Data Security Practices That Actually Hold Up in 2026
Exploited vulnerabilities overtook stolen credentials as the top way in, and most breached firms had not encrypted the data. Seven practices that work.

If you can only fund three things this year, fund these: phishing-resistant authentication, patching the vulnerabilities attackers are already exploiting, and encryption of sensitive data at rest and in transit. That order is not a preference. It follows from what changed in the 2026 breach data, where exploitation of vulnerabilities overtook stolen credentials as the most common way in, and where more than half of breached organisations turned out not to have encrypted the data that was taken.
This guide covers seven practices, each with what it costs to skip, sourced to the organisations that publish the research rather than to vendors selling the fix.
What Data Security Actually Covers
Data security spans the physical layer of hardware and storage, the administrative layer of policy and access control, and the logical layer of applications, configuration and keys. Done properly it protects information assets against criminal activity, against human error, and against insiders, and the last two categories cause more incidents than most security programmes budget for.
The tooling question follows the data question, never the other way round. You cannot protect what you cannot locate, which is why data discovery and classification sit underneath every practice below rather than alongside them.
What the 2026 Breach Data Changes About Priorities
Two independent studies published this year should reset how a security budget is argued.
IBM's 2026 Cost of a Data Breach report, covering 602 breached organisations, put the global average cost at USD 4.99 million, a record and a 12% rise year on year. The United States average was USD 11.50 million. Mean time to identify and contain a breach rose to 247 days, reversing five years of improvement.
The 2026 Verizon Data Breach Investigations Report, built on more than 22,000 confirmed breaches, found exploitation of vulnerabilities is now the single most common initial access vector at 31%, ahead of credential abuse at 13%. Third parties were involved in 48% of breaches, up from 30% the year before. The human element remained present in 62%.
IBM also isolates which practices move average breach cost, which is the most useful budget table published anywhere:
| Factor | Effect on average breach cost |
|---|---|
| DevSecOps programme | About USD 254,000 lower |
| Identity and access management | About USD 226,000 lower |
| Encryption | About USD 213,000 lower |
| Employee training | About USD 196,000 lower |
| Supply chain compromise | About USD 227,000 higher |
| Shadow IT | About USD 201,000 higher |
| Excessive privileges and poor role management | About USD 177,000 higher |
These are isolated effects measured against the global average across breached organisations, not results from a controlled trial. Treat them as evidence of direction and rough magnitude, which is still far more than most security spending decisions get.
Seven Practices That Hold Up
1. Phishing-resistant authentication, not just multi-factor
Multi-factor authentication remains the highest-leverage control available. Microsoft's research put the risk reduction at 99.22% across the population studied, and 98.56% for accounts whose credentials had already leaked. That study dates from 2023 and measures MFA against no MFA, which matters, because the attacks that work now are specifically designed to defeat weak second factors.
IBM's 2026 data lists social engineering, defined to include helpdesk impersonation and MFA fatigue attacks, as the initial vector in 13% of breaches at an average cost of USD 5.23 million. Push notification approvals and SMS codes are what those attacks are built against.
The correct target is phishing-resistant authentication: passkeys and hardware security keys, which bind the credential to the site and cannot be relayed by an attacker sitting in the middle. Microsoft reported roughly 98% sign-in success with passkeys against 32% with passwords, and around one million passkeys registered a day. The usability argument, which used to be the blocker, now runs in the same direction as the security argument.
Practical sequence: enforce MFA everywhere first, since partial coverage is the common failure, then move administrators and finance to hardware keys or passkeys, then extend to the rest of the workforce. The identity side of this is covered in more depth in the passwordless authentication implementation checklist.
2. Least privilege, enforced and reviewed
Access control is the practice everyone claims and few audit. The principle is unchanged: database, network and administrative access goes to as few people as the work allows, and only for as long as the work lasts. What has changed is that the cost is now measurable. Excessive privileges and poor role management add around USD 177,000 to average breach cost, while an identity and access management programme subtracts around USD 226,000.
Two structural points. Joiners get access easily and leavers rarely lose all of it, so the recurring access review matters more than the provisioning workflow. And the authoritative framing is no longer perimeter-based: NIST SP 800-207 defines zero trust as granting no implicit trust from network location or device ownership, with authentication and authorization evaluated per session. CISA's Zero Trust Maturity Model version 2 is the practical roadmap for getting there in stages rather than as a project.
3. Patch what is actually being exploited
"Update your software regularly" is true and useless as a priority. Every organisation has more vulnerabilities than capacity to fix them, so the question is which ones first. The answer is public: CISA's Known Exploited Vulnerabilities catalog lists the vulnerabilities confirmed to be exploited in the wild, and it is the right prioritisation input for any organisation, not only federal agencies.
Most organisations are losing this race. The 2026 DBIR found only 26% of vulnerabilities in the KEV catalog were fully remediated in 2025, down from 38%, with the median time to full resolution rising to 43 days. The median organisation had 50% more critical vulnerabilities to handle than the year before.
One current-policy note worth having right, because a lot of published guidance is now wrong on it. CISA's Binding Operational Directive 22-01, the source of the familiar two-week and six-month KEV deadlines, was revoked on 10 June 2026 and replaced by BOD 26-04. The new directive is risk-tiered rather than catalogue-wide: three days for publicly exposed assets with automatable exploits granting full control, fourteen days for publicly exposed KEV entries with automatable exploits, thirty days for other publicly exposed critical vulnerabilities. Those tiers are a reasonable model for a private-sector policy too.
Back up before you patch. That advice has not aged.
4. Encrypt, and start the post-quantum inventory
Encryption is the control with the widest gap between assumed and actual adoption. IBM found 53% of breached organisations had not encrypted sensitive data at rest and in transit, and a further 10% did not know. Only 37% had. Encryption sits among the top cost reducers at about USD 213,000 below average, and it is often the difference between a notifiable breach and a contained incident.
Get the basics right before anything exotic: strong modern algorithms, TLS everywhere including internal service-to-service traffic, encryption at rest on databases, object storage and backups, and key management that is genuinely separate from the data. Poor key handling is how encryption programmes fail in practice, and IBM prices mismanaged secrets and keys as a cost increase of roughly USD 199,000, with key lifecycle tooling as a reducer of roughly USD 215,000.
Then start the long piece of work. NIST published the first post-quantum cryptography standards in August 2024: FIPS 203 for key encapsulation, with FIPS 204 and FIPS 205 for digital signatures. NIST's draft transition guidance proposes deprecating today's quantum-vulnerable algorithms such as RSA and elliptic curve after 2030 and disallowing them after 2035. That document is still a draft, so treat the dates as NIST's proposed direction rather than settled policy. The work that is not optional either way is the inventory: knowing where your organisation uses public-key cryptography, in which products, with which expiry horizons. That takes years, which is why it starts now.
5. Know where your data is, including the AI copies
The fastest-growing category of exposure is data an organisation did not know it had in places it did not approve. IBM found shadow AI involved in 43% of security incidents, more than double the previous year's 20%, at an average cost of USD 5.39 million. Shadow IT, defined as lack of visibility into applications in use, adds about USD 201,000.
The DBIR puts numbers on the behaviour behind it: 45% of employees are now regular AI users on corporate devices, up from 15%, and 67% of them use non-corporate accounts to do it. That is company data leaving through a browser tab, at scale, with no logging.
Blocking is not a strategy, because the demand is real and people route around it. Provide a sanctioned tool with enterprise terms, log its use, apply data loss prevention to the paths employees actually take, and classify data so the rules can distinguish a public draft from customer records. IBM also found that 92% of organisations suffering an AI-related breach lacked proper AI access controls, which is a familiar problem in an unfamiliar place.
6. Backups that are offline, encrypted and tested
Ransomware was present in 48% of breaches in the DBIR dataset, and 39% of IBM's breached organisations were hit by it. Encouragingly, 69% of DBIR ransomware victims did not pay, and the median ransom paid fell to USD 139,875.
CISA's guidance on the StopRansomware hub is worth quoting precisely, because it contains the three words most backup strategies fail on: "Maintain offline, encrypted backups of data and regularly test your backups." Offline, because a backup reachable from a compromised domain gets encrypted too. Encrypted, because backups are a complete copy of everything you are protecting. Tested, because an untested restore is a hypothesis.
The widely quoted three-two-one backup rule is a sound industry convention, but it originates from a photography workflow book rather than from any standards body, so present it as a rule of thumb and not as official guidance.
7. Training, scoped honestly
Training everyone with access to sensitive data is worth doing, and the case for it should be made without overclaiming. The only primary figure available is IBM's isolated estimate that employee training sits about USD 196,000 below the average breach cost, roughly a 4% reduction. That is an observational correlation across breached organisations, not a controlled experiment.
The counterweight is that the human element was present in 62% of breaches, up from 60%, after two decades of awareness programmes. And the DBIR found the median successful click rate on voice and SMS social engineering ran about 40% higher than on email, which is where nearly all training content is aimed.
The defensible position: training is modest, measurable and insufficient on its own. It is worth funding, and it is not a substitute for controls that work when a person is fooled. Design so that a single employee mistake cannot become a breach, then train people to make fewer mistakes.
The Practice Everyone Under-Funds: Third-Party Risk
Third parties were involved in 48% of breaches in the 2026 DBIR, a 60% increase year on year, and supply chain compromise is IBM's single largest cost-amplifying factor at about USD 227,000. Yet third-party risk management is usually a questionnaire sent once at onboarding.
Better minimum: know which vendors hold or can reach your data, know what access their integrations actually have rather than what the contract says, revoke integrations on offboarding the way you would revoke an employee, and require breach notification terms with a defined clock. The DBIR also found that only 23% of third-party organisations fully remediated missing or improperly secured MFA on cloud accounts, which is a useful thing to ask about specifically.
Know Your Notification Clock Before You Need It
Under GDPR Article 33, a controller must notify the supervisory authority of a personal data breach without undue delay and, where feasible, not later than 72 hours after becoming aware of it. Article 34 requires communication to affected individuals without undue delay where the breach is likely to result in high risk to their rights and freedoms.
The UK's Information Commissioner's Office applies the same 72-hour standard and notes that failure to report can attract fines up to £8.7 million or 2% of global turnover. The ICO also records a 2025 change: from 20 August 2025, the Data Use and Access Act moved breach reporting under PECR from 24 hours to 72 hours for communications service providers.
Other regimes, including sector rules and United States securities disclosure requirements, carry their own clocks and have been subject to amendment. Confirm the current text of any obligation that applies to you with the regulator rather than with a summary article, this one included.
A Practical Order of Operations
- Inventory. What sensitive data exists, where it lives, who can reach it, and which third parties touch it. Everything else is guesswork without this.
- Authentication. MFA everywhere, then phishing-resistant factors for administrators and finance.
- Exploited vulnerabilities. Build the KEV feed into patch prioritisation and set risk-tiered deadlines in writing.
- Encryption and keys. At rest and in transit, with key management separated from the data.
- Access review. Quarterly, with leavers and role changes as the first pass.
- Backups. Offline, encrypted, and restore-tested on a schedule with the result recorded.
- Shadow AI and shadow IT. Sanction a tool, log it, and apply data protection rules to the real paths.
- Training and tabletop. Short and frequent, plus one exercise a year that includes the notification clock.
How This Guide Was Verified
Every figure here comes from the organisation that published the research: IBM's 2026 Cost of a Data Breach report, the 2026 Verizon Data Breach Investigations Report, Microsoft's published MFA and passkey research, and guidance documents from NIST, CISA, the European Union's official legal text and the UK Information Commissioner's Office. No listicles or vendor marketing were used as sources, and no product was tested for this article; the methodology, not a hands-on claim, is what backs the recommendations.
Two honest limitations. The Microsoft MFA effectiveness figure dates from 2023 and measures MFA against no MFA, so it should not be read as evidence against adversary-in-the-middle phishing. And NIST's post-quantum transition timeline remains a public draft, so the 2030 and 2035 dates are proposed rather than final.
Last verified: September 2026. Checked: IBM 2026 breach cost figures and cost-factor values, DBIR 2026 vectors and third-party findings, CISA BOD 26-04 replacing BOD 22-01, KEV catalog status, NIST FIPS 203 and the IR 8547 draft status, CISA StopRansomware wording, GDPR Article 33 text, and the ICO PECR change.
Frequently Asked Questions
What should a small business do first?
Turn on multi-factor authentication for email, finance and administrative accounts, because those three cover most of the loss. Then get backups that are offline and tested. Then patch anything on the CISA exploited-vulnerabilities list that you run. Those three cost very little and remove the majority of realistic scenarios.
Is MFA still enough?
It is still the best single control and it is no longer sufficient by itself for high-value accounts. Push-approval and SMS factors are specifically targeted by MFA fatigue and relay attacks, which IBM records as part of a 13% initial-access category averaging USD 5.23 million. Passkeys and hardware security keys are the answer for administrators and anyone with access to money or customer data.
If data is encrypted, is a breach still notifiable?
It depends on the regime and on whether the keys were also exposed, so this is a question for your counsel rather than a checklist. What is consistent across regimes is that properly implemented encryption reduces the risk to individuals, which is the test several notification rules turn on. That is a separate benefit from the average cost reduction IBM measures.
Is security awareness training worth the money?
Yes, modestly, and it should be sold that way. The measurable effect is real but small, and the human element still appears in 62% of breaches. Buy it as one layer, and make sure the controls around it assume people will occasionally click.
How do we handle employees using AI tools with company data?
Provide a sanctioned option with enterprise terms and logging, because 45% of employees are already using AI on corporate devices and two thirds of those are using personal accounts. Then apply data protection rules and classification so that sensitive categories are blocked or warned on at the point of use. Prohibition without an alternative produces the invisible version of the same behaviour.
How often should access be reviewed?
Quarterly for standing access, immediately on role change or departure, and continuously for privileged and service accounts. The recurring review is the control that catches the accumulation problem, since access is granted far more readily than it is removed.
More like this
All Scams & Cybersecurity- Scams & CybersecurityTop 7 Google Drive Security Mistakes Companies Keep MakingMost Drive exposures come down to unenforced 2-Step Verification and nobody auditing external sharing. Here are the seven mistakes and…
- Scams & CybersecurityData Security Best Practices: The 2026 Checklist80% of data breaches involve compromised credentials. Yet most organizations are still fighting 2026 threats with 2015 defenses.
- Scams & CybersecurityWhat to Do When You Receive a Bug Bounty EmailA stranger emails saying they found a security hole in your site and would like a reward. Is it a genuine researcher, a low-effort "beg…
Get new Scams & Cybersecurity writing
Enjoyed this? Subscribe and tell us what you read most. Scams & Cybersecurity is already ticked for you. No tracking pixels, unsubscribe with one click.