeaways
- The 2026 DBIR shows that breaches now converge on reachable data, not just compromised infrastructure.
- Ransomware, third parties, vulnerabilities, and Shadow AI all become more dangerous when identity scope is wider than data scope.
- Teams that can map who or what can access sensitive data will be better placed to prioritise, contain, and reduce breach impact.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-4 | Access control and least privilege are central to limiting breach reachability. |
| NIST SP 800-53 Rev 5 | AC-6 | Least privilege directly addresses overpermissioned access and data reachability. |
| CIS Controls v8 | CIS-5 , Account Management | Account lifecycle control is relevant to third-party and Shadow AI access paths. |
| MITRE ATT&CK | TA0006 , Credential Access; TA0008 , Lateral Movement; TA0010 , Exfiltration | The report's breach patterns follow access abuse, movement, and data theft. |
Map observed breach paths to ATT&CK tactics to improve detection and containment priorities.
Key terms
- Dependency Reachability: Dependency reachability is the question of whether a vulnerable library or function can actually be invoked in the deployed application path. It matters because not every disclosed package flaw creates equal risk. Teams use it to separate theoretical exposure from issues that can be exploited in practice.
- Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
- Third-Party Identity: An identity issued to a partner, vendor, contractor, or external service that can access internal systems. These identities often sit outside normal employee governance and can become persistent trust paths if they are not reviewed, expired, and revoked on schedule.
- Blast Radius: The potential scope of damage if a specific credential or identity is compromised. Identities with broad permissions have a larger blast radius and represent a higher priority for least-privilege enforcement and security controls.
What's in the full report
Sentra's full research covers the operational detail this post intentionally leaves for the source:
- Year-over-year DBIR comparison tables and the exact breach-pattern breakdown behind the headline figures
- Sentra's data-security framing for ransomware, third-party exposure, and Shadow AI
- Practical DSPM-oriented guidance for prioritising exposed data and reachable identities
- Source examples and context that support board-level investment conversations
Deepen your knowledge
The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It helps practitioners build the governance habits needed to control exposure across modern identity programmes.
Published by the NHIMG editorial team on August 19, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org