Skip to content
FortaRisks
All quarterly reports
Q1 2026

The response window closed. Twenty-nine minutes to lateral movement, four to exfiltration.

A year ago we opened this series at 48 minutes and called containment measured in hours structurally too slow. That number is now 29 minutes, the fastest breakout was 27 seconds, and one intrusion began exfiltrating four minutes after initial access.

Published
March 24, 2026
Period covered
January 1, 2026March 31, 2026
Documentary cut-off
March 24, 2026

Executive perspective

Six conclusions that matter for the year ahead

  1. Intrusion speed improved 65% in a single year

    Average eCrime breakout fell from 48 to 29 minutes, with a 27-second extreme and one exfiltration beginning four minutes after initial access. Detection that produces a ticket for a human to triage in the morning is no longer participating in the incident. Whatever escalation path your organisation has, it is probably longer than that.

  2. Malware-free detection reached 82%, and the mechanism is trust rather than stealth

    CrowdStrike describes adversaries operating through valid credentials, trusted identity flows, approved SaaS integrations and inherited software supply chains. Evasion is no longer achieved by hiding. It is achieved by being authorised, along pathways somebody deliberately created.

  3. Our AI governance forecast finally landed

    The share of organisations with a process to assess AI tool security before deployment rose from 37% to 64% in a year. We forecast this in September and carried it unresolved through December. Separately, 87% now name AI-related vulnerabilities the fastest-growing cyber risk, and 94% call AI the most significant driver of change.

  4. The edge remains the door, and the clock on it has shortened again

    Zero-day exploitation prior to public disclosure rose 42%. Of vulnerabilities exploited by China-nexus adversaries, 67% granted immediate system access and 40% targeted internet-facing edge devices. X-Force recorded a 44% increase in exploitation of public-facing applications, and found 56% of disclosed vulnerabilities required no authentication at all.

  5. Ransomware fragmentation has not slowed after two years

    X-Force recorded a 49% increase in active ransomware groups against 2024, which was itself up 60% on 2023. Two consecutive years of roughly 50% growth in operators, through a period when payment rates fell and median payments halved. More operators earning less historically produces more aggression, not less.

  6. Third-party assessment now takes longer than the risk takes to change

    For 64% of large organisations a third-party assessment routinely takes four months or more, and 63% report insufficient visibility past the first tier. We argued in June that an annual instrument cannot govern a risk that doubles in twelve months. The instrument turns out to be slower than we assumed.

The quarter in numbers

  • 29 min

    Average breakout time to lateral movement

    Down from 48 minutes, 65% faster in a year, with a 27-second extreme. Shorter than most escalation procedures.

  • 4 min

    Fastest observed time from initial access to exfiltration

    Containment targets measured in hours are now measuring the wrong thing entirely.

  • 82%

    Detections involving no malware at all

    Up from 79%. Adversaries operate through valid credentials, trusted identity flows and approved integrations.

  • 64%

    Organisations assessing AI tool security before deployment

    Up from 37% in a year, the fastest improvement in any defensive measure across five editions of this series.

  • +42%

    Increase in zero-day exploitation before public disclosure

    For a growing share of cases there is no patch window at all: the flaw is used before anyone outside the adversary knows it exists.

  • 56%

    Disclosed vulnerabilities requiring no authentication to exploit

    Public-facing application exploitation has moved back ahead of valid credentials, at 40% of cases against 32%.

  • +49%

    Increase in active ransomware groups against 2024

    A third consecutive year of fragmentation, against a shrinking pool of payers. Actor-indexed intelligence keeps depreciating.

  • 4+ months

    Typical third-party assessment duration for 64% of large organisations

    The governing instrument is slower than the risk it governs, and 63% cannot see past the first tier anyway.

The board agenda

Five questions your board should be able to answer this quarter

They follow directly from the findings above. The full edition carries, for each one, the evidence behind it and the prioritised action that answers it.

  1. What can our security operation disconnect without asking anyone, and under what conditions?

    29-minute breakout, four-minute exfiltration.

  2. How many internet-facing services do we operate, and is that number falling?

    42% rise in pre-disclosure exploitation; 56% of vulnerabilities need no authentication.

  3. How long does one third-party assessment take us, and what changed at that supplier while we were doing it?

    Four months or more for 64% of large organisations.

  4. Which suppliers' suppliers can reach us through an inherited trust relationship?

    Inherited software supply chains named as a primary evasion pathway.

  5. Are we in the 64% who assess AI tools before deployment, or the 36% who do not?

    Up from 37% in a year.

Full edition

Want to see what changed this quarter, the trend radar, the FortaRisks point of view and what we are watching next?

The executive perspective above is the opening of the report. The complete edition carries the analysis and the recommendations that follow from it.

What the full edition adds

  • What changed this quarter, and what only looks new
  • Trend radar: direction, maturity and business impact
  • The FortaRisks point of view, four convictions
  • Looking ahead, next 3 to 6 months, with confidence levels
  • The threat landscape, developments in detail
  • Sector exposure, with OT and manufacturing broken out
  • Prioritised recommendations, by theme and by risk addressed
  • The prioritised action answering each question above, plus the source base and method

16 pages · 22 sources · immediate download, no wait

Your address tells us who is reading. No list, no sequence, no sharing with anyone.

How this edition was built

This edition draws on the executive and annual reports published by leading consulting, research and cybersecurity firms up to the cut-off date, read against FortaRisks Research analysis and our own cyber threat intelligence. It scores the five forecasts made in December: one materialised, one partially, three unresolved because the measurement we needed was not published in the window. We report that rather than reaching for a proxy.

Every figure on this page appears in the full edition with its source, its data period and its methodological limits. A source is admitted only when its publication date precedes the documentary cut-off, so a historical edition never draws on research that did not yet exist. Where two independent datasets disagree, we report both rather than selecting one. The reading, the cross-source synthesis and the conclusions are FortaRisks Research's own, informed by the threat intelligence we operate.

See where your organisation sits on these numbers

The report says what is happening across the market. A 30-minute demo says what is happening on your attack surface.