Cybersecurity in 2027: fund the controls that still work when prevention fails
Use 2026 evidence to plan the next security budget around identity, exposed systems, recovery, telemetry, suppliers and AI — before buying another dashboard.
Scope
Use 2026 evidence to plan the next security budget around identity, exposed systems, recovery, telemetry, suppliers and AI — before buying another dashboard.
Start with evidence, not prediction theatre
Nobody can tell you which vulnerability, ransomware family or AI-assisted campaign will matter most in 2027.
That is not a useful planning question anyway.
A useful security forecast asks something different:
Which attacker advantages are already visible, are likely to persist, and require architectural work that cannot be completed during an incident?
The evidence available in 2026 points in a fairly consistent direction.
Attackers are exploiting exposed vulnerabilities quickly. Identity remains valuable. More intrusions use legitimate tools instead of obvious malware. Ransomware operators are attacking the systems required for recovery. SaaS and cloud services create control planes outside the traditional network perimeter. AI is making several existing attack techniques cheaper and faster while simultaneously creating a new class of identities, integrations and permissions that organisations need to manage.
The 2027 planning problem is therefore not “how do we stop every attack?”
It is:
How do we make a successful intrusion difficult to expand, visible while it happens, and recoverable without negotiating with the attacker?
That is a much more achievable objective.
The evidence entering 2027
The Verizon 2026 Data Breach Investigations Report provides one particularly useful warning.
Exploitation of vulnerabilities accounted for 31% of known initial access in breaches in its dataset, ahead of credential abuse at 13%. Verizon also found that only 26% of critical vulnerabilities in the CISA Known Exploited Vulnerabilities catalogue were fully remediated by organisations in 2025. Median resolution time had increased to 43 days.
Those numbers do not mean every organisation has exactly the same risk.
They do mean that “we patch monthly” is no longer enough information.
The important questions are which systems are reachable, whether the vulnerability is being exploited, what privilege the exposed service provides, and how quickly the organisation can apply an emergency change.
CrowdStrike's 2026 Global Threat Report describes another part of the same problem. Its telemetry recorded an average eCrime breakout time of 29 minutes, with the fastest observed case reaching 27 seconds. It also reports that 82% of its detections during 2025 were malware-free. These are vendor-specific observations rather than universal Internet measurements, but the operational implication is still useful: defenders should not assume that malicious behaviour will arrive as an unfamiliar executable that antivirus can conveniently quarantine.
Meanwhile, Mandiant's 2026 reporting describes ransomware increasingly as a recovery-denial problem. Attackers are targeting identity infrastructure, virtualisation management and backup systems specifically because those systems determine whether the victim can restore operations.
These are better foundations for a 2027 security plan than a speculative list of ten new attack names.
Planning assumption 01: the patch window will continue to shrink
A traditional patching process is often calendar-driven.
Servers are patched monthly. Network devices are reviewed occasionally. Emergency patching requires several approvals. Nobody is completely certain which management interfaces are reachable from the Internet.
That model becomes dangerous when exploitation begins before the ordinary maintenance window.
For 2027, vulnerability management should be treated as an exposure-management problem rather than merely a software-update problem.
Start with the outside.
An organisation should be able to produce a current list of its public IP addresses, domains, VPN gateways, remote-access services, web applications, mail infrastructure, cloud endpoints and externally reachable management interfaces.
Then answer four questions for every critical finding:
Is it exposed? Is exploitation known? What privilege does compromise provide? How quickly can we mitigate it?
CVSS alone cannot answer those questions.
A critical vulnerability on an isolated test system and a slightly lower-rated vulnerability on the company's Internet-facing VPN gateway are not necessarily equal operational priorities.
Investment for 2027
Fund asset discovery, vulnerability scanning and an emergency remediation process before buying another threat-intelligence feed.
The useful metric is not “number of vulnerabilities found”.
Measure time from known exploitation to mitigation on exposed assets.
That tells you whether the control can win the race it was purchased for.
Planning assumption 02: identity will behave like infrastructure
The phrase “identity is the new perimeter” has been repeated enough to lose some of its meaning.
The practical version is simpler.
A compromised identity can now provide access to email, files, SaaS applications, cloud infrastructure, source code, VPN, device management and administrative portals without the attacker ever crossing a traditional network firewall.
The attacker may not need to exploit the workstation at all.
Microsoft's 2025 Digital Defense Report found phishing or social engineering responsible for 28% of initial access in its incident-response dataset, with unpatched web assets at 18% and exposed remote services at 12%. Microsoft also continues to observe large-scale password attacks and infostealer-driven credential theft.
For 2027, MFA should therefore be considered a starting control rather than the finished architecture.
Organisations should separate privileged administration from ordinary daily accounts, reduce standing administrative privilege, remove stale accounts and app grants, protect recovery mechanisms, monitor sign-ins and move important identities towards phishing-resistant authentication where the platform supports it.
More importantly, account recovery must receive the same attention as account login.
An excellent MFA configuration can be defeated by a help-desk process that allows an attacker to socially engineer a reset.
The recovery workflow is part of the authentication system.
Investment for 2027
Fund identity governance before expanding the firewall estate.
Know who has privilege, why they have it, how they authenticate, how their access is recovered and what event tells you that privilege changed.
For small organisations, this often delivers more risk reduction than another appliance at the network edge.
Planning assumption 03: ransomware will attack the way back
A backup is not automatically a recovery capability.
If the same administrator identity controls production, virtualisation and backup infrastructure, one compromised identity may provide the attacker with all three.
If backup storage is continuously writable from production, ransomware may reach it.
If nobody has restored the business application from the protected copy, the organisation does not yet know whether recovery works.
Mandiant's 2026 findings describe attackers targeting backup infrastructure, identity systems, virtualisation management planes and even hypervisor datastores. The objective is straightforward: reduce the victim's ability to recover and increase the pressure to pay.
That changes the design objective.
Do not only protect servers.
Protect the machinery required to rebuild the servers.
For environments using VMware, Hyper-V or another central virtualisation platform, the management plane should be treated as a high-value security boundary. The same applies to backup consoles, storage controllers, BMC interfaces and identity systems.
Investment for 2027
Fund immutable or offline recovery copies, separate administrative paths and tested restoration.
A quarterly recovery exercise is more valuable than a dashboard showing that last night's backup job was green.
A successful backup job proves data was written.
A successful recovery exercise proves the organisation can use it.
Those are different claims.
Planning assumption 04: endpoint security alone will see less of the attack
CrowdStrike reported that 82% of the detections in its 2025 dataset were malware-free. ENISA has also documented continued use of legitimate services and living-off-the-land techniques to make malicious activity resemble ordinary administration.
That creates an awkward problem.
powershell.exe is not malware.
SSH is not malware.
RDP is not malware.
An OAuth application is not malware.
A newly created administrator account is not malware.
A hypervisor snapshot operation is not malware.
Whether those actions are malicious depends on identity, source, timing, sequence and expected behaviour.
That means the organisation needs evidence from several control planes.
Endpoint telemetry matters, but so do Entra ID or another identity provider, VPN, firewall, DNS, email, cloud, SaaS, hypervisor and backup logs.
The objective is not to ingest every event because storage has become inexpensive.
The objective is to collect the events required to make a decision.
Can you identify a new privileged role?
Can you see an administrator logging in from an unusual source?
Can you detect a backup repository being deleted?
Can you reconstruct which identity changed the firewall?
Can you tell whether a new OAuth application obtained access to company data?
If not, add that evidence before adding another million low-value events.
Investment for 2027
Fund telemetry around high-consequence changes.
Central logging is useful when an alert has an owner, an expected response and enough context to investigate it.
A SIEM that nobody watches is an expensive archive.
Planning assumption 05: AI will mostly accelerate existing security problems
There will be spectacular claims about AI-powered cyberattacks during 2027.
Some will be real.
Some will be marketing.
The safer planning assumption is that AI makes several existing activities cheaper.
Reconnaissance becomes faster.
Phishing can be localised and personalised at scale.
Scripts can be modified faster.
Attackers can process stolen information more efficiently.
CrowdStrike reported an 89% year-over-year increase in activity it classified as involving AI-enabled adversaries. Microsoft likewise reports attackers using AI to scale phishing and intrusion activity.
But AI also introduces a second problem inside the organisation.
Employees are connecting AI services to company information.
Developers are using coding assistants.
Departments are experimenting with agents.
Applications are receiving tokens that allow them to read mail, files, databases and business systems.
An AI agent that can read company data and perform actions is not merely a chatbot.
Operationally, it is another identity with privileges.
Treat it accordingly.
Ask what data it can read, which actions it can perform, which credentials it uses, how its activity is logged and how access is revoked.
Investment for 2027
Fund AI inventory and governance before AI security theatre.
Discover which services are actually being used.
Approve supported platforms.
Define what data may be submitted.
Review connectors and permissions.
Log important actions.
Give agents the minimum privilege required for their task.
Do not grant broad administrative access because the proof of concept was easier to configure that way.
Convenience has an impressive ability to become permanent architecture.
Planning assumption 06: your supplier's identity may become your incident
ENISA's recent work continues to identify supply-chain and dependency risk as a major concern for European organisations. In its cybersecurity investment analysis, supply-chain attacks were the second most frequently cited future concern after ransomware.
The practical risk is broader than compromised software updates.
Consider every organisation that can remotely administer your environment.
Every SaaS provider that stores business data.
Every MSP account.
Every support tunnel.
Every application with tenant-wide OAuth permissions.
Every external developer with repository access.
Every backup provider with a management agent.
These are parts of your effective trust boundary whether or not the network diagram shows them.
Investment for 2027
Build a small register of critical suppliers and record the access each one has.
For the important ones, know how access is authenticated, how quickly it can be revoked, which logs exist, who owns the relationship and what happens to your business if the provider becomes unavailable.
The supplier questionnaire is not the control.
The ability to revoke the supplier's access is.
Planning assumption 07: European regulation will increasingly reward work you should already be doing
For organisations operating in the EU, 2027 also has a very concrete date attached to it.
The Cyber Resilience Act becomes fully applicable on 11 December 2027. Reporting requirements for manufacturers concerning actively exploited vulnerabilities and severe security incidents already started on 11 September 2026.
The CRA is particularly relevant to manufacturers placing products with digital elements on the EU market.
Its direction should nevertheless look familiar to security practitioners: risk assessment, secure-by-default design, vulnerability handling, supported product lifecycles and evidence.
NIS2 and national implementations similarly reinforce the idea that cybersecurity is an organisational risk-management function rather than an antivirus purchase. ENISA guidance includes incident handling, business continuity, supply-chain security, vulnerability management, access control and other technical and organisational measures.
The useful response is not to create a parallel “compliance security” environment.
Build controls that produce both security outcomes and evidence.
A tested restore is good security and good evidence.
An access review is good security and good evidence.
A vulnerability remediation record is good security and good evidence.
One activity should ideally satisfy both worlds.
Where I would put the next security euro
The first investment would be identity: strong MFA, privileged-account separation, recovery controls, lifecycle management and visibility into authentication.
The second would be Internet exposure and vulnerability management: know what is public, identify known-exploited vulnerabilities and create an emergency patching route.
The third would be recovery: isolated or immutable copies, separate backup administration and repeated restore tests.
The fourth would be detection: endpoint protection plus useful central telemetry from identity, network, cloud and critical infrastructure.
The fifth would be management-plane protection: hypervisors, backup servers, network administration, storage and other systems capable of changing many systems at once.
The sixth would be supplier access and SaaS governance.
The seventh would be AI governance, including agent identities, application permissions and sensitive-data handling.
The precise order can change with the organisation.
A software company with no on-premises infrastructure will look different from a manufacturer running ten-year-old production equipment.
But purchasing should follow an identified failure mode.
If you cannot explain which failure a new product prevents, detects or helps recover from, do not let the word “AI” on the sales presentation make the decision for you.
A practical 90-day start
Do not attempt to “implement Zero Trust” by the end of the quarter.
Choose evidence you can obtain and controls you can verify.
During the first month, establish the inventory: public services, privileged identities, critical SaaS applications, backup systems, hypervisors, important suppliers and systems without an accountable owner.
During the second month, close obvious exposure. Patch known-exploited vulnerabilities, remove unnecessary public management interfaces, review privileged accounts and application grants, test session revocation and confirm that critical security events reach monitoring.
During the third month, run recovery and incident exercises.
Restore a representative system.
Disable a privileged identity and confirm access disappears.
Simulate a compromised supplier account.
Walk through a ransomware scenario in which Active Directory or the primary identity provider is unavailable.
Record what failed.
That failure list is probably a better input to the 2027 budget than another generic maturity questionnaire.
Measure outcomes, not purchases
A security programme can own EDR, SIEM, MFA, vulnerability scanning, immutable storage and several impressive dashboards while remaining surprisingly fragile.
Measure what those products allow the organisation to do.
How long does it take to remove an exposed critical vulnerability?
What percentage of privileged accounts use the required authentication control?
How quickly can privileged sessions be revoked?
When was the last successful restore?
How long does it take to rebuild a critical service from protected backups?
Can the security team identify who created a new administrator?
How many external suppliers retain privileged access?
How many AI or SaaS integrations have permissions nobody can explain?
Those answers describe security capability.
The invoice describes only procurement.
What should not be the first 2027 investment
Do not begin by buying an autonomous SOC platform because the organisation cannot investigate alerts manually.
Do not buy a larger SIEM because the existing one contains poor telemetry.
Do not buy another vulnerability scanner because nobody owns remediation.
Do not buy cyber insurance instead of recovery engineering.
Do not add another MFA product while administrators continue sharing accounts.
Do not deploy an AI security gateway while nobody knows which SaaS applications already hold company data.
Technology can automate a process.
It cannot manufacture the missing process underneath it.
Operational judgement
The important shift for 2027 is not a particular product or threat actor.
It is the decreasing usefulness of treating prevention as the only successful outcome.
Assume that one password will eventually be stolen.
One vulnerability will be missed.
One employee will approve the wrong prompt.
One supplier will have an incident.
One endpoint will execute something it should not.
Then design the environment so that none of those events automatically becomes control of the organisation.
Limit privilege.
Separate control planes.
Collect useful evidence.
Make destructive actions difficult.
Keep recovery outside the attacker's easiest path.
Practice using it.
Security becomes much easier to reason about when the objective changes from “nothing bad must ever happen” to “one failure must not become every failure.”
That is the security architecture worth funding for 2027.
Validate before you close the budget
A 2027 security plan is credible when each significant expense can be connected to an observed failure mode, an owner and a measurable outcome.
For every proposed control, record the condition it addresses, the systems in scope, the expected evidence, the person responsible for operating it and the test that proves it works.
Then remove purchases whose only measurable result is that the product was deployed.
The safest budget is not necessarily the largest one.
It is the one that makes the organisation harder to enter, harder to control, easier to observe and possible to recover.
Primary references
Verizon — 2026 Data Breach Investigations Report.
CrowdStrike — 2026 Global Threat Report.
Google Cloud / Mandiant — M-Trends 2026 Executive Edition.
Microsoft — Digital Defense Report 2025.
ENISA — Threat Landscape 2025.
ENISA — Cybersecurity investment and preparedness analysis.
European Commission — Cyber Resilience Act summary and implementation timeline.
ENISA — Technical implementation guidance for cybersecurity risk-management measures.
Editorial note: This article uses 2025–2026 observations to make planning assumptions for 2027. A planning assumption is not a prediction that a specific attack will occur. Review the underlying reports and current vendor guidance before making product- or environment-specific changes.