Eliminate the mundane gaps fueling today’s record-breaking cyberattacks

How MSPs can close identity, endpoint and firewall blind spots before they trigger a cascade.

Eliminate Cybersecurity Gaps

For years, the cybersecurity industry has chased the next big thing in threat tech, often overlooking a sobering reality: attackers aren’t always using revolutionary tools to break in. Instead, they’re masterfully exploiting the mundane.

The latest findings from the Barracuda Managed XDR Global Threat Report reveal that the most devastating incidents of the past year weren’t the result of unbeatable malware, but rather simple security oversights, including unpatched firewalls, rogue endpoints and dormant identities.

Analysis of over two trillion IT events and 600,000 security alerts from 2025 shows that attackers are moving at an incredible pace. In the quickest case, the time from initial breach to complete ransomware encryption was only three hours. For managed services providers (MSPs), this signals the end of the reaction-based defense era. If you’re not detecting a threat as soon as it hits the network, you’ve already lost the race.

The identity crisis: when attackers log in instead of breaking in

The report confirms a fundamental shift in attacker tradecraft: the focus has moved from compromising systems to compromising identities. Identity-based attacks now lead the list of top detections, with Microsoft 365 anomalous logins and “impossible travel” alerts becoming the primary red flags for credential theft.

Once an attacker gains a foothold via a stolen credential, their first order of business is to escalate privileges. By joining high-risk security groups or granting themselves global administrator rights, they turn limited access into full sovereign control over the environment.

The ghost account risk: In one real-world incident, attackers breached a network using a “ghost” account created for a third-party vendor that was never deactivated after the contract ended. This single oversight allowed them to move laterally and eventually launch ransomware.

For MSPs, securing the identity perimeter is no longer optional. It requires:

  • Enforcing strict MFA: Moving beyond basic SMS to phishing-resistant authentication.
  • Continuous identity auditing: Regularly purging dormant accounts and monitoring for unauthorized changes to administrative groups.
  • Behavioral monitoring: Utilizing XDR tools to flag logins that deviate from a user’s typical patterns.

The anatomy of a breach: rogue endpoints and unpatched firewalls

One startling statistic from the 2026 report is that 100% of security incidents involved at least one unprotected or rogue endpoint. Attackers hunt for the one laptop, tablet or server that lacks an active security agent, using it as a blind spot to bypass corporate defenses.

Furthermore, 90% of ransomware incidents exploited firewalls through unpatched vulnerabilities (CVEs) or vulnerable accounts. Despite patches being available, the most detected vulnerability last year was a 13-year-old bug in outdated encryption, making this a clear reminder that set-it-and-forget-it is a recipe for disaster.

To counter these patterns, MSPs must prioritize:

  • Total asset visibility: You can’t protect what you can’t see. Implementing continuous scanning to identify rogue devices is critical.
  • Aggressive patch management: Prioritizing critical CVEs, particularly in edge devices like firewalls and VPNs, which are the primary gateways for ransomware.
  • Hardening remote access: Ransomware actors increasingly abuse legitimate remote management tools (RMM) and protocols such as RDP to blend into normal IT traffic.

Countering stealthy LOTL tactics and agentic AI

Attackers are becoming increasingly stealthy by using living-off-the-land (LOTL) techniques, such as leveraging legitimate tools like PowerShell to execute malicious commands. This makes detection difficult because the activity mirrors standard IT maintenance.

Looking ahead, the challenge will only intensify as agentic AI rises. These AI-driven systems can scan environments 24/7, identify weak configurations in minutes and rewrite malicious code on the fly to bypass defenses.

To stay ahead, MSPs must adopt a managed XDR model that offers 24/7/365 monitoring. By combining AI-driven detection with human expertise, you can identify subtle anomalies, for example, a PowerShell script reaching out to a suspicious domain, which may indicate an ongoing breach.

Futureproofing: from reactive support to continuous cyber resilience

The vulnerabilities being exploited are often the ones we consider “basic,” but their impact is anything but. By securing identities, enforcing 100% endpoint coverage and eliminating dormant exposures, MSPs can turn these open doors into a brick wall.

For more deep dives into the latest threat data, explore our full 2026 Managed XDR Global Threat Report and learn more about defending against AI-driven phishing.


×