Cyber Security Insights April 2026

Cyber Security Insights April 2026

Written by Bryan Altimas

Cyber security risk is becoming more concentrated, not more dispersed. The most significant incidents we are seeing in 2026 are not coming from obscure technical weaknesses. They are emerging from core business dependencies.

This month we focus on three areas where that shift is most visible. Ransomware has evolved into a data extortion model that targets reputation as much as operations. Supply chain risk continues to expose organisations through trusted partners and embedded software. Identity has become the primary attack surface as traditional network boundaries fade.

Ransomware Evolution: From Encryption to Extortion

Ransomware has undergone a fundamental shift. It is no longer primarily about denying access to systems. It is about creating leverage through exposure.

For years, organisations invested in backup and recovery as the primary defence. That approach assumed attackers needed to encrypt data to force payment. That assumption no longer holds.

Attackers have adapted their model. Data is now the asset. Extortion is the objective.

This evolution has been visible across multiple incident reports and threat intelligence briefings. In many cases, encryption is either delayed or removed entirely. The pressure comes from the threat of data publication, regulatory scrutiny, and loss of customer trust.

This creates a different risk profile:

  • Data exfiltration often occurs before any visible disruption
  • Double extortion has become standard practice rather than escalation
  • Triple extortion introduces pressure through customers, partners, and media exposure
  • Cloud environments and software as a service platforms are increasingly targeted due to centralised data stores

The implication for organisations is significant. Traditional resilience measures do not address this form of attack. Backups do not prevent data from being copied. Recovery does not prevent reputational damage.

This requires a shift in defensive thinking.

Detection must move earlier in the attack chain. Indicators such as unusual data access patterns, privilege escalation, and outbound data movement become critical signals. Response plans must also expand. Legal, regulatory, and communications functions need to be engaged from the outset, not after containment.

Leadership teams should also recognise that this is not purely a technical event. It is a business crisis scenario that intersects with contractual obligations, regulatory timelines, and stakeholder communication.

Final thought
If your strategy is built on restoring systems after an attack, you are planning for interruption. The current threat is exposure. That requires a different level of preparation and a different level of accountability.

Image

An AI-generated image of red digital locks and encrypted data streams on a dark, high-tech circuit background.

Supply Chain and Third Party Risk: Trust Is No Longer Implicit

Modern organisations are not isolated environments. They are ecosystems of suppliers, platforms, integrations, and dependencies.

That interconnected model has created efficiency and scalability. It has also introduced systemic risk.

Some of the most significant breaches in recent years have not originated within the target organisation. They have entered through trusted suppliers, software updates, or embedded components. The common factor is not technical complexity. It is inherited trust.

This is where the challenge lies.

Many organisations have visibility of their direct suppliers. Fewer have a clear understanding of the extended supply chain, including downstream dependencies and software components. Even fewer have continuous assurance over how those suppliers operate in practice.

Risk is increasing across several areas:

  • Software as a service platforms with deep integration into core business processes
  • Open source components that are widely reused but not always fully tracked
  • Application programming interface (API) driven connectivity between internal and external systems
  • Managed service providers operating with privileged or administrative access

The traditional approach to third party risk management has been periodic assessment. Questionnaires, certifications, and onboarding checks provide a snapshot in time. They do not reflect how risk evolves.

Leading organisations are moving towards continuous assurance models. This includes monitoring supplier behaviour, validating controls in practice, and maintaining updated inventories of software components through software bills of materials.

Procurement and legal functions also play a critical role. Security expectations must be defined contractually. Accountability must be clear. Escalation paths must be agreed before an incident occurs.

This is not about eliminating third party risk. That is not realistic. It is about understanding it, managing it, and ensuring that responsibility is not assumed without evidence.

Final thought
If your business relies on third parties to operate, then your risk extends beyond your control. Trust may be necessary, but without verification it becomes a vulnerability rather than a strength.

Image

An AI-generated image of a glowing central padlock connecting various nodes in a complex digital network.

Identity Is the New Perimeter: Access Is the Attack Surface

The concept of a defined network boundary has eroded. Cloud adoption, remote working, and system integration have changed how access is granted and used.

Attackers have adapted to this environment. They do not need to bypass perimeter controls if they can obtain valid credentials. In many incidents, the attacker’s activity appears legitimate because it is performed through authorised access.

This is why identity has become the central focus of modern attack strategies.

The most common entry points are not sophisticated exploits. They are methods that target access:

  • Phishing campaigns designed to capture credentials
  • Multi factor authentication fatigue and social engineering techniques
  • Token theft and session replay attacks
  • Compromise or misuse of privileged accounts

These methods are effective because they exploit how access is managed, not how systems are built.

Defensive strategies must therefore prioritise identity as a core control layer.

This involves more than implementing multi factor authentication. It requires a structured approach to how access is granted, monitored, and enforced:

  • Applying least privilege across all users, systems, and services
  • Strengthening authentication mechanisms and reducing reliance on single factors
  • Monitoring identity behaviour to detect anomalies and misuse
  • Implementing zero trust principles where access is continuously evaluated based on context

This also has organisational implications. Identity, security, and operational teams must work in alignment. Access decisions are no longer static events. They are ongoing processes that require visibility and control.

From a leadership perspective, identity risk is often underestimated because it does not present as a traditional system vulnerability. However, if an attacker can authenticate successfully, they inherit the permissions and access of that identity.

Final thought
If an attacker can log in, they do not need to break in. Controlling identity is no longer an administrative function. It is one of the most critical security controls your organisation has.

Image

An AI-generated image of a remote worker at a desk overlaid with digital security graphics and a city view.


Join the Newsletter
Insights from Riverside Court Consulting Ltd into cyber security, data protection and regulatory compliance
Subscribe Now
Categories
Recent Posts

Cyber Security is serious. But it shouldn't be confusing and stressful

crossmenuarrow-right