Episode 126 April 29, 2025 • 🎧 12:11
Verizon DBIR 2025: Navigating Third-Party Risk and the Human Factor
Drawing on the Verizon 2025 DBIR, this episode highlights how third-party relationships and the human element continue to be central to data breaches, driven by pervasive threats like stolen credentials, ransomware, and evolving social engineering tactics
🎧 Listen to this Episode
Show Notes
Join us as we unpack the critical insights from the Verizon 2025 Data Breach Investigations Report. This episode dives deep into the report's most prominent themes, highlighting the ever-increasing involvement of third parties in data breaches and the persistent influence of the human element, which was involved in 60% of breaches this year. We explore the prevalent incident patterns including System Intrusion, often involving ransomware, Basic Web Application Attacks, largely driven by stolen credentials, and Social Engineering, where phishing and pretexting remain key techniques, now joined by emerging threats like prompt bombing. Drawing on data collected from November 1, 2023, to October 31, 2024, we discuss how attackers exploit vulnerabilities, how different industries and organizations of all sizes are targeted, and the importance of frameworks like VERIS for understanding the threat landscape. Tune in to gain actionable insights directly supported by the data and analysis from the DBIR sources.
breached.company/navigating-the-modern-threat-landscape-key-insights-from-the-verizon-dbir-2025
Enjoying CISO Insights?
Subscribe to get new episodes delivered directly to your podcast app.