Sophos’s 2026 Active Adversary Report provides useful incident-response and managed-detection evidence, but its percentages belong to the cases Sophos analyzed. They are not a census of every breach worldwide.
Current as of 2026-08-15
Sophos’s report article says 67.32% of root causes in its 2025 dataset were identity-related. Sophos’s press release says the report analyzed 661 IR and MDR cases handled from November 1, 2024 through October 31, 2025 across 70 countries and 34 industries.
Decision summary
- Keep 67.32% attached to Sophos’s 661-case dataset.
- Prioritize credential, brute-force, phishing, token, and trusted-relationship controls.
- Use identity and endpoint telemetry together.
- Do not convert one vendor’s case mix into a universal probability.
What the dataset says
Sophos groups compromised credentials, brute force, credential phishing, authentication-token theft, and trusted relationships as identity-related root causes. The report says this combined category represented 67.32% of root causes in the cases it could analyze.
What the dataset does not say
The dataset reflects organizations that reached Sophos IR or MDR and had usable evidence. It does not prove that 67.32% of all incidents everywhere share the same root cause, or that any one control would have prevented every case.
Translate the finding into controls
- Phishing-resistant MFA for privileged and high-risk access.
- Monitoring for credential attacks, suspicious token use, and authentication-method changes.
- Least privilege and time-bound administration.
- Fast disable, session revocation, and recovery workflows.
- Endpoint and network visibility to detect activity after login.
Measure your own exposure
Track MFA coverage, legacy authentication, stale accounts, privileged-role duration, service-account ownership, risky sign-ins, session-revocation time, and the percentage of critical identity events visible to responders. Those environment measures are more actionable than repeating a market statistic.
Next step for your environment
Run an identity control review that produces tenant-specific coverage and remediation owners. If you need a documented baseline before changing production systems, start with an ITECS technology and security assessment.
Record the current baseline, accountable owner, source date, acceptance evidence, exceptions, and review trigger. Recheck assumptions before every consequential change, preserve rollback instructions, and close the work only when the intended result and unintended effects have been verified in the real environment. Keep the decision record with the system documentation so the next review starts from evidence rather than memory.
Sources and update trigger
Review trigger: Review with each new Active Adversary Report or methodology update.
continue reading
More ITECS blog articles
About ITECS Team
The ITECS team consists of experienced IT professionals dedicated to delivering enterprise-grade technology solutions and insights to businesses in Dallas and beyond.
View full profile and articles