DigitalCIO
No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
DigitalCIO
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
No Result
View All Result
Digitalcio
No Result
View All Result
Home Tech News

80% of Energy, Oil/Gas & Utilities Firms Hit by Identity Breaches — Sophos 2026 Research Reveals Critical Infrastructure Identity Crisis

DigitalCIO Bureau by DigitalCIO Bureau
May 21, 2026
in Tech News
0
80% of Energy, Oil/Gas & Utilities Firms Hit by Identity Breaches — Sophos 2026 Research Reveals Critical Infrastructure Identity Crisis
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

State of Identity Security 2026 report finds human error and poor non-human identity management are the root causes of most attacks, as agentic AI accelerates the risk

Sophos released the State of Identity Security 2026, a vendor-agnostic survey of 5,000 IT and cybersecurity leaders across 17 countries. The survey found that 76.8% of organizations surveyed in India suffered at least one identity-related breach in the past year, and on average organizations worldwide reported three separate incidents. Repeat victimization reached a notable level globally, with 5% reporting six or more breaches. These attacks are driven primarily by human error and weak management of non-human identities (NHIs), a challenge that is accelerating rapidly as agentic AI accelerates attack processes.

In India 79% of ransomware victims responding to this survey confirmed their ransomware incident stemmed from an identity attack, establishing identity compromise as a primary delivery mechanism for ransomware. Sophos X-Ops researchers have observed this consistently over the past year. Worldwide, the financial consequences are steep: the mean recovery cost reached US$1.64 million, with a median of US$750,000, and 73% of those affected faced costs of US$250,000 or more.

“Identity-based attacks are becoming increasingly sophisticated in India as organizations rapidly expand their digital ecosystems and adopt AI-driven technologies. The finding that nearly 77% of organizations in India experienced an identity-related breach highlights how critical it is for businesses to strengthen both human and non-human identity security practices,” said Sunil Sharma, Managing Director and Vice President – Sales, India and SAARC, Sophos. “As AI agents, cloud services, APIs and automated workflows continue to scale, organizations need far greater visibility and control over identities, access privileges and authentication activity. A proactive, layered identity security strategy combined with continuous monitoring and Zero Trust principles will be essential for Indian businesses to stay resilient against evolving cyber threats.”

Additional Global Key Findings from the State of Identity Security 2026: 

  • Data and Financial Theft Dominate Breach Fallout: 10% of organizations reported an identity breach that impacted their business in the last year with the primary consequences being data theft (49%) and ransomware (48%), and financial theft (47%)
  • Visibility Remains a Critical Weakness: Only 13% of organizations continually monitor for unusual login attempts, and more than half of organizations globally check every three months or less.
  • Detection Gaps Persist: 14% of breached organizations could not detect and stop their most significant identity attack before damage was done. Smaller organizations (100–250 employees) were nearly twice as likely to fail at detection as mid-sized peers.
  • Critical Infrastructure Most Exposed: Energy, oil/gas, and utilities (80%) and federal/central government (78%) reported the highest breach rates across all industries surveyed.
  • Compliance Struggles Signal Broader Risk: Organizations that found compliance requirements very challenging had a breach rate of 82.4%, a full 14 percentage points higher than those with lower compliance difficulty (68.3%).

Globally, human error (employees tricked into providing credentials) was cited in nearly 43% of incidents. Weak NHI management, including API keys stored in code, static credentials, and orphaned service accounts, was cited in 41%. Organizations with weak NHI management are 22% more likely globally to experience financial theft and pay approximately $150,000 more to recover than average.

The NHI management problem is intensifying globally. AI agents can autonomously spin up sub-agents, each generating new credentials with broad, persistent access and inconsistent human oversight. Existing identity frameworks were not built for this, and organizations are already behind: globally, only 1 in 3 organizations regularly rotate or audits service accounts and non-human identities, and just 11% do so continuously.

Recommendations to Reduce Identity-based Risks

To reduce exposure to identity-related attacks, organizations should implement a multi-layered approach covering both human and non-human identities. Essential steps include enforcing Multi-Factor Authentication (MFA) for all user accounts, applying least-privilege access principles, and disabling or removing inactive identities promptly.

For non-human identities specifically, organizations should inventory and classify all NHIs, replace long-lived credentials with short-lived alternatives, and implement secrets management platforms to manage NHI credentials at scale. As agentic AI accelerates NHI proliferation, deploying Identity Threat Detection and Response (ITDR) capabilities and adopting a Zero Trust security model are increasingly critical layers of defense.

The State of Identity Security 2026 report comes from a vendor-agnostic survey conducted in Q1 2026 of 5,000 IT and cybersecurity leaders across 17 countries, including the U.S., U.K., Germany, France, Australia, Japan, India, and Brazil, in organizations with 100 to 5,000 employees across 14 industries.

Tags: CyberattacksCybersecurityCybersecurity BreachesCybersecurity ThreatsSophos
Share30Tweet19
DigitalCIO Bureau

DigitalCIO Bureau

Recommended For You

KPMG and Anthropic form a global alliance, unveiling the Claude-powered Digital Gateway

by DigitalCIO Bureau
May 20, 2026
0
KPMG and Anthropic form a global alliance, unveiling the Claude-powered Digital Gateway

KPMG and Anthropic have announced the launch of KPMG Digital Gateway powered by Claude, integrating Anthropic’s frontier AI directly into KPMG’s client delivery platform. This initiative is part...

Read moreDetails

Veeam Introduces Intelligent ResOps for the Agentic AI Era

by DigitalCIO Bureau
May 20, 2026
0
Veeam Introduces Intelligent ResOps for the Agentic AI Era

Veeam Launches Intelligent ResOps for the Agentic AI Era, Turning Data Context into Faster, More Precise Recovery Veeam Software has introduced Veeam Intelligent ResOps, a new solution unveiled...

Read moreDetails

Persistent Recognized as a 2026 Google Cloud Partner of the Year in the Services & Industry Solutions

by DigitalCIO Bureau
May 19, 2026
0
Persistent Recognized as a 2026 Google Cloud Partner of the Year in the Services & Industry Solutions

Persistent Systems has been named a 2026 Google Cloud Partner of the Year in the Services & Industry Solutions – Supply Chain & Logistics category, underscoring the company’s...

Read moreDetails

Tata Electronics and ASML Announce Strategic Partnership to Advance the Semiconductor Manufacturing Ecosystem in India

by DigitalCIO Bureau
May 18, 2026
0
Tata Electronics and ASML Announce Strategic Partnership to Advance the Semiconductor Manufacturing Ecosystem in India

Tata Electronics and ASML announced the signing of a Memorandum of Understanding (MoU) to advance the semiconductor manufacturing ecosystem in India. Through this partnership, ASML will enable the...

Read moreDetails

Tata Technologies Wins Frost & Sullivan 2026 Asia-Pacific Company of the Year for Autonomous Vehicle Engineering

by DigitalCIO Bureau
May 18, 2026
0
Tata Technologies Wins Frost & Sullivan 2026 Asia-Pacific Company of the Year for Autonomous Vehicle Engineering

Recognition highlights growing demand for end-to-end engineering as automakers shift to software-defined mobility Tata Technologies has been named Frost & Sullivan’s 2026 Asia-Pacific Company of the Year in...

Read moreDetails

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Related News

TCS Recognized as a Leader in Cloud Advisory

July 30, 2018
Gerald Beuchelt joins Acronis as CISO

Gerald Beuchelt joins Acronis as CISO

January 9, 2025
Dual Role of CISO & Head of Data Protection Office for Anil Kuril at Union Bank

Dual Role of CISO & Head of Data Protection Office for Anil Kuril at Union Bank

April 17, 2025

Browse by Category

  • Acquisition
  • Appointment
  • Archive
  • Artificial Intelligence
  • CIO Interviews
  • Cloud
  • Datacenter
  • Events and Conferences
  • Market Insights
  • News
  • Opinion and Analysis
  • Products
  • Resources
  • Security
  • Storage
  • Tech News
  • Telecom
Digitalcio

Welcome to DigitalCIO, your ultimate source for staying ahead in the ever-evolving world of technology and business.

BROWSE BY TAG

Accenture Acquisition AI Appointment artificial intelligence Artificial Intelligence and Machine Learning AWS Big Data and Analytics Blockchain CISCO Cloud Computing Cloudflare Commvault CrowdStrike Cybersecurity Digital Transformation E-books Fortinet Gartner Generative AI Google Cloud HCLTech IBM India Infographics Infosys Internet of Things (IoT) Kaspersky NTT DATA NVIDIA Palo Alto Networks Panel Discussion Qlik Salesforce Sophos Tata Consultancy Services TCS Tenable Trend Micro Veeam Veeam Software Vertiv Webinars Whitepaper Zscaler

CATEGORIES

  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
  • Archive

NAVIGATION

  • Home
  • About Us
  • Advertise with Us
  • Contact Us

© 2024 digitalcio.in - All rights reserved.

No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources

© 2024 digitalcio.in - All rights reserved.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?