SecBriefs
← Industry Reports
Palo Alto NetworksPalo Alto Networks
INDUSTRY REPORTTechnology & Innovation8 min read

Identity Weakness and Multi-Surface Intrusions Are Accelerating Impact

Identity appeared in 89% of Unit 42 investigations, while most incidents crossed multiple attack surfaces. The report shows why fragmented controls and slow response allow initial access to become enterprise-wide impact.

Palo Alto Networks
2026

2026 Unit 42 Global Incident Response Report

TECHNOLOGY & INNOVATION · SECBRIEFS ANALYSIS
THE SHORT VERSION

Executive Takeaway

Unit 42’s 2026 incident-response evidence shows that intrusions increasingly span identity, endpoint, network, human, application and cloud layers. Identity appeared in 89% of investigations, and 87% involved at least two attack surfaces.

Leadership should focus on the seams between teams and platforms. The central risk is not merely a missing control, but the time and opportunity attackers gain when ownership, telemetry and containment are fragmented across the enterprise.

Key Findings

  1. 01

    Identity was involved in 89% of Unit 42 incident investigations conducted in 2025.

  2. 02

    Eighty-seven percent of incidents involved two or more attack surfaces, and 67% involved three or more.

  3. 03

    Phishing and vulnerability exploitation were tied as the leading initial-access vectors at 22% each.

  4. 04

    The fastest quarter of intrusions reached exfiltration in 1.2 hours, down from 4.8 hours in the prior calendar year.

  5. 05

    Browser activity played a role in 48% of investigations.

  6. 06

    Unit 42 observed a shift from encryption toward data theft and extortion as a primary impact pattern.

What the Data Says

89%

Identity involvement

Identity was one of the most frequently affected surfaces in Unit 42’s incident-response caseload.

87%

Multi-surface incidents

Most investigations involved at least two attack surfaces, making cross-domain visibility and ownership essential.

1.2 hours

Fastest-quarter exfiltration

The fastest 25% of intrusions reached exfiltration in 1.2 hours, compared with 4.8 hours in the prior calendar year.

What It Doesn’t Say / Limitations

The report reflects Unit 42 incident-response engagements, so the sample is weighted toward organizations that experienced material incidents and engaged the publisher. It is not a prevalence survey of all enterprises.

Attack-surface percentages are not mutually exclusive, and geographic, sector and client-selection effects may influence the distribution. Palo Alto Networks is a commercial provider; its operational findings should be compared with internal incident data and independent sources.

Why It Matters

The findings make organizational fragmentation measurable. An identity event can quickly expand into endpoints, cloud services, browsers and applications, while separate teams each see only part of the intrusion.

That matters especially for financial services, where workforce identity, customer fraud, third-party access and cloud administration intersect. Incident readiness must join these signals before data theft or extortion becomes the first shared indicator.

Who Should Care

  • CISOs and security leaders
  • Incident-response and SOC teams
  • Identity and access teams
  • Cloud and application-security teams
  • Fraud and insider-risk teams
  • Business-continuity leaders
SECBRIEFS VIEW

SecBriefs Assessment

Unit 42 provides valuable frontline evidence about how incidents move across control boundaries. The identity and multi-surface findings are more actionable than treating every incident as an endpoint problem.

The report should prompt leaders to test end-to-end detection and containment across teams. Its client-based sample means the percentages are not universal benchmarks, but the speed and coordination problem is broadly applicable.

What To Do Now

  1. Map high-risk identities to the endpoints, applications, cloud roles and business processes they can reach.
  2. Join browser, email, identity, endpoint and cloud telemetry for common attack paths.
  3. Patch internet-facing vulnerabilities according to exploitability and exposure, with accountable business owners.
  4. Exercise a 60-minute data-exfiltration scenario involving multiple security teams.
  5. Harden help-desk, contractor-onboarding and remote-hiring verification against synthetic identities and deepfakes.
  6. Prepare response playbooks for data theft and extortion, not only encryption-based ransomware.
ORIGINAL REPORT

2026 Unit 42 Global Incident Response Report

Publisher
Palo Alto Networks
Published
URL
https://www.paloaltonetworks.com/resources/research/unit-42-incident-response-report
View on publisher site(opens in a new tab)

Get the next SecBriefs report analysis

Clear analysis of major cybersecurity reports, delivered by SecBriefs.