According to Verizon's 19th annual Data Breach Investigations Report, vulnerability exploitation has surpassed credential abuse as the leading initial access vector in data breaches. The telecommunications giant analyzed over 31,000 real-world security incidents, including more than 22,000 confirmed breaches spanning 145 countries. In this year's report dataset, exploitation rose to 31%, while credential abuse fell to 13%.

This finding creates new action requirements for channel partners: helping customers accelerate patch deployment, regulate AI usage, secure new employee endpoints, and build sufficient resilience against ransomware attacks to avoid being forced to pay ransoms.

This urgent requirement expands the scope of security conversations beyond mere identity management to a broader domain. Mark Tina, Verizon Business channel chief and vice president of indirect partner sales, stated that the latest DBIR shows the attack surface has "fundamentally changed," and partners must adapt accordingly.

"For our partners, this is a signal: they can no longer just passively defend at the credential level, but should shift toward more proactive, continuous exposure management, because the enterprise boundary is no longer just the firewall—it's the entire network edge," Tina said.

This gives MSPs, MSSPs, and solution providers a more significant role in security, risk assessment, and patch management, especially in the network and connectivity environments that customers rely on. Tina noted that partners providing managed security services around core network and connectivity offerings are protecting "the critical transition point where the internet meets enterprise infrastructure."

As customers struggle to translate vulnerability data into complete remediation efforts, partners' responsibilities are also expanding.

In 2025, organizations fully remediated only 26% of critical vulnerabilities (defined as those in the U.S. Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalog), down from 38% the previous year. The median time to full remediation increased from 32 days to 43 days. In the median case, the number of known exploited vulnerabilities organizations needed to patch increased by nearly 50%, rising from a median of 11 in 2024 to 16 in 2025.

These issues do not stem from a lack of resources.

"This is not a tool problem—most organizations have plenty of tools," Tina said. "What they lack is prioritization and people who truly drive the work, which is exactly where partners can step in."

The biggest partner opportunity lies in helping customers focus on vulnerabilities that are being actively exploited, rather than trying to address all exposures at once, and then guiding remediation efforts through to completion.

Ransomware and Supply Chain Risk

Ransomware remains another major area of focus for channel partners.

Verizon found that ransomware appeared in 48% of breaches, up from 44% the previous year. However, 69% of ransomware victims in the dataset did not pay the ransom, and the median ransom payment decreased from $150,000 to $139,875.

Tina said this decline does not mean ransomware is less disruptive. Downtime still carries costs, and when organizations cannot operate, the impact ripples through the entire supply chain. But the trend of refusing to pay does suggest that solid fundamentals can change outcomes.

"Adequate preparation means better backups, faster recovery, and clearer incident response plans," Tina said. "Partner conversations with customers must shift from 'how to prevent' to 'how to maintain operations when an incident occurs.' Resilience is now the product."

The supply chain is another pressure point where channel partners can get involved. The report shows that breaches involving third parties increased by 60% compared to last year, accounting for 48% of all breaches. In third-party cloud exposures, only 23% of third-party organizations fully remediated missing or misconfigured multi-factor authentication on cloud accounts. For weak passwords and permission misconfigurations, the time to resolve 50% of findings extended to nearly eight months.

Sensitive Data Is Leaking

Verizon's research also highlighted risks in the places where employees most often work: mobile devices, messaging apps, and unauthorized AI tools.

"That's where source code and sensitive data are walking out the door," Tina said.

The human element accounted for 62% of breaches. Mobile-centric social engineering attacks (including voice and SMS) had a median successful click rate in phishing simulations that was 40% higher than email.

Shadow AI is spreading just as rapidly. Nearly half of employees are now considered regular users of AI tools on corporate devices, up from 15% last year. More than two-thirds of users accessing AI services on corporate devices do so through non-corporate accounts. In Verizon's data loss prevention dataset, shadow AI has become the third most common non-malicious insider behavior.

Channel partners should proceed with caution when addressing these issues.

"Employees are not intentionally creating risk," Tina said. "They are just seeking speed, and AI accelerates that trend. Partners who incorporate this reality into security—through policy, controls, education, and AI governance—will be the ones customers turn to first when something goes wrong. You need to stay close to where users actually work."