Security

2025's Breach Landscape - What CIOs Should Actually Do Differently

January 3, 2026 · 7 min read

2025 was brutal for cybersecurity. Sixteen billion credentials leaked. The largest crypto heist in history. Ransomware took down major retailers. Healthcare systems compromised at scale. If you're a CIO heading into 2026, here's what actually matters - not the vendor pitch, not the compliance checkbox, but the practical reality of defending an enterprise.

2025's Breach Landscape

The Numbers That Should Scare You

Let's start with the headline: researchers discovered 30 exposed datasets containing over 16 billion login credentials. That's not a typo. Sixteen billion. Aggregated from years of infostealers, previous breaches, and poor password hygiene across every major platform. Google, Apple, Facebook, GitHub, government services. If your users reused passwords anywhere, assume those credentials are compromised.

The Bybit heist netted $1.4 billion in cryptocurrency. Linked to North Korea's Lazarus Group, it demonstrated that nation-state actors are happy to fund their operations through commercial targets. The Salesforce ecosystem attacks exposed potential data from thousands of organizations through third-party integrations. The M&S ransomware attack disrupted retail operations for weeks.

This isn't theoretical anymore. This is the operating environment.

Third-Party Risk is the New Frontline

The pattern across 2025's major breaches is clear: attackers aren't breaking down your front door. They're coming through your vendors, your integrations, your SaaS ecosystems. The Salesforce attacks exploited OAuth tokens and third-party services. The PowerSchool breach hit schools through their student information system provider. The M&S and Co-op attacks reportedly involved compromises of outsourced IT services.

Here's what this means practically. Your security is only as good as your weakest vendor. That small software company handling a non-critical function? They're a path into your environment. That integration you set up three years ago and forgot about? It's still authenticated.

What to do:

  • Audit every third-party connection to your environment. Yes, all of them.
  • Review OAuth tokens and API keys. Rotate anything you can't justify.
  • Require security assessments for vendors with data access, not just the big ones.
  • Monitor for anomalous activity in integrations, not just in your own systems.

Identity is Everything

Credential theft was the entry point for the majority of significant breaches in 2025. Once attackers have valid credentials, they're no longer attackers. They're authenticated users. Your perimeter defenses don't matter. Your endpoint detection struggles. They look legitimate until they don't.

The Coinbase breach came through a compromised support contractor. Insider threats, whether malicious or compromised, bypassed technical controls because the humans had access.

What to do:

  • MFA everywhere. Phishing-resistant MFA where possible. FIDO2 keys for privileged accounts.
  • Conditional access policies that consider context, not just authentication.
  • Regular access reviews. Not annual, quarterly at minimum.
  • Zero trust architecture where practical. Verify continuously, not just at login.
  • Offboarding procedures that actually work. Terminated employees shouldn't have access tomorrow, let alone months later.

Ransomware Evolved Again

The 2025 ransomware landscape shifted toward data theft without encryption. Why bother encrypting when you can just steal the data and extort? This means your backup strategy, while still important, doesn't fully protect you. Even if you can restore, the attackers have your data. They'll threaten to leak it. They'll sell it. They'll use it to extort your customers.

The retail sector got hammered. M&S, Co-op, Harrods, Adidas. The attacks demonstrated that operational disruption plus data theft creates maximum leverage. Can't sell if your systems are down. Can't recover reputation if customer data leaks.

What to do:

  • Assume breach. Plan for data exfiltration, not just encryption.
  • Network segmentation that limits lateral movement.
  • Data classification. Know what's sensitive and where it lives.
  • Incident response plans that include public communications. You'll need them.
  • Cyber insurance that actually covers modern attack patterns.

The Help Desk Problem

Social engineering against help desks enabled several major breaches. The M&S attack, the Co-op incident, and others reportedly involved attackers convincing support staff to reset credentials or bypass security controls. The UK government issued specific guidance on this threat, which tells you how widespread it became.

Your help desk is trained to help. That's the vulnerability. They want to resolve tickets, make users happy, and move on. Attackers exploit that helpfulness.

What to do:

  • Verification procedures that actually work. Callback on known numbers. Manager approval for sensitive changes.
  • Training that includes realistic social engineering scenarios.
  • Limits on what help desk can do without additional authorization.
  • Monitoring for unusual help desk activity, especially around privileged accounts.

What I'm Doing at Julius Silvert

This isn't theoretical for me. I'm running security for a food distribution company with two locations, 60 trucks, and enough attack surface to give me insomnia. Here's our practical approach.

We run SentinelOne for endpoint detection. It's caught things our previous solution missed. Arctic Wolf handles our MDR because we don't have a 24/7 SOC internally. Palo Alto firewalls at the perimeter with proper segmentation internally. Microsoft Entra ID for identity with conditional access policies that actually do something.

We've handled two ransomware incidents in my career without paying ransom. The key both times was having functioning backups, tested recovery procedures, and leadership willing to ride out the storm rather than pay. That takes preparation before the incident, not during.

Most importantly, we treat security as a business function, not just an IT function. My board understands the risks in business terms. My CFO knows why we spend what we spend. When something happens, they're not surprised by the response plan because they helped build it.

What Vendors Won't Tell You

Every security vendor will tell you their product would have stopped whatever breach is in the news. Most of them are lying, or at least oversimplifying. The breaches that make headlines are usually multi-stage attacks that exploit multiple weaknesses. No single product stops a determined attacker with valid credentials and inside knowledge.

Defense in depth is not a marketing term. It's the reality. You need layers because individual layers fail. You need visibility because threats evolve. You need process because technology alone isn't enough.

The 2026 Priorities

If I had to pick three security priorities for a mid-market CIO heading into 2026:

  1. Identity hardening. MFA everywhere, access reviews, zero trust where feasible. This blocks the most common attack paths.
  2. Third-party visibility. Know your integrations, audit your vendors, monitor for anomalies in connected systems.
  3. Incident readiness. Have a plan, test the plan, update the plan. Include communications, legal, and leadership. Practice before you need it.

Everything else is secondary until these three are solid. You can buy all the tools you want, but if your identity hygiene is poor, your vendors are unmonitored, and your incident response is untested, you're waiting for a headline.

2025 showed us the playbook attackers are using. 2026 is our chance to adapt. The organizations that take this seriously will weather the storms. The ones that don't will be case studies for the next annual breach report.

Stay vigilant out there.

Planning an ERP modernization?

6 SAP-to-Dynamics conversions with zero business disruption. Let's discuss your project.

ERP Services Book a Call

If you’re a PE-backed operator or family-owned business working through similar technology and operations decisions, I’m always open to a conversation.

Schedule a CIO Strategy Conversation