Updated: 6 July 2026
What is the Verizon DBIR and why does it matter to your organisation? The Data Breach Investigations Report (DBIR) is Verizon’s annual analysis of thousands of confirmed security incidents and data breaches worldwide. It is widely treated as one of the most reliable sources of security statistics and a useful reference point for CISOs, boards, and regulators when making cybersecurity investment decisions. Instead of reacting to headlines, DBIR shows what actually compromises organisations – not what attacks them only in theory.
Cyber threats 2025 – key takeaways:
- According to Verizon DBIR 2024, the human element was present in 68% of breaches – phishing, errors, and privilege misuse continue to outweigh purely technical attacks
- Ransomware was present in 32% of breaches (DBIR 2024), while the median ransom payment rose to USD 46,000, with many cases reaching millions
- Exploitation of vulnerabilities as an initial access method increased by 180% year over year (DBIR 2024), mostly through CVEs in VPN and firewall software
- 15% of breaches involved third parties such as suppliers and partners, a 68% year-over-year increase that reflects the growth of supply chain attacks
- Financial services and insurance remain the most frequently attacked verticals, but attacks on manufacturing and retail are growing fastest
- Patronusec, as an accredited QSA and vCISO partner, helps organisations translate DBIR data into concrete priorities: from gap analysis to penetration testing programmes and anti-fraud training
Table of Contents
How does the human element in 68% of breaches change security programme priorities?
If 68% of breaches involve a human component, investing only in technical tools is inefficient. DBIR defines the human element as errors, such as misconfiguration or misdelivery of data; privilege misuse, such as insider activity; and social engineering, including phishing, pretexting, and vishing.
What this means in practice for budget and security planning:
Security training must be regular, not a once-a-year exercise. DBIR has consistently shown that annual one-off training has limited impact on employee behaviour. Effective programmes include monthly phishing simulations with immediate feedback, role-specific training for finance, IT, and management, and measurement of suspicious email reporting rates, not only click rates.
Identity and access management deserves the same priority as firewalls. Insider misuse and stolen credentials appear together across many DBIR breach categories. MFA, least privilege, and regular access reviews are simpler and cheaper than most threat detection tools.
Verification processes are security controls, just like technology. MGM Resorts lost more than USD 100 million in 2023 not because of a technical exploit, but through a helpdesk call in which an attacker persuaded an employee to reset MFA. Process controls such as identity verification and two-person approval for privileged changes are often missing from tool-heavy security programmes.
Patronusec Insight: In vCISO engagements, we regularly see the same pattern: an organisation has advanced EDR, SIEM, and DLP tooling, but no documented identity verification process for MFA resets and no helpdesk procedure for “urgent” account unlock requests. These process gaps are exactly what social engineering exploits. A security programme needs both tools and processes. Without both, it remains exposed. We discuss this during a free vCISO consultation.
How should ransomware in 32% of breaches change backup and recovery strategy?
Ransomware is no longer an exotic attack. It is a standard operational risk, comparable to a fire in a server room. DBIR 2024 shows that 32% of breaches involved ransomware, and the median ransom payment rose to USD 46,000, with a typical distribution that includes much larger cases.
Three DBIR lessons for backup strategy:
First, backups must be offline or immutable. Attackers know that backups are the first recovery target. A backup connected to the production domain is encrypted along with everything else. The 3-2-1 rule (3 copies, 2 media types, 1 off-site copy) must be supplemented by isolation from the production network.
Second, recovery testing is mandatory. A backup that has never been restored is a hypothesis, not a control. Sophos State of Ransomware 2024 showed that organisations with tested backups recover much faster. The difference between 22 days of downtime and a few days often comes down to this.
Third, Recovery Time Objective must be defined for every system. When ransomware hits, the question “how quickly do we need to restore this system?” cannot be improvised. A Business Impact Analysis and documented RTOs are not paperwork. They are decisions that need to take seconds in a crisis, not weeks.
Do you know whether your backup and recovery strategy would survive a ransomware attack?
Patronusec reviews business continuity and recovery strategies as part of the vCISO service. Within 2-3 weeks, we deliver a gap assessment and action plan from the perspective of what actually blocks organisations during an incident.
Discuss BCM strategy with an expert
How does a 180% increase in vulnerability exploitation change vulnerability management priorities?
DBIR 2024 recorded a 180% year-over-year increase in exploitation of vulnerabilities as an initial access method. Most of these exploits involved publicly known CVEs in edge systems: VPNs, firewalls, and remote access gateways.
What this means:
Patch prioritisation must be risk-based, not CVSS-only. A CVE with CVSS 9.8 on a system isolated from the internet is less urgent than a CVE with CVSS 7.5 on a public VPN gateway. Vulnerability management must account for system exposure, not only vulnerability severity.
Edge systems deserve the highest priority. VPNs, firewalls, remote access systems, and public web applications are preferred entry points because they are reachable from the internet and often follow slower patch cycles than internal servers.
Vulnerability scans must cover the external attack surface. Organisations often scan internal infrastructure while lacking visibility into what is exposed to the internet. External Attack Surface Management (EASM) is becoming a core part of the security programme.
Patronusec Insight: Regular vulnerability scans of external systems are the minimum, but scans alone are not enough. A scanner says: “this port is open and this version has CVE-X.” A penetration test says: “this vulnerability gives full access to the internal network within 20 minutes.” These two findings lead to fundamentally different priority decisions. We deliver penetration testing focused on real attack paths, not only CVE lists.
How do growing supplier attacks (15% of breaches, +68% year over year) change TPSP management?
The growth of supplier and supply chain attacks is one of the most concerning trends in DBIR 2024. MOVEit in 2023 – one product affecting more than 2,700 organisations – is an extreme example, but it reflects a broader trend.
Implications for supplier management:
Every organisation must know which supplier systems have access to its environment or data. This sounds obvious, but many companies do not have a current TPSP inventory with access scope documented.
Supplier security questionnaires must ask about specific controls, not only certificates. “Do you have ISO 27001?” is a weaker question than “How quickly do you patch critical CVEs in internet-facing systems?” or “What is your MTTD for security incidents?”
The division of responsibility between you and the supplier must be documented. PCI DSS v4.0.1 Requirement 12.8.5 and ISO 27001 section 8.4 make this explicit. Even outside regulation, knowing “who protects what” is critical during incident response.
How can DBIR data be translated into concrete budget priorities?
DBIR gives empirical data that can be used directly to justify security budget decisions to the board.
Prioritisation based on DBIR 2024:
| Threat (DBIR 2024) | Priority controls | Estimated cost |
|---|---|---|
| Human element in 68% of breaches | Training programme, phishing simulations, helpdesk procedures | PLN 10,000-30,000/year |
| Ransomware in 32% of breaches | Immutable backup, recovery testing, IR plan | PLN 20,000-80,000 once |
| Vulnerability exploitation +180% | Quarterly scans, annual pentest, patch prioritisation | PLN 30,000-80,000/year |
| Supplier attacks +68% | TPSP inventory, security questionnaire, Responsibility Matrix | PLN 5,000-20,000/year |
How to present this data to the board:
Boards understand financial risk, not technical risk. Instead of saying “our firewalls are outdated,” say: “According to DBIR 2024, organisations without current patches on edge systems face materially higher risk of compromise through vulnerability exploitation. For a company with PLN 50 million in revenue, and an average breach cost of USD 4.88 million (IBM 2024), the residual risk of not patching is X.”
FAQ – Cyber Threats 2025 and Verizon DBIR
Does Verizon DBIR apply only to large enterprises?
No. DBIR analyses incidents across organisations of all sizes. In fact, DBIR reports consistently show that small and mid-sized businesses are disproportionately affected by financially motivated attacks because they have fewer defensive resources and attackers know their success probability is higher.
How often should I update my security programme based on DBIR?
DBIR is published annually, usually in May. Good practice is to review security programme priorities once a year based on the new report, ideally in sync with the annual management review required by ISO 27001. Between DBIR editions, it is worth following quarterly threat intelligence from ENISA, CERT Polska, or security vendors.
Which other threat intelligence reports are worth tracking alongside DBIR?
Alongside DBIR, useful sources include IBM X-Force Threat Intelligence Index, especially for breach costs; Mandiant M-Trends, especially for APT techniques; ENISA Threat Landscape, especially for European and regulatory perspective; and Proofpoint State of the Phish, especially for phishing and BEC. Each source gives a different view of the threat landscape.
How does ransomware affect PCI DSS and ISO 27001 requirements?
PCI DSS v4.0.1 requires a documented incident response plan (Requirement 12.10) and annual testing of that plan. ISO 27001 requires incident management (Annex A controls A.5.24-A.5.28) and business continuity readiness (A.5.29-A.5.30). Ransomware is the most likely incident scenario auditors will ask about in both standards.
How does Patronusec help organisations respond to DBIR threats?
In the vCISO model, we help translate DBIR data into 30-, 90-, and 180-day priorities. We also deliver concrete projects: vulnerability scans and penetration tests for technical threats, phishing programmes for human-factor risks, and TPSP management reviews for supply chain exposure.
What does a security programme maturity assessment cost at Patronusec?
A gap analysis against NIST CSF, ISO 27001, or PCI DSS requirements is priced individually after a free introductory call. For organisations without a formal security programme, we often recommend starting with the vCISO service. The monthly cost is usually lower than a one-off gap analysis project and provides ongoing support instead of a report that sits in a drawer.
Cyber threats in 2025 – free consultation
Patronusec helps organisations translate threat intelligence reports into a concrete security programme, from priority setting to control implementation and certification. As an accredited QSA and vCISO partner, we work with financial services, fintech, e-commerce, and retail organisations.
In a free 30-minute consultation, we will help you:
- Assess which DBIR threats are most relevant to your sector and business model
- Identify the most important gaps in your current security programme
- Plan 12-month priorities with concrete budget justification for the board
- Choose a support model aligned with your resources: project-based support or ongoing vCISO
Free consultation | vCISO | Penetration testing | Vulnerability scans | ISO 27001