Attacker capability became a commodity. The consequences landed unevenly.
The defining shift of 2024 was not a new attack technique. It was the industrialisation of existing ones, and the residual risk moved into the supply chain, into machine identity, and onto the remote access edge.
- Published
- March 25, 2025
- Period covered
- January 1, 2025 – March 31, 2025
- Documentary cut-off
- March 25, 2025
Executive perspective
Six conclusions that matter for the year ahead
The sophistication gap closed, and a resilience gap opened in its place
Huntress reports that the gap in attack sophistication between large enterprises and smaller businesses has all but disappeared, because attackers now standardise enterprise-tested methods across targets of every size. The World Economic Forum measures the consequence: 35% of small organisations judge their own resilience inadequate, sevenfold more than in 2022, while the share of large organisations saying the same has nearly halved. Small organisations did not get worse at security. The bar moved to enterprise level everywhere at once.
That resilience gap is the supply chain risk, seen from the other end
54% of large organisations name supply chain challenges as the single biggest barrier to their own cyber resilience. The population they are describing is precisely the population whose resilience deteriorated. Risk did not so much increase as migrate: large enterprises hardened their own estates, and the residual reappeared in their vendor portfolios.
Law enforcement disrupted ransomware brands, not ransomware capacity
The LockBit takedown and the AlphV exit scam produced a measurable slump through Q2 and early Q3 2024. Q4 was then the most active ransomware quarter ever recorded: 1,667 publicly posted victims, up 49% year over year, claimed by 61 distinct named groups. Forty new groups emerged during the year, double the 2023 count.
The presence of detection tooling no longer predicts the absence of an incident
91% of systems affected by an incident already had an EDR installed. 79% of detections involved no malware at all. At Expel, EDR was the initial alert source for only 25% of incidents. The question "do we have endpoint detection" has been answered across the market, and it is no longer the question that separates outcomes.
Organisations are scaling a vulnerability process that attacks are leaving
More than 39,000 CVEs were published in 2024, up 40%, an average of 378 per day. Over the same period the number of CVEs confirmed as exploited in ransomware campaigns fell from 40 to 24. Meanwhile identity-based incidents reached 68% of the total and abuse of external remote services accounted for 45% of successful initial access.
For Canadian industrial organisations, three findings describe one exposure
North America absorbed 58% of the world's industrial ransomware attacks. Manufacturing accounted for more than half of all industrial victims, at 1,171 attacks. And the Canadian Centre for Cyber Security names ransomware the top cybercrime threat to Canada's critical infrastructure. A Canadian mid-market manufacturer is not adjacent to this trend; it is the modal target.
The quarter in numbers
48 min
Average breakout time to lateral movement
Reported independently by CrowdStrike and ReliaQuest from different populations. Containment measured in hours is structurally too slow.
68%
Share of incidents that were identity-based
Up four points year over year, while endpoint incidents fell to 22%. Identity is not one attack surface among several; it is the majority case.
1,667
Ransomware victims posted in Q4 2024, up 49% year over year
The most active quarter on record, arriving after the post-LockBit slump. The recovery, not the disruption, is the finding.
91%
Systems hit by an incident that already had an EDR installed
Mid-market telemetry. Detection coverage has stopped being the differentiator, even though the tooling demonstrably works.
45%
Successful initial access through external remote services
VPN portals, RDP and VDI. Access broker listings offering VPN access rose 250% in a year. The most under-inventoried surface in the mid-market.
85%
Breaches involving a compromised service account
Machine identity, not human. Service accounts sit outside MFA, are rarely rotated and are over-privileged by accumulation.
39,000 vs 24
CVEs published in 2024, against CVEs confirmed used in ransomware
Publication rose 40% while confirmed ransomware-linked CVEs fell 42.5%. The two series moved in opposite directions.
1,171
Ransomware attacks against manufacturing, over half of all industrial victims
Corroborated from a separate dataset: 67% of all tracked ransomware groups claimed at least one manufacturing victim.
The board agenda
Five questions your board should be able to answer this quarter
They follow directly from the findings above. The full edition carries, for each one, the evidence behind it and the prioritised action that answers it.
Can we produce a list, generated from outside our network, of every internet-reachable remote access service we operate, and confirm MFA and device certificates on each?
45% of successful initial access.
Who, by name, is accountable for each service account in our environment, and what happens to an account whose owner has left the organisation?
85% of breaches involve a compromised service account.
What is our service desk permitted to refuse?
Vishing up 442%; 14% of successful entry.
Which of our suppliers are a weakness problem and which are a concentration problem, and do we manage them differently?
54% of large organisations name supply chain their top resilience barrier; vendor concentration identified as a distinct national trend.
If an attacker copied everything and encrypted nothing, who decides what we disclose, and within what deadline?
The documented shift to extortion without encryption.
Want to see what changed this quarter, the trend radar, the FortaRisks point of view and what we are watching next?
The executive perspective above is the opening of the report. The complete edition carries the analysis and the recommendations that follow from it.
What the full edition adds
- What changed this quarter, and what only looks new
- Trend radar: direction, maturity and business impact
- The FortaRisks point of view, four convictions
- Looking ahead, next 3 to 6 months, with confidence levels
- The threat landscape, developments in detail
- Sector exposure, with OT and manufacturing broken out
- Prioritised recommendations, by theme and by risk addressed
- The prioritised action answering each question above, plus the source base and method
22 pages · 9 sources · immediate download, no wait
How this edition was built
This edition draws on the executive and annual reports published by leading consulting, research and cybersecurity firms up to the cut-off date, read against FortaRisks Research analysis and our own cyber threat intelligence. Nine primary sources inform it. The flagship annual editions covering 2024 in full had not yet been published when the quarter closed, so they are deliberately absent here and will inform the June 2025 edition.
Every figure on this page appears in the full edition with its source, its data period and its methodological limits. A source is admitted only when its publication date precedes the documentary cut-off, so a historical edition never draws on research that did not yet exist. Where two independent datasets disagree, we report both rather than selecting one. The reading, the cross-source synthesis and the conclusions are FortaRisks Research's own, informed by the threat intelligence we operate.
See where your organisation sits on these numbers
The report says what is happening across the market. A 30-minute demo says what is happening on your attack surface.