The response window closed. Twenty-nine minutes to lateral movement, four to exfiltration.
A year ago we opened this series at 48 minutes and called containment measured in hours structurally too slow. That number is now 29 minutes, the fastest breakout was 27 seconds, and one intrusion began exfiltrating four minutes after initial access.
- Published
- March 24, 2026
- Period covered
- January 1, 2026 – March 31, 2026
- Documentary cut-off
- March 24, 2026
Executive perspective
Six conclusions that matter for the year ahead
Intrusion speed improved 65% in a single year
Average eCrime breakout fell from 48 to 29 minutes, with a 27-second extreme and one exfiltration beginning four minutes after initial access. Detection that produces a ticket for a human to triage in the morning is no longer participating in the incident. Whatever escalation path your organisation has, it is probably longer than that.
Malware-free detection reached 82%, and the mechanism is trust rather than stealth
CrowdStrike describes adversaries operating through valid credentials, trusted identity flows, approved SaaS integrations and inherited software supply chains. Evasion is no longer achieved by hiding. It is achieved by being authorised, along pathways somebody deliberately created.
Our AI governance forecast finally landed
The share of organisations with a process to assess AI tool security before deployment rose from 37% to 64% in a year. We forecast this in September and carried it unresolved through December. Separately, 87% now name AI-related vulnerabilities the fastest-growing cyber risk, and 94% call AI the most significant driver of change.
The edge remains the door, and the clock on it has shortened again
Zero-day exploitation prior to public disclosure rose 42%. Of vulnerabilities exploited by China-nexus adversaries, 67% granted immediate system access and 40% targeted internet-facing edge devices. X-Force recorded a 44% increase in exploitation of public-facing applications, and found 56% of disclosed vulnerabilities required no authentication at all.
Ransomware fragmentation has not slowed after two years
X-Force recorded a 49% increase in active ransomware groups against 2024, which was itself up 60% on 2023. Two consecutive years of roughly 50% growth in operators, through a period when payment rates fell and median payments halved. More operators earning less historically produces more aggression, not less.
Third-party assessment now takes longer than the risk takes to change
For 64% of large organisations a third-party assessment routinely takes four months or more, and 63% report insufficient visibility past the first tier. We argued in June that an annual instrument cannot govern a risk that doubles in twelve months. The instrument turns out to be slower than we assumed.
The quarter in numbers
29 min
Average breakout time to lateral movement
Down from 48 minutes, 65% faster in a year, with a 27-second extreme. Shorter than most escalation procedures.
4 min
Fastest observed time from initial access to exfiltration
Containment targets measured in hours are now measuring the wrong thing entirely.
82%
Detections involving no malware at all
Up from 79%. Adversaries operate through valid credentials, trusted identity flows and approved integrations.
64%
Organisations assessing AI tool security before deployment
Up from 37% in a year, the fastest improvement in any defensive measure across five editions of this series.
+42%
Increase in zero-day exploitation before public disclosure
For a growing share of cases there is no patch window at all: the flaw is used before anyone outside the adversary knows it exists.
56%
Disclosed vulnerabilities requiring no authentication to exploit
Public-facing application exploitation has moved back ahead of valid credentials, at 40% of cases against 32%.
+49%
Increase in active ransomware groups against 2024
A third consecutive year of fragmentation, against a shrinking pool of payers. Actor-indexed intelligence keeps depreciating.
4+ months
Typical third-party assessment duration for 64% of large organisations
The governing instrument is slower than the risk it governs, and 63% cannot see past the first tier anyway.
The board agenda
Five questions your board should be able to answer this quarter
They follow directly from the findings above. The full edition carries, for each one, the evidence behind it and the prioritised action that answers it.
What can our security operation disconnect without asking anyone, and under what conditions?
29-minute breakout, four-minute exfiltration.
How many internet-facing services do we operate, and is that number falling?
42% rise in pre-disclosure exploitation; 56% of vulnerabilities need no authentication.
How long does one third-party assessment take us, and what changed at that supplier while we were doing it?
Four months or more for 64% of large organisations.
Which suppliers' suppliers can reach us through an inherited trust relationship?
Inherited software supply chains named as a primary evasion pathway.
Are we in the 64% who assess AI tools before deployment, or the 36% who do not?
Up from 37% in a year.
Want to see what changed this quarter, the trend radar, the FortaRisks point of view and what we are watching next?
The executive perspective above is the opening of the report. The complete edition carries the analysis and the recommendations that follow from it.
What the full edition adds
- What changed this quarter, and what only looks new
- Trend radar: direction, maturity and business impact
- The FortaRisks point of view, four convictions
- Looking ahead, next 3 to 6 months, with confidence levels
- The threat landscape, developments in detail
- Sector exposure, with OT and manufacturing broken out
- Prioritised recommendations, by theme and by risk addressed
- The prioritised action answering each question above, plus the source base and method
16 pages · 22 sources · immediate download, no wait
How this edition was built
This edition draws on the executive and annual reports published by leading consulting, research and cybersecurity firms up to the cut-off date, read against FortaRisks Research analysis and our own cyber threat intelligence. It scores the five forecasts made in December: one materialised, one partially, three unresolved because the measurement we needed was not published in the window. We report that rather than reaching for a proxy.
Every figure on this page appears in the full edition with its source, its data period and its methodological limits. A source is admitted only when its publication date precedes the documentary cut-off, so a historical edition never draws on research that did not yet exist. Where two independent datasets disagree, we report both rather than selecting one. The reading, the cross-source synthesis and the conclusions are FortaRisks Research's own, informed by the threat intelligence we operate.
See where your organisation sits on these numbers
The report says what is happening across the market. A 30-minute demo says what is happening on your attack surface.