Trend Cyber Risk Report 2026 vs 2025: What Changed?
Trend Micro's 2026 Cyber Risk Report shows improved risk scores but the same stubborn identity, cloud, and configuration weaknesses as 2025 — plus a new Attack Path Prediction dataset that changes how to prioritize them.

Trend Micro's 2025 and 2026 Cyber Risk Reports show a security environment in which measured enterprise risk improved, but several of the conditions driving that risk remained stubbornly familiar. The 2025 edition analyzed 2024 telemetry, while the 2026 edition builds mainly on 2025 telemetry and adds a new Attack Path Prediction dataset.
The most important change is not simply a shift in which risks rank highest. The 2026 edition connects exposures, identity weaknesses, vulnerabilities, detections, and target assets into predicted attack sequences. That gives more context to problems already visible in the 2025 report, especially stale accounts, weak authentication, cloud access risk, endpoint misconfiguration, and delayed patching.
For CISOs, SOC leaders, vulnerability management teams, identity teams, cloud security teams, and researchers, the comparison is useful because it separates persistent weaknesses from genuinely new findings. It also shows where 2025 observations were reinforced by the following year's telemetry and where the 2026 material does not provide enough evidence to claim confirmation.
Short answer
The 2026 report reinforces several of the strongest signals from the 2025 edition: risky cloud application access remains the top detected risk event, stale Microsoft Entra ID accounts remain second, and weak authentication controls continue to appear prominently. Overall Cyber Risk Index performance improved, but the 2026 report argues that better baseline posture has not eliminated operational gaps. The biggest analytical change is the addition of Attack Path Prediction, which shows vulnerabilities and password attacks as major attack-path initiators and user accounts as the most frequent terminal target. Some 2025 AI-related threat expectations cannot be judged from the 2026 report because it does not provide comparable AI threat telemetry.
What this report series covers
The Trend Cyber Risk Report series uses telemetry from Trend's Cyber Risk Exposure Management capabilities, XDR detections, vulnerability data, security configuration findings, and threat intelligence to examine enterprise cyber risk.
The 2025 edition focuses on 2024 telemetry and frames cyber risk management around the Cyber Risk Index, or CRI. It examines overall and regional risk, industry risk, risky events, endpoint and cloud misconfigurations, XDR detections, patching, response playbooks, ransomware, APT activity, malware, zero-day vulnerabilities, and selected uses of AI in cybercrime.
The 2026 edition continues the CRI-based analysis using primarily 2025 telemetry. It adds a new dataset from TrendAI Vision One Attack Path Prediction, intended to show how individual exposures can connect into plausible end-to-end attacker routes. The report explicitly describes this as a transitional addition and notes that some Attack Path Prediction sections use later snapshots rather than full-year 2025 data.
The comparison therefore works best at two levels: first, whether core enterprise risk indicators persisted or improved; and second, whether the 2026 report adds evidence that changes how those risks should be prioritized.
What changed across editions?
Overall risk improved, but improvement became less consistent
The 2025 report describes a broad decline in CRI during 2024, with the monthly score improving from February through December. The 2026 edition reports a 2025 annual average CRI of 35.8, down from a 2024 average of 38.5.
That is a positive year-over-year movement, but the 2026 report also describes more monthly volatility. Instead of the relatively steady improvement seen in 2024, the 2025 monthly CRI moved up and down, including a rise to 37.4 in April, a low of 34.1 in July, and a year-end level of 36.7 in both November and December.
This changes the interpretation of progress. The 2025 edition emphasized the value of proactive risk reduction. The 2026 edition still supports that direction, but suggests that organizations may be improving their baseline posture without sustaining continuous improvement throughout the year.
Cloud access and identity weaknesses remained persistent
The most direct confirmation across the two editions is in the top risk events.
In the 2025 report, Risky Cloud App Access ranked first and Stale Microsoft Entra ID Account ranked second. The 2026 report preserves exactly those two positions.
Weak identity controls also remain visible across both editions. The 2025 report highlights MFA-disabled accounts, stale accounts, password expiration being disabled, and accounts that do not require passwords. The 2026 report again places MFA-disabled accounts and password-expiration weaknesses among the most detected events.
This is one of the clearest cases where a 2025 trend was confirmed in the 2026 edition: identity hygiene and cloud access governance were not temporary anomalies in the earlier data. They remained systemic enough to rank among the leading enterprise risk events for a second year.
Endpoint configuration problems also persisted
The 2025 edition ranks unoptimized Web Reputation Settings as the most detected Trend Vision One endpoint misconfiguration. The 2026 edition again places Web Reputation Settings at number one.
Other recurring configuration issues include Device Control, anti-malware, predictive machine learning, firewall, application control, and behavior monitoring settings. The exact rankings shift, but the broader pattern is stable: organizations have security capabilities deployed without consistently optimizing the controls available to them.
The 2026 report develops this point further by arguing that these settings should not be viewed independently. It emphasizes that multiple unoptimized controls can compound one another, turning configuration hygiene into an operational security problem rather than a collection of isolated settings.
XDR detections shifted toward defense evasion
The 2025 report lists Possible OS Credential Dumping as the leading XDR model hit, followed by Possible Data Encrypted for Impact and detections involving built-in Windows tools, defense impairment, and hacking tools.
In the 2026 edition, Possible Disabling of Antivirus Software becomes the top XDR model hit, followed by Hacking Tool Detection - Blocked. Credential dumping remains present, but lower in the top 10.
This is a meaningful change in emphasis. The earlier edition showed strong evidence of credential access and later-stage attack activity. The newer edition gives more prominence to adversaries attempting to weaken defenses and establish persistence before moving further through the environment.
The supplied material supports describing this as a shift in observed detection ranking. It does not provide enough evidence to conclude that credential theft became less important overall.
Vulnerability management moved from patch speed toward exploit-chain context
The 2025 report stresses that many highly detected vulnerabilities remained unpatched even though patches had already been released. It also links faster mean time to patch with lower risk and recommends continuous scanning and regular patching.
The 2026 report goes further by challenging patch prioritization based only on CVSS severity. Three medium-severity vulnerabilities appear among the ten most detected unpatched CVEs, and the report argues that lower-severity issues can become much more consequential when they enable or strengthen an exploit chain.
This is an evolution rather than a reversal. The 2025 edition says organizations need to patch faster and continuously. The 2026 edition says they also need to understand how vulnerabilities interact and which ones participate in plausible paths to compromise.
Attack Path Prediction is the biggest new analytical layer
The 2026 edition introduces Attack Path Prediction as a new dataset. This is the most important structural change between the reports because it connects risk factors into sequences rather than treating them only as separate exposures or detections.
In the new data, Vulnerability is the leading component risk event associated with attack-path creation, followed by Password Spraying and Password Guessing. The report then identifies public IP addresses as the most common entry-point asset type and user accounts as the most frequent terminal target.
This new layer reinforces several findings from the 2025 edition. The earlier report already showed unpatched vulnerabilities, stale accounts, weak authentication, risky cloud access, and attack activity involving credentials and built-in Windows tools. The 2026 report provides a model for how those conditions can connect into an adversary route.
That makes the 2026 edition more useful for prioritization: it attempts to distinguish a frequently detected risk from a risk that helps create a viable path toward a high-value target.
Industry risk shifted, but structural weaknesses remained
The 2025 report places education among the sectors with the highest CRI and discusses legacy systems, remote-learning environments, user complexity, resource constraints, misconfiguration, and phishing exposure. Agriculture and construction are also highlighted as relatively high-risk sectors.
The 2026 report shows a reshuffled industry ranking. Mining rises to the highest average CRI, while healthcare, agriculture, telecommunications, and education remain prominent. Education is described as having made the strongest measurable improvement, falling from a quarterly peak CRI of 45.1 in early 2024 to 39.8 in 2025.
However, the 2026 report also shows that education's identity problem persisted: four of its top five risk events are directly related to stale accounts or weak authentication policies.
This is a useful example of partial confirmation. The earlier report identified structural identity and user-management challenges in education. The later report shows measurable risk improvement, but the same class of identity weaknesses remained central to the sector's risk profile.
Ransomware became more fragmented and more active in the observed leak-site data
The 2025 report uses ransomware leak-site monitoring to examine successful attacks disclosed by ransomware groups and notes that actual successful attacks may be higher because paying victims might not appear on leak sites. It also reports increased use of zero-day exploits by ransomware groups since 2020.
The 2026 edition describes a major reshuffling of ransomware groups in 2025. Across the top ten groups in its leak-site monitoring, confirmed breach counts increased from 1,518 to 5,096, which the report describes as approximately 236% growth. Five groups are new to the top-ten ranking, while previously dominant groups decline and other groups expand rapidly.
The strongest supported conclusion is that ransomware remained highly active while the group landscape changed substantially. The 2026 edition reinforces the importance of reducing underlying exposures rather than relying only on intelligence about a stable set of named ransomware groups.
The supplied material does not provide enough like-for-like data to say that the 2025 report's observation about growing ransomware use of zero-day exploits was directly confirmed in 2026.
Which 2025 trends were confirmed in 2026?
Several 2025 findings were clearly reinforced by the following edition.
Risky cloud application access remained the number-one detected risk event. This is the strongest direct year-over-year confirmation in the reports.
Stale Microsoft Entra ID accounts remained the number-two detected risk event. The persistence of stale identities suggests that account lifecycle management continued to lag behind account growth and organizational change.
Weak authentication remained unresolved. MFA-disabled accounts and weak password policies appear prominently in both editions, and the 2026 attack-path data gives these issues more context by placing password spraying and password guessing among the top attack-path initiators.
Security configuration remained an operational problem. Web Reputation Settings remains the top endpoint misconfiguration, while several other control categories recur across both years.
Vulnerability exposure continued to matter beyond static severity. The 2025 report focused on unpatched high-risk CVEs and patch speed; the 2026 edition adds evidence that vulnerabilities are the largest component category in attack-path creation and argues for prioritization based on chained risk rather than CVSS alone.
Education's identity-management problem persisted even as its overall risk improved. The 2026 report records meaningful CRI improvement for education but still shows an unusually identity-heavy risk profile.
Which 2025 expectations were not confirmed by the 2026 report?
The 2025 report includes a dedicated section on notable uses of AI in cybercrime, including AI-assisted reconnaissance, disinformation, deepfake-enabled scams, intensified phishing, and malicious digital twins.
The 2026 report does not provide a directly comparable section with enough data to judge whether those specific AI-related developments accelerated, plateaued, or changed form. Instead, it says the 2027 report is expected to expand AI-related risk and threat datasets as 2026 telemetry matures.
That means the 2026 edition cannot be used, from the supplied material alone, to claim that the 2025 AI-related expectations were confirmed. The cautious conclusion is that those expectations remain untested in this particular year-over-year report comparison.
The same caution applies to the 2025 report's observation about ransomware groups increasingly using zero-day exploits. The 2026 report discusses ransomware growth and mentions Cl0p's historical association with zero-day exploitation, but it does not provide equivalent trend data showing whether ransomware use of zero-days increased again in 2025.
Themes that became more prominent
Vulnerability & Exposure Management
This theme becomes more prominent because the 2026 report connects unpatched vulnerabilities directly to attack-path creation and argues for prioritizing vulnerabilities based on real-world exploitability and chained risk, not only CVSS severity.
Identity, Phishing & Access Security
Identity risk was already central in 2025, but the 2026 attack-path findings increase its importance by linking password spraying, password guessing, stale accounts, and weak MFA controls to viable paths toward user accounts.
SOC, Detection & Response
The 2026 report places stronger emphasis on how security teams operationalize detections and prioritize actions across multiple controls, especially through the relationship between XDR detections, configuration gaps, and attack paths.
Cloud Security
Cloud risk remains persistent across both editions. The 2026 report continues to show Risky Cloud App Access at the top of the risk-event ranking and adds more emphasis on cloud workload configuration and cloud-native entry points such as EC2 instances.
Cyber Risk & Resilience
Both editions are built around risk-based security management, but the 2026 edition sharpens the distinction between a lower aggregate risk score and actual resilience. Its conclusion explicitly notes that improving CRI scores do not necessarily mean environments are becoming safer at the same rate.
Themes that remained consistent
Stale accounts, MFA gaps, weak password policies, email threats, and credential-related activity recur across both years, and risky cloud application access remains the most detected risk event while configuration weaknesses continue to affect cloud environments.
Both editions emphasize continuous visibility into vulnerabilities and prioritization of remediation, even though the 2026 edition adds more exploit-chain context. Both also use XDR detections and security configuration telemetry to show how attacker behavior appears inside enterprise environments and how defenders can prioritize response.
The central argument remains consistent: organizations should manage cybersecurity as a continuous risk-reduction process rather than as a purely reactive response to incidents. Ransomware remains an important external threat category in both editions, though the 2026 report places more emphasis on rapid ecosystem reshuffling and growth in observed leak-site breach counts.
What this means for security teams
The two reports together suggest that improvement in aggregate risk metrics should not be treated as evidence that the underlying security problems are solved.
The strongest operational priority is identity hygiene. Stale accounts and weak authentication appear repeatedly in CRI data, and the 2026 attack-path model shows password spraying and password guessing as major path initiators. That gives security teams a stronger reason to treat account lifecycle management and MFA enforcement as exposure-reduction work, not only identity administration.
Cloud governance remains another persistent priority. Risky Cloud App Access stays at the top of the risk-event ranking across both years, while the newer report also highlights cloud workload configuration and internet-facing assets as part of attack-path formation.
Vulnerability management also needs a broader prioritization model. The 2025 report supports faster patching; the 2026 report adds the argument that medium-severity vulnerabilities may still be important when they enable a larger exploit chain. Security teams should therefore consider exploitability, exposure, asset criticality, and interaction with other weaknesses alongside severity scores.
Finally, the 2026 report makes operationalization a central issue. The repeated appearance of unoptimized controls across endpoint and cloud environments suggests that buying or deploying a capability does not guarantee that the control is configured, enforced, and used consistently enough to reduce risk.
Recommended reports to read
Read Trend 2025 Cyber Risk Report if you want a broad baseline of 2024 enterprise risk, including CRI trends, regional and industry comparisons, risky events, patching, response playbooks, ransomware, APT activity, malware, and AI-enabled cybercrime observations.
Read TrendAI 2026 Cyber Risk Report if you want the newer view of 2025 enterprise risk, a direct comparison of 2024 and 2025 CRI performance, updated risk-event and misconfiguration rankings, newer vulnerability prioritization analysis, and the first Attack Path Prediction dataset.
For year-over-year analysis, the two are best read together. The 2025 edition establishes the recurring exposures; the 2026 edition shows which of those exposures persisted and adds a model for how they may combine into attack paths.
Reports mentioned in this article

Trend Micro — TrendAI™ 2026 Cyber Risk Report
This report provides insights into the evolving cyber risk landscape in 2025, emphasizing the Cyber Risk Index (CRI), Attack Path Prediction, and the growing threat of ransomware. It highlights key trends, vulnerabilities, and recommendations for improving enterprise security posture.

Trend Micro — Trend 2025 Cyber Risk Report
The 2025 Cyber Risk Report by Trend Micro provides an in-depth analysis of the evolving threat landscape, focusing on the Cyber Risk Index (CRI), key risk factors, and proactive strategies to mitigate cyber threats. It highlights the importance of continuous monitoring, cloud security, and the role of AI in both cybercrime and defense.
