Alice in Supply Chains

← Alice in Supply Chains19 mei · 1 u 08 min

Bonus Episode with Special guest Alex Pinto | DBIR 2026

Bonus Episode with Special guest Alex Pinto | DBIR 202619 mei1 u 08 min

<p>In this special interview episode, <a href="https://www.linkedin.com/in/adrian-sanabria/" target="_blank" rel="noopener noreferer">Adrian</a> and <a href="https://www.linkedin.com/in/sieira/?skipRedirect=true" target="_blank" rel="noopener noreferer">Alexandre</a> sit down with <a href="https://www.linkedin.com/in/alexcpsec/" target="_blank" rel="ugc noopener noreferrer">Alex Pinto</a>, lead author of the Verizon Data Breach Investigations Report, to walk through the 2026 edition before the broader industry has fully digested it. </p><p><br></p><p>Pinto explains why the 2026 dataset, with 31,850 incidents and 22,624 confirmed breaches contributed by over 100 organizations in 145 countries — is the most statistically rigorous breach corpus in the industry.</p><p><br><a href="https://www.tenchisecurity.com/en?_gl=1*frc7uy*_ga*MTcwMjY3Mjk0Mi4xNzc2NzAzMTM2*_ga_Q6MBLVT4CZ*czE3NzkxMzg4NjIkbzgyJGcxJHQxNzc5MTQwNTQwJGo1MCRsMCRoMCRkVTViM29JR3Z5R19Ec29fbkFlb3NEOHMzNzczVkVsbUVUQQ.." target="_blank" rel="ugc noopener noreferrer">Tenchi Security</a> is a 2026 contributor, providing the survival-analysis dataset behind the report&#39;s new look at third-party MFA and cloud privilege exposures. Alex Sieira walks through what the curves actually mean: half of MFA findings get fixed in seven days, but 45% of cloud privilege management findings are still open a year after discovery.</p><p><br>The conversation digs into the headline shifts: vulnerability exploitation has now overtaken credential abuse as the most common initial access vector. Third-party involvement in breaches has climbed from 30% last year to 48% this year, and the median time to fully remediate CISA KEV findings slipped from 32 to 43 days.</p><p><br>will probably be the most-talked-about new section of the 2026 report: <em><strong>Verizon analyzed an anonymized dataset from Anthropic.</strong></em><strong> </strong>The data includes analysis of nearly 800 threat actors, maps their prompt activity to MITRE ATT&amp;CK techniques, and cross-references it against MITRE&#39;s software database. The DBIR folks immediately think to ask the data: “are attackers using LLMs for novel techniques, or for things every EDR already catches?”<br>The trio close out by debating Sieira&#39;s hypothesis that the metric to watch isn&#39;t total CVE volume — it&#39;s the percentage of vulnerabilities with reliable working exploits, which is the variable AI is most likely to move — and Pinto makes the case that vulnerability management is becoming a crisis-management discipline rather than a dashboard-watching one.<br>References:<br></p><ul><li>The 2026 Verizon Data Breach Investigations Report (DBIR): <a href="https://www.verizon.com/business/resources/reports/dbir/" target="_blank" rel="ugc noopener noreferrer">https://www.verizon.com/business/resources/reports/dbir/</a></li><li>Sieira and Pinto&#39;s RSA 2026 talk on how cloud-hyperscaler UX design impacts security outcomes <a href="https://path.rsaconference.com/flow/rsac/us26/FullAgenda/page/catalog/session/1755192044047001WRoa" target="_blank" rel="ugc noopener noreferrer">https://path.rsaconference.com/flow/rsac/us26/FullAgenda/page/catalog/session/1755192044047001WRoa</a></li><li>The Vercel Breach: <a href="https://cyberscoop.com/vercel-security-breach-third-party-attack-context-ai-lumma-stealer/" target="_blank" rel="ugc noopener noreferrer">https://cyberscoop.com/vercel-security-breach-third-party-attack-context-ai-lumma-stealer/</a></li><li>The British Library breach write-up Adrian cited as a candid post-incident report (their &quot;Learning Lessons&quot; document): <a href="https://www.bl.uk/home/british-library-cyber-incident-review-8-march-2024.pdf" target="_blank" rel="ugc noopener noreferrer">https://www.bl.uk/home/british-library-cyber-incident-review-8-march-2024.pdf</a></li><p><br></p></ul><p>Tenchi Security has an article out with the biggest insights related to the report, find it <a href="https://www.tenchisecurity.com/en/i