For nineteen years, stolen credentials were the most common way a breach started. In Verizon’s 2026 Data Breach Investigations Report, that changed — and it should change how a small business thinks about security spending, because it means the front door isn’t where the fight is anymore.
31%
of breaches now start with vulnerability exploitation
Up from third place — now the single largest vector
50%
of ransomware victims had a credential or infostealer event first
Within the preceding 95 days
~40%
higher success rate for phone-based social engineering
Compared with email campaigns
The entry point is no longer predictable
For years the advice was essentially “train people not to click.” That advice is still worth following, but look at how the numbers now spread out.
| Category | Share of breaches |
|---|---|
| Vulnerability exploitation | 31% |
| Phishing | 16% |
| Credential abuse | 13% |
| Pretexting | 6% |
No single vector is even a third of the problem. An attacker who can’t phish you will exploit an unpatched edge device instead. One who can’t do that will buy credentials someone else stole. You cannot pick one door to guard.
Two details in the same report make the picture sharper:
- Half of ransomware victims had a credential or infostealer event within 95 days before the attack. The ransomware wasn’t the beginning. It was the end of a process that had been running for weeks.
- Phone-based social engineering is succeeding at roughly 40% higher rates than email campaigns. Your email filter does not see a phone call.
Why this argues for detection over prevention
If you can’t reliably predict how they get in, the useful question becomes what happens in the hours and days after they do.
That gap is what endpoint detection and response covers. Traditional antivirus asks “is this file known to be bad?” — which works for malware already in circulation and fails on anything new. EDR asks a different question: what is this process actually doing?
An attacker who exploits an unpatched service still has to do recognisable things afterwards: enumerate the network, dump credentials, disable backups, start encrypting files. Those behaviours look wrong regardless of how the attacker arrived, and regardless of whether any file involved has been seen before.
That 95-day window is the practical argument. In half of ransomware cases there was something to catch, for weeks, before the damage. Prevention had already failed by then. Detection was the remaining chance.
Being honest about what EDR does not fix
The same DBIR finding cuts against over-selling this. If 31% of breaches start with an exploited vulnerability, then patching is not optional and no endpoint product replaces it. EDR is what catches the intrusion you failed to prevent — it is not a reason to stop preventing.
What a small business should actually do
In rough order of return on effort:
-
Patch anything internet-facing Do this first
This is now the top vector at 31%. Nothing else on this list beats it, and it costs nothing but attention.
-
Turn on MFA everywhere
Prefer app or hardware factors over SMS — while remembering that MFA fatigue attacks target the human, not the token.
-
Keep backups you have actually restored from
An untested backup is a hypothesis, not a backup. Restore one this quarter and find out.
-
Run EDR on every endpoint
So the intrusion that gets past the first three has something watching it, and so an attack can be rolled back rather than just cleaned up.
-
Assume credentials leak
Half of ransomware victims had an infostealer event first. Treat a credential alert as an early warning, not a nuisance.
If you’re weighing whether that fourth item is worth paying for, we wrote a separate honest comparison of EDR against consumer antivirus, including the cases where Microsoft Defender is the right answer and you shouldn’t pay us anything.
Figures in this post are from Verizon’s 2026 Data Breach Investigations Report. We license SentinelOne to small businesses at $7–$10 per endpoint per month with no seat minimum — see pricing.