For the first time, cyber incidents from inside organisations have overtaken external risks like hacking as the number one threat facing businesses, according to new research from Orange Cyberdefense.
Analysing over 139,000 triaged security events, the cyber firm’s Security Navigator 2026 shows internal threats now make up the bulk of confirmed incidents, up from 47% to 57% in less than a year.
Employee misuse is now a factor in 45% of all incidents, rising from just 29% in previous studies and a sharp contrast to those involving external hacking, which remained steady at 31%, largely unchanged from 2024.
While such misuse is often not malicious, often taking the form of unapproved software or security workarounds and web access, or the abuse of privileged access, it can play straight into the hands of attackers.
Orange found that account incidents, relating to identity and credential access, have climbed from 10% to 17%, figures which suggest attackers are increasingly aware of the patterns of misuse employees fall into, and are on the hunt to exploit these behaviours.
Added to that, the data reveals that end-user devices such as mobiles and laptops are now the most impacted assets, involved in around 53% of all incidents – up from 39%.
These shifts indicate that, for many organisations, the immediate risk is not a hacker cracking their firewalls, but an employee bypassing a security policy on endpoint hardware, providing threat actors an opportunity to weaponise workarounds.
“This data tells us that, while a hacker bypassing a firewall remains a concerning threat, the greatest threat to businesses today is their own employees bypassing policies in their daily work,” said Carl Morris, security researcher at Orange Cyberdefense.
“While not inherently malicious, employee misuse can be just as damaging as a sophisticated breach, especially given that attackers are increasingly turning policy workarounds into external entry points.”
According to the data, the organisations worst hit by incidents involving employee misuse are small businesses (43%) and large enterprises (45%), but while they face the same challenges, their core problems lie at opposite ends of the spectrum.
Small businesses often have fewer resources and less restrictive security and usage policies, granting employees more access than they need, and increasing the likelihood of mistakes or of attackers gaining a foothold.
In larger organisations, meanwhile, the sheer volume of employees and systems makes it easier for insider misuse to slip past even the best security measures.
Recommended reading
- ChatGPT Misuse Drives Majority of Enterprise AI Data Exposure
- Report: Enterprise PCs Wide Open to Hackers 76 Days a Year
- NCSC Warns Hackers Are Targeting WhatsApp and Signal
By contrast, medium-sized businesses tend to deal with far more hacking, accounting for 47% of their incidents compared with 31% attributed to misuse.
While these firms’ headcounts may be at a ‘sweet spot’ for managing internal access, they still occupy an attractive space for attackers as they often hold more valuable access than small businesses, but without the advanced security systems of large enterprises.
Across the board, improving cyber hygiene from the ground up, by boosting cyber literacy, investing in skills and awareness and putting additional measures in place, like 2FA for account access, are the most practical starting points to regain ground.





