Threat Briefing

TrendAI 2026 Cyber Risk Report: Global cyber risk index improves for the second consecutive year, yet enterprises remain mired in the medium-risk range.

Based on the TrendAI 2026 Cyber Risk Report, this provides an in-depth analysis of changes in the global enterprise cyber risk index, industry risk rankings, identity and configuration issues, and offers defense recommendations for enterprise security leaders.

Global Cyber Risk Index Improves for Second Consecutive Year, but Enterprises Remain Stuck in Medium-Risk Zone: Analysis of the TrendAI 2026 Cyber Risk Report

Lead: Global enterprises' cybersecurity risk levels showed a second consecutive year of improvement in 2025, but worryingly, nearly all organizations under telemetry remained in the medium-risk zone, meaning there is still a structural gap from "safe." The TrendAI 2026 Cyber Risk Report, released on July 8, 2026, is based on extensive telemetry data from TrendAI Vision One Cyber Risk Exposure Management (CREM), XDR, and global threat intelligence, providing CISOs and security teams with a year-round picture of risk exposure, identity hygiene, and configuration vulnerabilities. This report is not just a set of numbers; it also reveals the long-term hazards enterprises are planting during cloud migration, identity management, OT digitalization, and zero trust implementation.

Event Overview: An Annual Risk Profile Based on Global Telemetry

The TrendAI 2026 Cyber Risk Report is TrendMicro's flagship annual report under TrendAI Research, with data primarily coming from telemetry collected in customer environments throughout 2025. The report's core metric—the Cyber Risk Index (CRI)—aggregates scores from different assets and risk factors into a value from 0 to 100, directly reflecting an organization's overall security risk. In addition to CRI, the report also introduces, for the first time, attack path prediction data from the TrendAI Vision One Attack Path Prediction capability, attempting to add a forward-looking perspective to the annual risk statistics. Report download link: TrendAI 2026 Cyber Risk Report.

The report clearly states that these data are not statistically representative samples of any industry or region, but rather observations from the customer base, intended to provide directional signals. This means that when interpreting specific rankings, we should view them as trend references rather than industry benchmarks.

Technical and Risk Analysis: Structural Hazards Behind the Improvement

Global Risk Index: Declining but Not Out of DangerIn 2025, the global average CRI fell from 38.5 in 2024 to 35.8, continuing the improvement trend that began in 2023. However, the path of improvement has not been smooth: the CRI rebounded to 37.4 in April, dropped to a low of 34.1 in July, and then rose again to 36.7 at the end of the year. This pattern of volatility stands in stark contrast to the continuous downward curve seen in 2024, possibly indicating that many organizations are reactively responding to risk events rather than systematically advancing risk governance. More notably, all organizations participating in telemetry in the report still fell within the “medium risk” range of 31 to 69, and no organization entered the “low risk” band. In other words, despite the improving overall numbers, no company has truly reached the security baseline.

Industry Risk Ranking: Infrastructure and Healthcare Continue to Face Pressure

By industry, mining, healthcare, agriculture, telecommunications, education, government, and utilities were among the top ten risk sectors. Mining ranked first for the first time with a CRI of 42.5, closely linked to the rapid advancement of OT (operational technology) digitalization at remote sites. The speed of attack surface expansion has clearly outpaced the deployment of security controls. Risk events in the mining industry were dominated by email threats, rather than the cloud application access commonly seen in other industries, suggesting that targeted phishing may be the primary initial intrusion vector. Meanwhile, suboptimal endpoint sensor configurations mean these organizations may have significant security detection blind spots.

The healthcare industry ranked in the top three for the second consecutive year with a CRI of 40.3. Among its vast device assets, many run software that cannot be patched without affecting continuity of patient care or without regulatory approval. 2024 data already showed that the average patching time in the healthcare industry was as high as 41.5 days, the slowest across all industries. Among risk events in healthcare, cloud application access risks remained high, and device control settings had numerous misconfigurations, reflecting that cloud-based clinical tools are being adopted rapidly while the corresponding governance frameworks have not kept up.

The agricultural industry also recorded a CRI of 40.3, with its primary risk events dominated by data loss prevention (DLP) violations. Given agriculture's increasing reliance on precision agriculture technologies and connected machinery, this likely means that sensitive supply chain and operational data are leaking through poorly regulated channels. The high incidence of misconfigured device control settings is also consistent with the expansion of IoT and automated equipment.

The telecommunications industry entered the top five for the first time with a CRI of 39.9. Its transformation driven by 5G deployment, cloud-native architecture, and software-defined infrastructure exposes it to multiple security challenges. It is also the only industry in the top five where both inbound email policy violations and outbound data loss prevention failures are simultaneously high, meaning its risks affect not only itself but also the customers and critical infrastructure that rely on its services.Although the education industry ranks fifth with a CRI of 39.8, it recorded the greatest improvement of all industries, falling from 45.1 at the start of 2024 to 39.8. Four of its top five risk events are directly identity-related, including stale accounts, disabled MFA, disabled password expiration, and disabled strong passwords. The high mobility of students and faculty makes identity governance a persistent challenge.

In addition, the government and public services sector has a CRI of 39.7, long affected by lengthy procurement cycles, numerous legacy systems, and a distributed workforce; the communications industry fell to 39.3, but its XDR detections of "possible antivirus software disablement" events remain high, suggesting that once attackers gain entry, they are actively crippling endpoint protections. The financial services industry has a CRI of 38.9. Despite strict regulation, disabled MFA accounts remain highly prevalent, exposing the gap between policy requirements and operational execution. Utilities also have a CRI of 38.9 and entered the top ten for the first time; the convergence of OT and IT networks is exposing industrial control systems—designed for reliability rather than security—to threats. The insurance industry has a CRI of 38.8, with the governance complexity of multi-cloud environments (including GCP) slowing remediation speed.

Enterprise Size: Mid-Sized Enterprises Become the Risk Hotspot

The report reveals a counterintuitive phenomenon: mid-sized enterprises with 5,001 to 10,000 employees have an average CRI as high as 41.5, surpassing that of larger enterprises with greater asset scale. This group has network complexity comparable to that of large enterprises, but often lacks a correspondingly mature security operations center and depth of staffing. The largest enterprises achieved the greatest absolute improvement, dropping 3.8 points from 44.2 in 2024 to 40.4, likely benefiting from economies of scale brought by centralized risk management. Meanwhile, small enterprises with fewer than 100 employees were the only size segment where CRI rose year over year, increasing from 31.6 to 32.4. Although their absolute risk values remain in the moderate range, the upward trend aligns with attackers' increased focus on SMBs as entry points into supply chains.

Risk Events: Identity and Cloud Access Dominate the Ranking for the Second Time

In the risk event ranking, "risky cloud application access" ranked first for the second consecutive year, and "Microsoft Entra ID stale accounts" ranked second. Seven of the top ten events are directly identity-related, including "disabled MFA accounts" at fourth and "password expiration disabled" at seventh/ninth. The high degree of overlap for two consecutive years shows that security teams are aware of identity risks but have failed to translate that awareness into systematic remediation actions. Zero Trust Security Access (ZTSA) rule matching—private access control—entered the top five for the first time. This may indicate that as enterprises expand zero-trust adoption, previously undetected policy violations are beginning to surface. However, stale accounts and MFA deficiencies remain widespread, presenting a dangerous misalignment: zero-trust frameworks are being deployed on top of an identity foundation that has not yet been cleaned up.

Configuration Errors: A Systematic Lack of Security Baselines 配置问题方面,端点配置错误列表以Web信誉设置为主,而在医疗和农业等行业中,设备控制设置成为最常见的错误配置。这些错误不只影响端点,还可能削弱DLP、防病毒等关键控制的有效性,为攻击者留下可乘之机。

企业影响分析:风险数据背后的业务含义

  • 运营风险:中型企业的高CRI意味着它们在网络攻击面前更脆弱。一次成功的勒索软件或钓鱼攻击就可能中断其核心业务流程,而它们缺乏大型企业的冗余和应急资源。对于采矿、公用事业等OT密集行业,攻击甚至可能危及物理安全。
  • 财务风险:报告指出,小企业风险上升与供应链攻击趋势相吻合。任何中小供应商的失守都可能成为攻击者进军大型客户网络的跳板,进而导致赔偿、罚款和业务损失。对于被当作入口的中小企业,其财务和声誉损失可能更为直接。
  • 合规风险:医疗和金融业长期受到严格监管,但MFA和修补问题依然突出。这说明满足合规审计和应对真实威胁之间,存在一个执行力的鸿沟。监管机构正在加强对身份管理和供应链安全的审查,这些发现可能成为下一次合规检查时的问责证据。
  • 品牌风险:电信和医疗行业的高风险直接影响公众利益。这些行业一旦遭遇数据泄露,往往引发公众信任危机和监管制裁。教育行业则因学生数据的高敏感性,任何身份账户的失守都可能导致大规模隐私事件。
  • 数据风险:农业行业DLP违规的集中出现,提示供应链数据、产量数据等商业机密的保护不足。通信行业同时存在入站攻击和出站泄露,表明其不仅面临入侵威胁,还要解决内部数据外流问题。

行业趋势观察:身份卫生、零信任与OT扩张

这份报告揭示的趋势并非孤立事件,而是至少三大长期变化的交叉点:1. Identity security has become a core variable in enterprise risk. Identity incidents topping the charts for two consecutive years shows that the failure of traditional perimeter defenses has forced attackers to turn to account abuse. A new generation of identity security architectures (such as ID-first security) must shift from "cleanup after the fact" to "clean by design." 2. Zero trust is an amplifier, not a panacea. ZTSA's entry into the top five demonstrates the prevalence of zero trust deployments, but it also exposes the inadequacy of underlying identity hygiene. Without identity governance, zero trust's "never trust" can only become "always false positives." 3. OT/IT convergence is stacking new and old risks on infrastructure industries. The rising rankings of mining, utilities, and agriculture reflect the inevitable trend of digitalization extending from offices to production sites. These industries must combat traditional cyberattacks while also addressing vulnerabilities specific to IoT and industrial control systems.

Defense and Response Recommendations: From Data to Action

Based on the report's findings, enterprises should take action at the following four levels:

I. Identity Governance: Fix the Most Basic Risks

  • Immediately conduct account audits to clean up all zombie accounts, accounts of departed employees, and third-party integration accounts.
  • Enable MFA comprehensively, especially on cloud applications, remote access, and administrator accounts. Do not compromise on "privileged" accounts.
  • Reassess password lifecycle policies to ensure alignment with NIST guidelines, and use conditional access policies to detect anomalous logins.

II. Zero Trust Implementation: Clean Up Before Connecting

  • Before expanding ZTSA coverage, address dormant accounts and disabled MFA first; otherwise zero trust policies may be bypassed by invalid identities.
  • Combine zero trust policies with asset discovery and attack path prediction, prioritizing protection of critical data and highly privileged accounts.

III. Configuration Hardening and Visibility

  • Conduct baseline audits of endpoint configurations, prioritizing remediation of risks such as web reputation settings, device control settings, and disabled antivirus.
  • Optimize EDR/XDR sensor settings to ensure full log coverage and eliminate detection blind spots. For OT environments, asset discovery and anomalous behavior detection tailored to industrial protocols can be introduced.

IV. Targeted Plans for Weak Links

  • Mid-sized enterprises: refer to mature frameworks used by large enterprises, but adopt on-demand models such as managed security services (MDR) based on actual budgets to compensate for insufficient staffing.
  • Healthcare and mining: establish OT security teams or bring in external assessments; isolate systems that cannot be patched and apply virtual patching, while strengthening email security gateways and DLP.
  • Supply chain: SMBs should deploy basic endpoint protection and DLP, while large enterprises should incorporate supplier security assessments into their procurement processes.

SecurityPost InsightThe true value of the TrendAI 2026 Cyber Risk Report lies not in proving that "risk is declining," but in clearly pointing out that "decline does not equal safety." The fact that all organizations fall within the medium-risk range shows that the industry's baseline is still too low. The most glaring data in the report is that identity issues have topped the list for two consecutive years—this is not a technical challenge, but a failure of management and execution. As advanced architectures like Zero Trust begin to spread, while underlying identity hygiene remains unresolved, this "new clothes, old lining" mismatch is likely to translate into more attack vectors in the future. Mid-sized enterprises need special attention—they are not small in scale yet lack security maturity, making them the preferred prey of attackers. The report also previews the future inclusion of AI-related risk data. It can be expected that the 2027 report will more clearly outline how AI is changing the attack and defense landscape. For enterprises, now is the time to put identity cleanup, configuration hardening, and OT security on the agenda, because the window period in which the risk index improves is precisely the golden time to harden defenses.

---

Source: TrendAI 2026 Cyber Risk Report - TrendMicro

Evidence route · securitypost

securitypost frames this note through Security Post publishes defensive cybersecurity intelligence for enterprise security leaders, covering thre.... Threat Briefing / Enterprise Security / AI & Cybersecurity explains the local editorial angle: Source links should be opened before the summary is reused. dates, names and status changes still need checking.

Source URL

  1. https://www.trendmicro.com/vinfo/us/security/research-and-analysis/threat-reports/roundup/trendai-2026-cyber-risk-reportPrimary

Related articles

Back to channel