|8 min read|Yvann Lièvre

DBIR 2026: 96% of Ransomware Victims Are SMBs, Now What?

The Verizon 2026 report puts vulnerability exploitation ahead as the top initial access vector and confirms ransomware mainly hits SMBs. The concrete actions.

IOCThreat intelSMBVulnerabilities
DBIR 2026: 96% of Ransomware Victims Are SMBs, Now What?

Verizon's Data Breach Investigations Report, published on May 25, 2026, remains the most cited annual reference in the industry, and for good reason: it rests on the analysis of tens of thousands of real incidents. The 2026 edition delivers two findings that should reframe the priorities of any SMB. The first concerns initial access, the second concerns ransomware. Together they draw a clear roadmap.

Finding one: vulnerabilities overtake stolen credentials

For the first time in the report's history, vulnerability exploitation becomes the most common initial access vector, reaching 31 percent of breaches, up 55 percent from the previous year. This is a fundamental shift. For years, the dominant message was that credential theft, through phishing or password reuse, was the primary way in. That is no longer the case. Attackers now favor exploiting software flaws.

This shift comes with an observation on remote access. Analysis of initial access broker offerings shows that 44 percent of the connection types sold involve VPNs and 35 percent remote desktop applications. In other words, edge devices, VPNs, and remote access, are both the most exploited target and the most sold commodity on the access market. The earlier articles on this blog about SonicWall, Check Point, or SimpleHelp are not isolated cases: they are the trend itself.

Finding two: ransomware is an SMB problem

Ransomware was present in 48 percent of all breaches analyzed. And crucially, small and medium-sized businesses account for roughly 96 percent of ransomware victims for which organization size is known. That figure is worth pausing on. It contradicts the received idea that ransomware primarily targets large groups. The reality is that most campaigns are opportunistic: they target organizations with stolen credentials, unpatched vulnerabilities, or limited security resources. That is the typical profile of an SMB, not of a large enterprise with a security operations center.

Turning these numbers into concrete actions

A report is only worth what you do with it. Here is how an SMB can translate these two findings into operational priorities, in order.

First, exposure management takes precedence over vulnerability management alone. Since flaw exploitation is the top vector, and edge devices lead, the absolute priority is to know what you expose on the internet and to patch those devices first. An unpatched VPN or firewall is today, statistically, your biggest risk.

Second, prioritize by real exploitation, not by theoretical score. Not all vulnerabilities are equal. Those in CISA's Known Exploited Vulnerabilities catalog, or with a high EPSS exploitation probability score, must be handled before the rest, regardless of their raw CVSS score. Patch in the order of the real threat, not the order of the catalog.

Third, get fresh threat indicators. Since campaigns are opportunistic and fast, having an up-to-date indicator feed, IP addresses, domains, and hashes associated with ongoing campaigns, lets you block or detect an attack before it succeeds. This is especially true for an SMB without a dedicated team, which cannot run its own continuous threat monitoring.

The SMB blind spot: remote access

The through-line of the report, for a small organization, is that remote access has become the main battlefield. A remote employee, a provider connecting from outside, an exposed access server: each of these points is both essential to operations and coveted by attackers. The most cost-effective measure is therefore not necessarily the latest fashionable security tool, but the discipline of patching edge devices quickly and monitoring what connects to them.

The DBIR 2026 findings are not a fate SMBs must accept, they are a priority list. Detecting and blocking opportunistic attacks rests on qualified, up-to-date indicators. That is what the ThreatClaw IOC feed provides: an indicator stream ready to feed your firewall or SIEM, to turn the findings of an annual report into daily defense.

Related articles