Key Findings

  • Released by Sophos on Tuesday,the 2026 State of Identity Security Reportshows that over the past year, 7 out of 10 organizations experienced at least one identity-related breach. Surveyed companies reported an average of three separate identity-related incidents.

  • Sophos noted that two-thirds of ransomware victims said their attacks originated from identity-related events. The report is based on a survey of 5,000 IT and cybersecurity leaders across 17 countries.

  • The report shows that the average recovery cost of an identity breach is $1.64 million, with a median of $750,000. Seven out of ten respondents reported recovery costs exceeding $250,000.

In-Depth Analysis

The report highlights the growing role of identity in modern enterprise security. Chester Wisniewski, Sophos's Global Field CISO, told Cybersecurity Dive via email: "Identity has become the perimeter of cybersecurity, and that perimeter is expanding faster than most organizations can track. With the acceleration of cloud adoption, remote work, and machine-to-machine connections, every credential, API key, service account, and OAuth token can become a potential entry point."

Wisniewski said attackers are increasingly using identity as a primary attack vector because it allows them to bypass traditional security defenses, move laterally within systems, and access sensitive data more quickly.

Identity-related cyberattacks also affect critical industries. The report shows that oil and gas and utility companies reported the highest attack rates, followed by government agencies.

The report notes that successful identity attacks primarily stem from human error and inadequate management of non-human identities. Only 24% of organizations regularly monitor for anomalous logins, and fewer than one-third regularly rotate non-human credentials.