Reddit
CRIMZONHOST

Threat landscape

How attacks actually get in — and why EDR is the layer that catches them

For nineteen years, stolen credentials were the most common way a breach started. In Verizon’s 2026 Data Breach Investigations Report, that changed — and it should change how a small business thinks about security spending, because it means the front door isn’t where the fight is anymore.

31%

of breaches now start with vulnerability exploitation

Up from third place — now the single largest vector

50%

of ransomware victims had a credential or infostealer event first

Within the preceding 95 days

~40%

higher success rate for phone-based social engineering

Compared with email campaigns

The entry point is no longer predictable

For years the advice was essentially “train people not to click.” That advice is still worth following, but look at how the numbers now spread out.

How breaches start, 2026
Category Share of breaches
Vulnerability exploitation 31%
Phishing 16%
Credential abuse 13%
Pretexting 6%
Verizon 2026 Data Breach Investigations Report.

No single vector is even a third of the problem. An attacker who can’t phish you will exploit an unpatched edge device instead. One who can’t do that will buy credentials someone else stole. You cannot pick one door to guard.

Two details in the same report make the picture sharper:

  • Half of ransomware victims had a credential or infostealer event within 95 days before the attack. The ransomware wasn’t the beginning. It was the end of a process that had been running for weeks.
  • Phone-based social engineering is succeeding at roughly 40% higher rates than email campaigns. Your email filter does not see a phone call.

Why this argues for detection over prevention

If you can’t reliably predict how they get in, the useful question becomes what happens in the hours and days after they do.

That gap is what endpoint detection and response covers. Traditional antivirus asks “is this file known to be bad?” — which works for malware already in circulation and fails on anything new. EDR asks a different question: what is this process actually doing?

An attacker who exploits an unpatched service still has to do recognisable things afterwards: enumerate the network, dump credentials, disable backups, start encrypting files. Those behaviours look wrong regardless of how the attacker arrived, and regardless of whether any file involved has been seen before.

That 95-day window is the practical argument. In half of ransomware cases there was something to catch, for weeks, before the damage. Prevention had already failed by then. Detection was the remaining chance.

Being honest about what EDR does not fix

The same DBIR finding cuts against over-selling this. If 31% of breaches start with an exploited vulnerability, then patching is not optional and no endpoint product replaces it. EDR is what catches the intrusion you failed to prevent — it is not a reason to stop preventing.

What a small business should actually do

In rough order of return on effort:

  1. Patch anything internet-facing Do this first

    This is now the top vector at 31%. Nothing else on this list beats it, and it costs nothing but attention.

  2. Turn on MFA everywhere

    Prefer app or hardware factors over SMS — while remembering that MFA fatigue attacks target the human, not the token.

  3. Keep backups you have actually restored from

    An untested backup is a hypothesis, not a backup. Restore one this quarter and find out.

  4. Run EDR on every endpoint

    So the intrusion that gets past the first three has something watching it, and so an attack can be rolled back rather than just cleaned up.

  5. Assume credentials leak

    Half of ransomware victims had an infostealer event first. Treat a credential alert as an early warning, not a nuisance.

If you’re weighing whether that fourth item is worth paying for, we wrote a separate honest comparison of EDR against consumer antivirus, including the cases where Microsoft Defender is the right answer and you shouldn’t pay us anything.


Figures in this post are from Verizon’s 2026 Data Breach Investigations Report. We license SentinelOne to small businesses at $7–$10 per endpoint per month with no seat minimum — see pricing.

Written by Josh Lytle. Questions? Email support@crimzonhost.com.