Cyber security risk is becoming more concentrated, not more dispersed. The most significant incidents we are seeing in 2026 are not coming from obscure technical weaknesses. They are emerging from core business dependencies.
This month we focus on three areas where that shift is most visible. Ransomware has evolved into a data extortion model that targets reputation as much as operations. Supply chain risk continues to expose organisations through trusted partners and embedded software. Identity has become the primary attack surface as traditional network boundaries fade.
Ransomware has undergone a fundamental shift. It is no longer primarily about denying access to systems. It is about creating leverage through exposure.
For years, organisations invested in backup and recovery as the primary defence. That approach assumed attackers needed to encrypt data to force payment. That assumption no longer holds.
Attackers have adapted their model. Data is now the asset. Extortion is the objective.
This evolution has been visible across multiple incident reports and threat intelligence briefings. In many cases, encryption is either delayed or removed entirely. The pressure comes from the threat of data publication, regulatory scrutiny, and loss of customer trust.
This creates a different risk profile:
The implication for organisations is significant. Traditional resilience measures do not address this form of attack. Backups do not prevent data from being copied. Recovery does not prevent reputational damage.
This requires a shift in defensive thinking.
Detection must move earlier in the attack chain. Indicators such as unusual data access patterns, privilege escalation, and outbound data movement become critical signals. Response plans must also expand. Legal, regulatory, and communications functions need to be engaged from the outset, not after containment.
Leadership teams should also recognise that this is not purely a technical event. It is a business crisis scenario that intersects with contractual obligations, regulatory timelines, and stakeholder communication.
Final thought
If your strategy is built on restoring systems after an attack, you are planning for interruption. The current threat is exposure. That requires a different level of preparation and a different level of accountability.

An AI-generated image of red digital locks and encrypted data streams on a dark, high-tech circuit background.
Modern organisations are not isolated environments. They are ecosystems of suppliers, platforms, integrations, and dependencies.
That interconnected model has created efficiency and scalability. It has also introduced systemic risk.
Some of the most significant breaches in recent years have not originated within the target organisation. They have entered through trusted suppliers, software updates, or embedded components. The common factor is not technical complexity. It is inherited trust.
This is where the challenge lies.
Many organisations have visibility of their direct suppliers. Fewer have a clear understanding of the extended supply chain, including downstream dependencies and software components. Even fewer have continuous assurance over how those suppliers operate in practice.
Risk is increasing across several areas:
The traditional approach to third party risk management has been periodic assessment. Questionnaires, certifications, and onboarding checks provide a snapshot in time. They do not reflect how risk evolves.
Leading organisations are moving towards continuous assurance models. This includes monitoring supplier behaviour, validating controls in practice, and maintaining updated inventories of software components through software bills of materials.
Procurement and legal functions also play a critical role. Security expectations must be defined contractually. Accountability must be clear. Escalation paths must be agreed before an incident occurs.
This is not about eliminating third party risk. That is not realistic. It is about understanding it, managing it, and ensuring that responsibility is not assumed without evidence.
Final thought
If your business relies on third parties to operate, then your risk extends beyond your control. Trust may be necessary, but without verification it becomes a vulnerability rather than a strength.

An AI-generated image of a glowing central padlock connecting various nodes in a complex digital network.
The concept of a defined network boundary has eroded. Cloud adoption, remote working, and system integration have changed how access is granted and used.
Attackers have adapted to this environment. They do not need to bypass perimeter controls if they can obtain valid credentials. In many incidents, the attacker’s activity appears legitimate because it is performed through authorised access.
This is why identity has become the central focus of modern attack strategies.
The most common entry points are not sophisticated exploits. They are methods that target access:
These methods are effective because they exploit how access is managed, not how systems are built.
Defensive strategies must therefore prioritise identity as a core control layer.
This involves more than implementing multi factor authentication. It requires a structured approach to how access is granted, monitored, and enforced:
This also has organisational implications. Identity, security, and operational teams must work in alignment. Access decisions are no longer static events. They are ongoing processes that require visibility and control.
From a leadership perspective, identity risk is often underestimated because it does not present as a traditional system vulnerability. However, if an attacker can authenticate successfully, they inherit the permissions and access of that identity.
Final thought
If an attacker can log in, they do not need to break in. Controlling identity is no longer an administrative function. It is one of the most critical security controls your organisation has.

An AI-generated image of a remote worker at a desk overlaid with digital security graphics and a city view.
