SecBriefs
← Industry Reports
SophosSophos
INDUSTRY REPORTThreat Landscape7 min read

Identity Weaknesses Sit Behind Two-Thirds of Investigated Incidents

Sophos reports that 67% of investigated incidents were rooted in identity-related attacks, while attackers reached Active Directory in 3.4 hours and ransomware remained heavily concentrated outside business hours.

Sophos
2026

Sophos Active Adversary Report 2026

THREAT LANDSCAPE · SECBRIEFS ANALYSIS
THE SHORT VERSION

Executive Takeaway

Sophos' 2026 Active Adversary Report shows how often attackers succeed without exotic techniques. Identity compromise dominates root causes, brute-force activity has nearly caught vulnerability exploitation as an initial access method, and adversaries can reach Active Directory within hours.

The defensive implication is clear: organizations need identity controls, telemetry and 24/7 response coverage that work when attackers are most active—not only during business hours.

Key Findings

  1. 01

    Identity-related attacks were the root cause in 67% of incidents investigated by Sophos IR and MDR teams.

  2. 02

    Brute-force activity accounted for 15.6% of initial access, almost level with vulnerability exploitation at 16%.

  3. 03

    Median attacker dwell time declined to three days.

  4. 04

    Attackers reached Active Directory in an average of just 3.4 hours after gaining access.

  5. 05

    Eighty-eight percent of ransomware payload deployments and 79% of data-exfiltration actions occurred outside business hours.

  6. 06

    MFA was absent in 59% of cases, making stolen and compromised credentials easier to abuse.

What the Data Says

67%

Identity-related root cause

Two-thirds of investigated incidents were rooted in identity-related attacks.

3.4h

Time to Active Directory

Once inside, attackers reached Active Directory in as little as 3.4 hours on average in the report dataset.

88%

Ransomware after hours

Most ransomware payloads were deployed outside normal business hours, when response coverage may be thinner.

What It Doesn’t Say / Limitations

The report analyzes 661 Incident Response and Managed Detection and Response cases handled across 70 countries and 34 industries. These are Sophos and Secureworks customer cases rather than a random sample of all incidents.

MDR and IR cases can overrepresent organizations that had enough visibility or severity to engage responders. The figures are most useful for understanding attacker behavior and defensive timing, not estimating universal incident probability.

Why It Matters

Identity security is now an operational response problem as much as an authentication problem. If an attacker can move from valid credentials to Active Directory within hours, delayed investigation, weak MFA coverage and short log retention can erase the defender's margin for error.

The concentration of ransomware and exfiltration outside business hours also makes staffing and escalation design a control issue. A technically strong stack can still fail if no one can act quickly when it matters.

Who Should Care

  • Identity and access teams
  • SOC and MDR teams
  • Incident-response leaders
  • Active Directory and infrastructure teams
  • CISOs and security leaders
  • Organizations with limited after-hours coverage
SECBRIEFS VIEW

SecBriefs Assessment

Sophos provides one of the clearest operational arguments for treating identity as part of the attack surface. The 3.4-hour path to Active Directory and heavy after-hours activity are particularly useful for testing whether controls work under real timing pressure.

Organizations should combine phishing-resistant MFA, continuous identity monitoring, sufficient log retention and 24/7 response rather than assuming any one of those controls will compensate for the others.

What To Do Now

  1. Deploy phishing-resistant MFA for privileged and high-value accounts and validate coverage continuously.
  2. Monitor identity and Active Directory signals 24/7 with clear escalation paths.
  3. Extend firewall, identity and endpoint log retention far enough to support investigation and threat hunting.
  4. Reduce unnecessary exposure of internet-facing services and identity infrastructure.
  5. Test off-hours ransomware scenarios with named responders and decision-makers.
  6. Measure time from initial alert to identity containment and privileged-session revocation.
ORIGINAL REPORT

Sophos Active Adversary Report 2026

Publisher
Sophos
Published
URL
https://www.sophos.com/en-us/press/press-releases/sophos-active-adversary-report-2026-identity-attacks-dominate-as-threat-groups-proliferate
View on publisher site(opens in a new tab)

Get the next SecBriefs report analysis

Clear analysis of major cybersecurity reports, delivered by SecBriefs.