Skip to content
FortaRisks
All quarterly reports
Q1 2025

Attacker capability became a commodity. The consequences landed unevenly.

The defining shift of 2024 was not a new attack technique. It was the industrialisation of existing ones, and the residual risk moved into the supply chain, into machine identity, and onto the remote access edge.

Published
March 25, 2025
Period covered
January 1, 2025March 31, 2025
Documentary cut-off
March 25, 2025

Executive perspective

Six conclusions that matter for the year ahead

  1. The sophistication gap closed, and a resilience gap opened in its place

    Huntress reports that the gap in attack sophistication between large enterprises and smaller businesses has all but disappeared, because attackers now standardise enterprise-tested methods across targets of every size. The World Economic Forum measures the consequence: 35% of small organisations judge their own resilience inadequate, sevenfold more than in 2022, while the share of large organisations saying the same has nearly halved. Small organisations did not get worse at security. The bar moved to enterprise level everywhere at once.

  2. That resilience gap is the supply chain risk, seen from the other end

    54% of large organisations name supply chain challenges as the single biggest barrier to their own cyber resilience. The population they are describing is precisely the population whose resilience deteriorated. Risk did not so much increase as migrate: large enterprises hardened their own estates, and the residual reappeared in their vendor portfolios.

  3. Law enforcement disrupted ransomware brands, not ransomware capacity

    The LockBit takedown and the AlphV exit scam produced a measurable slump through Q2 and early Q3 2024. Q4 was then the most active ransomware quarter ever recorded: 1,667 publicly posted victims, up 49% year over year, claimed by 61 distinct named groups. Forty new groups emerged during the year, double the 2023 count.

  4. The presence of detection tooling no longer predicts the absence of an incident

    91% of systems affected by an incident already had an EDR installed. 79% of detections involved no malware at all. At Expel, EDR was the initial alert source for only 25% of incidents. The question "do we have endpoint detection" has been answered across the market, and it is no longer the question that separates outcomes.

  5. Organisations are scaling a vulnerability process that attacks are leaving

    More than 39,000 CVEs were published in 2024, up 40%, an average of 378 per day. Over the same period the number of CVEs confirmed as exploited in ransomware campaigns fell from 40 to 24. Meanwhile identity-based incidents reached 68% of the total and abuse of external remote services accounted for 45% of successful initial access.

  6. For Canadian industrial organisations, three findings describe one exposure

    North America absorbed 58% of the world's industrial ransomware attacks. Manufacturing accounted for more than half of all industrial victims, at 1,171 attacks. And the Canadian Centre for Cyber Security names ransomware the top cybercrime threat to Canada's critical infrastructure. A Canadian mid-market manufacturer is not adjacent to this trend; it is the modal target.

The quarter in numbers

  • 48 min

    Average breakout time to lateral movement

    Reported independently by CrowdStrike and ReliaQuest from different populations. Containment measured in hours is structurally too slow.

  • 68%

    Share of incidents that were identity-based

    Up four points year over year, while endpoint incidents fell to 22%. Identity is not one attack surface among several; it is the majority case.

  • 1,667

    Ransomware victims posted in Q4 2024, up 49% year over year

    The most active quarter on record, arriving after the post-LockBit slump. The recovery, not the disruption, is the finding.

  • 91%

    Systems hit by an incident that already had an EDR installed

    Mid-market telemetry. Detection coverage has stopped being the differentiator, even though the tooling demonstrably works.

  • 45%

    Successful initial access through external remote services

    VPN portals, RDP and VDI. Access broker listings offering VPN access rose 250% in a year. The most under-inventoried surface in the mid-market.

  • 85%

    Breaches involving a compromised service account

    Machine identity, not human. Service accounts sit outside MFA, are rarely rotated and are over-privileged by accumulation.

  • 39,000 vs 24

    CVEs published in 2024, against CVEs confirmed used in ransomware

    Publication rose 40% while confirmed ransomware-linked CVEs fell 42.5%. The two series moved in opposite directions.

  • 1,171

    Ransomware attacks against manufacturing, over half of all industrial victims

    Corroborated from a separate dataset: 67% of all tracked ransomware groups claimed at least one manufacturing victim.

The board agenda

Five questions your board should be able to answer this quarter

They follow directly from the findings above. The full edition carries, for each one, the evidence behind it and the prioritised action that answers it.

  1. Can we produce a list, generated from outside our network, of every internet-reachable remote access service we operate, and confirm MFA and device certificates on each?

    45% of successful initial access.

  2. Who, by name, is accountable for each service account in our environment, and what happens to an account whose owner has left the organisation?

    85% of breaches involve a compromised service account.

  3. What is our service desk permitted to refuse?

    Vishing up 442%; 14% of successful entry.

  4. Which of our suppliers are a weakness problem and which are a concentration problem, and do we manage them differently?

    54% of large organisations name supply chain their top resilience barrier; vendor concentration identified as a distinct national trend.

  5. If an attacker copied everything and encrypted nothing, who decides what we disclose, and within what deadline?

    The documented shift to extortion without encryption.

Full edition

Want to see what changed this quarter, the trend radar, the FortaRisks point of view and what we are watching next?

The executive perspective above is the opening of the report. The complete edition carries the analysis and the recommendations that follow from it.

What the full edition adds

  • What changed this quarter, and what only looks new
  • Trend radar: direction, maturity and business impact
  • The FortaRisks point of view, four convictions
  • Looking ahead, next 3 to 6 months, with confidence levels
  • The threat landscape, developments in detail
  • Sector exposure, with OT and manufacturing broken out
  • Prioritised recommendations, by theme and by risk addressed
  • The prioritised action answering each question above, plus the source base and method

22 pages · 9 sources · immediate download, no wait

Your address tells us who is reading. No list, no sequence, no sharing with anyone.

How this edition was built

This edition draws on the executive and annual reports published by leading consulting, research and cybersecurity firms up to the cut-off date, read against FortaRisks Research analysis and our own cyber threat intelligence. Nine primary sources inform it. The flagship annual editions covering 2024 in full had not yet been published when the quarter closed, so they are deliberately absent here and will inform the June 2025 edition.

Every figure on this page appears in the full edition with its source, its data period and its methodological limits. A source is admitted only when its publication date precedes the documentary cut-off, so a historical edition never draws on research that did not yet exist. Where two independent datasets disagree, we report both rather than selecting one. The reading, the cross-source synthesis and the conclusions are FortaRisks Research's own, informed by the threat intelligence we operate.

See where your organisation sits on these numbers

The report says what is happening across the market. A 30-minute demo says what is happening on your attack surface.