Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security What breaks when organisations assume falling crypto crime…
Cyber Security

What breaks when organisations assume falling crypto crime means the threat has meaningfully eased?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 20, 2026 Domain: Cyber Security

That assumption can blunt preparedness. The report shows scam revenue fell sharply, but ransomware rose and impersonation scams remained comparatively resilient. If teams generalise from the average, they may underinvest in incident response, backup resilience, and user awareness for the attack types that are still active. Security planning should follow the specific threat mix, not the headline trend.

Why the headline trend can be misleading

The key failure is treating an aggregate decline as proof that the whole threat environment improved. Crypto crime is not a single risk bucket, so a drop in one category can hide persistence or growth in others, especially where attackers have shifted to different monetisation paths, pressure tactics, or victim profiles.

That matters operationally because trend-based decisions often drive budget and attention. If leaders infer that the environment is broadly safer, they may slow incident response tuning, defer recovery testing, and soften awareness work just when certain attack types are still producing harm.

One useful data point from NHI Mgmt Group's Ultimate Guide to NHIs is that 80% of identity breaches involved compromised non-human identities such as service accounts and API keys, a reminder that apparently separate threat trends can still converge on the same access paths and compromise mechanics.

What breaks in planning and resilience

What usually breaks first is prioritisation. Teams over-correct toward the headline signal and underweight the attack types that remain active, which can leave response playbooks, backups, and user training misaligned with the current mix of abuse. The result is not just weaker defence, but slower detection and slower recovery when a less visible threat lands.

Ransomware is a good example of why the average can mislead. Even if one class of scam revenue falls, extortion-driven operations can remain dangerous because the real operational problem is interruption, data loss, and recovery cost, not just the immediate financial flow that appears in a trend chart.

  • Incident response should be tested against the attacks still generating loss, not the ones declining fastest.
  • Backup and restore readiness should be validated for extortion scenarios, because recovery time is often the real control failure.
  • User awareness should track current lure patterns, not last quarter's highest-volume scam type.

External guidance that tracks current threat activity, such as CISA cyber threat advisories, is more useful here than relying on a single aggregate crime trend.

Risk and Threat Considerations

The main risk is false reassurance. When organisations infer that falling crypto crime means lower exposure overall, they can miss the fact that threat actors often reallocate effort rather than disappear, leaving the most damaging tactics intact.

Failure mechanism: Security teams anchor on the decline in one metric, then reduce vigilance, funding, or testing for ransomware, impersonation, and other still-active attack paths. That creates a control gap between perceived and actual threat mix.

Impact: The organisation becomes easier to disrupt because response, recovery, and awareness controls are no longer tuned to the threats most likely to affect it. In practice, that can mean slower containment, weaker restoration outcomes, and more successful social engineering or extortion attempts.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS Control 17 — Incident Response ManagementRansomware and active scams demand tested response processes.
CIS Control 11 — Data RecoveryRecovery readiness matters when ransomware remains a live threat.
Recommendation — Exercise and refine incident response for the attack types still producing loss. Validate backups and restoration paths against extortion scenarios.
NIST CSF 2.0RS.RP — Response Plan ExecutionThe question is about whether planning stays aligned to current threat conditions.
RC.RP — Recovery PlanningFalling overall crime does not reduce the need to restore from extortion events.
Recommendation — Align response execution to the current threat mix, not the average trend. Test recovery plans against ransomware and other still-active disruption scenarios.
MITRE ATT&CKT1486 — Data Encrypted for ImpactRansomware remains the threat type that can still disrupt operations materially.
T1566 — PhishingImpersonation scams remain resilient because social-engineering paths still work.
Recommendation — Map ransomware scenarios to T1486 and prioritize detection plus restore readiness. Hunt for phishing and impersonation patterns that still drive compromise.

Practitioner Guidance

What to prioritise: Rebuild threat planning around attack types and business impact, not around a single market-wide revenue trend. If ransomware or impersonation is still active in your sector, those scenarios deserve the same or greater planning weight than the declining category.

What to verify: Check whether your incident response exercises, restore tests, and awareness content reflect the current threat mix. A mature programme should show clear coverage for the abuse patterns that remain operationally relevant, not just the ones that dominated last year.

Practitioner takeaway: The right question is not whether crypto crime is falling overall, but whether your control stack is still aligned to the threats that can actually hurt you today.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 20, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org