Cyber-attacks rise in 2026 with high and medium severity incidents surging 20.8% to 13.15 billion hits, according to the 2026 SonicWall Cyber Protect Report released this week. The report shifts focus from raw threat statistics to the protection outcomes that matter most to business decision-makers.

SonicWall drew on data from a global network of more than one million security sensors to compile the findings. Automated bots now generate more than 36,000 vulnerability scans per second, accounting for more than half of all internet traffic. Bad bot traffic alone has reached 37% of all global internet traffic.

Key Statistics from the 2026 Report

Cybersecurity threats are shifting in character, not just volume. Identity, cloud, and credential compromise now account for 85% of actionable security alerts, meaning stolen passwords have replaced zero-day exploits as the attacker’s primary tool. IoT attacks climbed 11% to 609.9 million hits, and Log4j alone generated 824.9 million intrusion prevention system hits in 2025, four years after its initial disclosure.

Small and medium-sized businesses carry a disproportionate share of the ransomware burden. In 2025, 88% of SMB breaches involved ransomware, more than double the rate recorded at large enterprises. A single SMB breach can exceed $4.91 million when downtime and recovery costs are included.

The Seven Deadly Sins of Cybersecurity

The report identifies seven recurring operational failures, which SonicWall calls the Seven Deadly Sins of Cybersecurity. These patterns appear consistently across breach investigations, security assessments, and incident reviews involving SMBs.

  • Ignoring the Fundamentals: Weak authentication, unpatched systems, and excessive admin privileges remain the primary attack surface.
  • False Confidence: Assuming a business is too small to be targeted, overestimating control effectiveness, and presuming resilience without testing it create dangerous blind spots.
  • Overexposed Access: Overly permissive rules, flat networks, and implicit trust after authentication give attackers a clear path once inside.
  • Reactive Security Posture: Without 24/7 monitoring and proactive threat hunting, attackers control the timeline. The average breach goes undetected for 181 days.
  • Cost-Driven Security Decisions: Deferring investment due to short-term budget pressure generates larger costs later. A single SMB breach can exceed $4.91 million.
  • Reliance on Legacy Access Models: VPNs that authenticate once and grant broad network access remain among the most exploited entry points. VPN CVEs grew 82.5% over the analyzed period.
  • Chasing Hype Over Execution: Buying tools without fully deploying them, and expecting technology to cover process gaps, is itself a vulnerability.

What SonicWall’s Leadership Said

“SonicWall data reveals attacks are getting faster, and in some instances, they’re getting a little more sophisticated. But the vast majority of the attacks that we’re seeing and investigating are basic fundamentals that continue to be missed. The danger isn’t that AI isn’t working; it’s that we’re using it as an excuse not to do the things we already know we should.”

Michael Crean, SVP and GM of Managed Security Services, SonicWall

Crean added that SMBs represent 99% of all U.S. businesses and nearly half of private sector employment. He said protecting them protects entire communities, which is why the report centers on protection outcomes rather than threat statistics alone.

Report Design and Target Audience

The 2026 Cyber Protect Report is the first in SonicWall’s history built around protection outcomes rather than threat data alone. It is designed to give managed service providers and managed security service providers the data and language needed for strategic conversations with SMB decision-makers.

The report translates technical threat intelligence into business risk that leaders can act on directly. SonicWall said the gap between protected and exposed organizations rarely comes down to technology; it comes down to execution. For SMBs and the providers that serve them, the report aims to close that gap with data, clarity, and a defined set of next steps.