Verizon recently released its annual Data Breach Investigations Report, one of the cybersecurity industry’s most closely watched reports. It is used by security professionals around the world to understand how attackers are changing, where organizations are struggling, and what trends business leaders should pay attention to.

It is important to note that these are global cybersecurity statistics from Verizon’s report, not Kalmer Solutions client data. Still, the trends are worth taking seriously because they point to a simple reality: attackers are not waiting around.


Patching is taking longer

One of the biggest takeaways is the growing challenge around vulnerability remediation. According to the report, the median time for vulnerability remediation rose to 43 days in 2025, compared to 32 days in 2024.

The median organization also had 50% more critical vulnerabilities to patch in 2025 compared to 2024. That means many teams are not just dealing with a longer repair window. They are also dealing with more serious problems at the same time.

That is a tough combination. Every unpatched vulnerability is a door left open, and attackers do not need every door. They just need one.


Ransomware is still a major player

Ransomware continues to be one of the most visible and disruptive cybersecurity threats. The report showed ransomware was involved in 48% of all breaches, up from 44% in 2024.

There was a little movement in the right direction when it comes to payments. The ransom was paid 31% of the time, down slightly from 35%. The median ransom payment also dropped to $140,000, compared to $150,000.

That is the kind of “good news, bad news” situation nobody wants to celebrate. Fewer organizations are paying, and the median payment is slightly lower, but ransomware is still showing up in nearly half of all breaches.


Artificial intelligence creates new risk

Another stat that stood out: 67% of users are using non-company artificial intelligence accounts on company devices.

At first, that may sound harmless. Someone is trying to write faster, summarize a document, clean up an email, or get a quick answer. It feels like a shortcut.

But shortcuts can create risk quickly. When employees use personal or non-company artificial intelligence tools for work, sensitive company information may end up outside approved systems, outside company visibility, and outside normal security controls.

It is the cybersecurity version of saying, “I know a faster way,” right before everything gets complicated.


Stolen accounts have real value

The report also highlights the value of compromised accounts. The average sale price of a compromised user account was $700. The average sale price of a compromised administrator account was $1,300.

That is a strong reminder that attackers do not always need to force their way in. Sometimes they buy their way in. Once a username and password are available, especially for an account with elevated access, the risk can grow fast.

This is why account security matters so much. Strong passwords, multi-factor authentication, access reviews, administrator account controls, and monitoring are not just technical details. They are part of keeping the business protected.


What businesses should do next

The latest Data Breach Investigations Report is not a reason to panic. It is a reason to pay attention. The trends point back to several practical cybersecurity priorities:

  • Patch critical vulnerabilities faster
    Make sure the most serious issues are identified, prioritized, and remediated before attackers can take advantage of them.
  • Review ransomware readiness
    Backups, recovery planning, endpoint protection, and incident response procedures should be tested before there is an emergency.
  • Create clear artificial intelligence policies
    Employees need to know which tools are approved, what information can be entered, and where the boundaries are.
  • Strengthen account security
    Multi-factor authentication, administrator access controls, and regular access reviews can reduce the damage caused by compromised credentials.
  • Train employees on real-world risks
    Security awareness works best when it is practical, consistent, and connected to the threats employees actually face.

Small gaps become big problems fast

Cybersecurity is not a one-time project. It is an ongoing process of finding risk, reducing exposure, improving systems, and helping employees make better decisions.

The Verizon report makes one thing clear: attackers are moving quickly. Organizations need to move with purpose.

Patching, account protection, artificial intelligence policies, ransomware preparation, and employee awareness all play a role. None of these areas have to be perfect overnight, but they do need attention before a small gap becomes a big problem.

Need help finding the gaps? Kalmer Solutions helps organizations strengthen cybersecurity, improve technology planning, and reduce risk before attackers find the weak spots first. If you want to review your current security posture and build a more proactive plan, contact Kalmer Solutions.