Decoding the world of cybersecurity

European security data links incidents to identity and visibility gaps

European security data analysed by Conscia links cyber incidents to compromised identities, excessive trust, incomplete visibility and delays between detection and response.

European security data links incidents to identity and visibility gaps
Summary
  • Conscia says its European teams carried out 260,943 investigations and contained 1,266 confirmed security incidents.
  • The company identifies identity exposure, excessive trust, incomplete visibility and delayed response as recurring conditions.
  • The figures describe Conscia’s vendor-owned operational data and are not a measurement of all European cyber incidents.

Compromised identities, excessive trust between systems, gaps in monitoring and delays in defensive action repeatedly appeared in incidents handled by Conscia across Europe, according to a new report based on the company’s security operations.

Cyber Resilience Insights 2026 draws on Conscia’s security operations centre and managed detection services, alongside forensic investigations, offensive testing and other security work.

The company says its teams carried out 260,943 investigations during the period covered by the report and contained 1,266 confirmed incidents. It says 64% of those incidents involved phishing, malware or misuse of identity, while 43% began outside weekday business hours.

Every forensic investigation included in the report uncovered exposed credentials, tokens or secrets, according to Conscia. Among offensive security findings assigned a severity rating, 27% were classified as critical or high.

Those figures describe organisations and incidents seen through Conscia’s own services. They cannot be used as a representative rate for Europe as a whole.

Fast detection does not guarantee fast containment

Conscia says 49% of confirmed incidents were detected and reported in less than 20 minutes, including 30% within 15 minutes. That speed did not always translate directly into containment because response still depended on staff availability and the authority to take disruptive defensive action.

An incident detected during the night or at a weekend can still progress if responders cannot disable an account, revoke a token or isolate a system without additional approval. Conscia therefore connects resilience with the decisions organisations make before an incident about who can act and under what conditions.

The report does not present attackers as relying primarily on unfamiliar techniques. Conscia says serious incidents repeatedly involved combinations of known weaknesses, including compromised identities, excessive trust relationships and incomplete monitoring.

Identity appears in the findings as more than a user account problem. Organisations increasingly rely on service accounts, software agents, tokens and other machine identities that can retain privileges and provide routes between systems.

The report also considers artificial intelligence, but Conscia does not claim AI has replaced established attack methods. Its assessment is that AI is increasing the speed and scale of familiar activity while basic weaknesses in identity, visibility and response remain decisive.

Conscia recommends changes around identity, legacy systems, recovery infrastructure, software dependencies, response authority and forensic readiness. Those recommendations are the company’s interpretation of its operational data rather than regulatory requirements.

The limitations of the vendor-owned dataset are material. Organisations buying managed detection, incident response or offensive testing services from Conscia are not necessarily representative of all European businesses, and the report cannot establish an overall European incident rate.

The volume of work does, however, allow recurring patterns within Conscia’s customer environment to be identified. More than 260,000 investigations and 1,266 contained incidents provide a substantial body of operational evidence even if that evidence cannot be extrapolated across the continent.

The pattern described is familiar rather than exotic. Identity compromise, trust between systems, incomplete visibility and delays in action continued to influence how far incidents progressed across the environments Conscia monitored.

×