• About Us
  • Advertising
  • Digital Magazine
  • Supplements
  • Media Pack
  • Privacy Policy
  • Contact us
CXO Insight Middle East
  • News
  • Opinion
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
    • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Awards
      • 2025
      • 2024
      • 2023
    • Channel Insights Summit 2025
    • Webinars
      • AI in Finance
      • The Resilient Enterprise
    • CXO50 Oman
    • CXO50
      • 2026
      • 2025
    • ICT Awards
      • Dubai 2025
      • Saudi Arabia
    • Cyber Strategists Summit
      • 2026
      • 2025
      • 2024
      • 2023
      • 2022
      • 2021
    • Cloud Connect 2025
    • All events
  • Digital Magazine
  • GITEX x AI EVERYTHING
No Result
View All Result
CXO Insight Middle East
  • News
  • Opinion
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
    • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Awards
      • 2025
      • 2024
      • 2023
    • Channel Insights Summit 2025
    • Webinars
      • AI in Finance
      • The Resilient Enterprise
    • CXO50 Oman
    • CXO50
      • 2026
      • 2025
    • ICT Awards
      • Dubai 2025
      • Saudi Arabia
    • Cyber Strategists Summit
      • 2026
      • 2025
      • 2024
      • 2023
      • 2022
      • 2021
    • Cloud Connect 2025
    • All events
  • Digital Magazine
  • GITEX x AI EVERYTHING
No Result
View All Result
CXO Insight Middle East
No Result
View All Result

71% of organisations suffered at least one identity breach in the past year, Sophos research finds

by CXO Staff
May 13, 2026
in Future, News, Region, Tech

State of Identity Security 2026 report finds human error and poor non-human identity management are the root causes of most attacks, as agentic AI accelerates the risk

71% of organisations suffered at least one identity breach in the past year, Sophos research finds

Sophos released the State of Identity Security 2026, a vendor-agnostic survey of 5,000 IT and cybersecurity leaders across 17 countries. The survey found that 71% of organisations suffered at least one identity-related breach in the past year, and on average organisations reported three separate incidents. Repeat victimisation reached a notable level, with 5% even reporting six or more breaches. These attacks are driven primarily by human error and weak management of non-human identities (NHIs), a challenge that is growing rapidly as agentic AI accelerates attack processes.

Two thirds of the ransomware victims (67%) responding to this survey confirmed their ransomware incident stemmed from an identity attack, establishing identity compromise as a primary delivery mechanism for ransomware. Sophos X-Ops researchers have observed this consistently over the past year. The financial consequences are steep: the mean recovery cost reached $1.64 million, with a median of $750,000, and 73% of those affected faced costs of $250,000 or more.

“Identity has become the primary attack surface in modern cybersecurity, and this data shows most organisations are losing ground,” said Ross McKerchar, chief information security officer, Sophos. “The non-human identity problem is particularly urgent. AI agents are being granted privileges faster than security teams can track them, and organisations that fail to get ahead of this will find it an increasingly costly gap to close.”

Additional key findings from the State of Identity Security 2026:

  • Data and financial theft dominate breach fallout: Overall, 10% of organisations reported an identity breach that impacted their business in the last year, with the primary consequences being data theft (49%), ransomware (48%), and financial theft (47%)
  • Visibility remains a critical weakness: Only 24% of organisations continually monitor for unusual login attempts, and more than half check every three months or less.
  • Detection gaps persist: 14% of breached organisations could not detect and stop their most significant identity attack before damage was done. Smaller organisations (100–250 employees) were nearly twice as likely to fail at detection as mid-sized peers.
  • Critical infrastructure most exposed: Energy, oil/gas, and utilities (80%) and federal/central government (78%) reported the highest breach rates across all industries surveyed.
  • Compliance struggles signal broader risk: Organisations that found compliance requirements very challenging had a breach rate of 82.4%, a full 14 percentage points higher than those with lower compliance difficulty (68.3%).

Human error (employees tricked into providing credentials) was cited in nearly 43% of incidents. Weak NHI management, including API keys stored in code, static credentials, and orphaned service accounts, was cited in 41%. Organisations with weak NHI management are 22% more likely to experience financial theft and pay approximately $150,000 more to recover than average.

The NHI management problem is intensifying. AI agents can autonomously spin up sub-agents, each generating new credentials with broad, persistent access and inconsistent human oversight. Existing identity frameworks were not built for this, and organisations are already behind: only 1 in 3 organisations regularly rotate or audits service accounts and non-human identities, and just 11% do so continuously.

Recommendations to reduce identity-based risks

To reduce exposure to identity-related attacks, organisations should implement a multi-layered approach covering both human and non-human identities. Essential steps include enforcing Multi-Factor Authentication (MFA) for all user accounts, applying least-privilege access principles, and disabling or removing inactive identities promptly.

For non-human identities specifically, organisations should inventory and classify all NHIs, replace long-lived credentials with short-lived alternatives, and implement secrets management platforms to manage NHI credentials at scale. As agentic AI accelerates NHI proliferation, deploying Identity Threat Detection and Response (ITDR) capabilities and adopting a Zero Trust security model are increasingly critical layers of defence.

The State of Identity Security 2026 report comes from a vendor-agnostic survey conducted in Q1 2026 of 5,000 IT and cybersecurity leaders across 17 countries, including the U.S., U.K., Germany, France, Australia, Japan, India, and Brazil, in organisations with 100 to 5,000 employees across 14 industries.

Tags: Identity SecuritySophosState of Identity Security 2026
ShareTweet

Related Posts

Nokia launches AI lab to fast-track AI-native data center networking
Future

Nokia launches AI lab to fast-track AI-native data center networking

May 21, 2026

Nokia announced the launch of its AI Networking Innovation Lab; a new center designed to drive co-innovation with AI and...

Core42 raises USD 550 million from HSBC to scale global AI infrastructure
Business

Core42 raises USD 550 million from HSBC to scale global AI infrastructure

May 21, 2026

Core42 announced the successful arrangement of two structured trade finance facilities (“the facilities”) amounting to USD550 million with HSBC to...

Discussion about this post

Latest Issue

Nokia launches AI lab to fast-track AI-native data center networking

Nokia launches AI lab to fast-track AI-native data center networking

May 21, 2026
Core42 raises USD 550 million from HSBC to scale global AI infrastructure

Core42 raises USD 550 million from HSBC to scale global AI infrastructure

May 21, 2026
Nairobi AI forum highlights growing Africa–Middle East cooperation on responsible AI

Nairobi AI forum highlights growing Africa–Middle East cooperation on responsible AI

May 21, 2026

The most trusted source of strategic intelligence for IT decision makers in the Middle East.

About

  • About Us
  • Advertising
  • Digital Magazine
  • Supplements
  • Media Pack
  • Contact Us

Policies

  • Privacy Policy
© 2025 – CXO Insight Middle East. All Rights Reserved.
Facebook-f X-twitter Linkedin
Separated they live in Bookmarksgrove right at the coast of the Semantics, a large language ocean. A small river named Duden.

About

  • About Us
  • Site Map
  • Contact Us
  • Career

Policies

  • Help Center
  • Privacy Policy
  • Cookie Setting
  • Term Of Use

Join Our Newsletter

© 2024 – CXO Insight Middle East. All Rights Reserved.

Facebook-f Twitter Youtube Instagram

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Join our mailing list
Sign up here to get the latest news, updates and special offers delivered directly to your inbox.
No Result
View All Result
  • News
  • Opinions
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
  • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Awards
      • 2025
      • 2024
      • 2023
    • Channel Insights Summit 2025
    • Webinars
    • CX50 Oman
    • CXO50
      • 2026
      • 2025
    • ICT Awards
      • Dubai
      • Saudi Arabia
    • Cyber Strategists Summit
      • 2026
      • 2025
      • 2024
      • 2023
      • 2022
      • 2021
    • Cloud Connect 2025
    • All events
  • Videos
  • GITEX x AI Everything
  • Digital Magazine

© 2025 - CXO Insight Middle East. All Rights Reserved.