For many years, information security investment was concentrated on the network perimeter, focusing on firewalls, email protection, and access control. This approach, however, did not keep pace with the transformation of the corporate environment, which is now characterized by devices accessing systems from different locations.
The exploitation of unpatched vulnerabilities took the lead among initial access vectors in data breaches, appearing in 31% of the analyzed cases. For the first time, this factor surpassed the use of stolen credentials. The data comes from the 2026 Data Breach Investigations Report, Verizon's annual study.
The median time to remediate a critical flaw increased from 32 to 43 days, and only 26% of these vulnerabilities were fully remediated during 2025, revealing organizations' difficulties in incident response.
According to Luiz Henrique Silveira, COO of ARX CYBER, a company specializing in cybersecurity, infrastructure, and cloud, companies concentrated their security investments on the perimeter for a long time, but the corporate environment has changed, making endpoint management an increasingly relevant aspect of protection strategy.




