Most businesses hit by ransomware already own the right security tools. The breach comes from what is unpatched, misconfigured or poorly segmented behind them, and since no one can patch everything, the businesses that recover fastest are the ones designed to contain an intrusion, not just keep it out.
Every operational business we have recovered from ransomware owned the right tools: firewalls, antivirus, backups, and often endpoint detection as well. Nothing was missing, but something had been misconfigured, left unpatched, or set up once and never finished. That is the part most cyber security advice skips over. The 2026 Verizon Data Breach Investigations Report found that exploitation of vulnerabilities is now the most common initial access vector in breaches, at 31%, up 55% year over year, overtaking both phishing and credential abuse. In plain terms, break-ins are increasingly about unpatched and misconfigured systems rather than clever new malware.
For anyone running IT in a transport or logistics business, that shifts the question worth asking from “Do we have the right tools?” because you almost certainly do, to “Is everything we own actually configured, current and contained?”
Patching Is Not a Task; It’s an Estate Problem
Ask most IT teams how their patching is going, and the honest answer follows a pattern we see on almost every audit: effort runs inversely to how important the system is.
– End-user PCs get patched reliably. They reboot every night, and the risk of doing it is low.
– Servers get patched maybe once a year, if that. Everyone depends on them, so the downtime risk feels too high to take often.
– Switches, routers and firmware get forgotten for years, because nothing prompts anyone to look.
The blind spot is also wider than Windows. It’s the third-party software sitting on every desktop, the media player or PDF reader or the niche tool one user installed without telling anyone. It’s also the switch firmware that has no Patch Tuesday to nudge it up the to-do list. Each one is a way in, and attackers know it.
In transport and logistics, a large part of the estate is close to impossible to patch at all. Much of it is weight, fuel, pressure and location sensors, or screenless controllers with no interface to update and no straightforward patch path. This kind of operational technology is notoriously hard to secure, and if a business invested early, the cloud-managed patching model may not have existed when it went in. It sits on the network, often internet-facing, quietly out of date.
This is why patching alone can never be the whole answer. The 2026 Verizon Data Breach Investigations Report logged 527 million vulnerability instances by 2025, with the volume growing faster than organisations can remediate. You can’t patch everything, so the realistic goal is to patch what matters most and design the network so the rest can’t sink you.
Active Directory Hygiene: The Gap Inside the Domain
Not every configuration gap is a tooling problem. Some are housekeeping, and those are the ones that survive longest, because they never show up as red on a dashboard.
Active Directory is where we see it most. On audit, the recurring findings look like this:
– Stale accounts that were never disabled: The person left months ago, but the account is still live.- Leavers removed from Microsoft 365 but not from AD: The obvious door is shut, but the one behind it is still open.
– Accounts password-reset but left enabled: Nobody can log in with the old password, so it feels handled when it isn’t. An enabled account is a standing target for brute force.
– SMB v1 still running on domain controllers: No patch fixes this one. Someone simply has to know it should be turned off and then do it.
This is usually the kind of work that gets deprioritised when the team is firefighting, and it accumulates over years of staff changes and half-finished migrations.
It matters because identity is how attackers move once they are inside. Stolen and guessed credentials remain one of the most common ways in, and a forgotten enabled account is effectively a free one. You can own every security tool on the market and still hand an attacker a working key, simply because nobody went back to clean up.
AI Has Not Changed the Weakness, Only the Speed
There is a lot of noise about AI-powered attacks. The reality is calmer than the headlines and more useful to plan around. AI is not inventing new ways. In its assessment of the cyber threat to 2027, the NCSC judged that AI will almost certainly continue to make elements of cyber intrusion operations more effective and efficient, driving up the frequency and intensity of attacks. It works by making existing techniques faster and cheaper, not by unlocking new ones. Crucially for anyone still catching up on patching, the NCSC also found that the time between a vulnerability being disclosed and being exploited has already shrunk to days, and AI will almost certainly reduce it further, with operational technology running lower levels of security especially exposed.
That does not make it any less serious. It makes the fundamentals matter more, not less. Every gap we have described so far, the unpatched switch, the sensor with no update path, and the account nobody disabled, is now found and exploited on a shorter clock. The margin around everything you have not got to yet has shrunk – probably without you ever realising.
If You Can’t Patch Everything, Contain It
You cannot patch every device, some of your estate can’t be patched at all, and AI is shortening the time you have to react. If that were the whole story, every operational business would be one bad weekend away from disaster.
It isn’t the whole story, however, because there’s a second question that matters more than “How do we keep everything out?” “When something gets in, how far can it go?”
That question has a name: the blast radius. And it’s the single biggest difference between a contained incident and a business-ending one.
Most networks are built for convenience, where systems talk to each other freely and an attacker who lands on one machine can move sideways to the servers, the backups and the domain controllers. A well-designed network assumes a breach will happen and boxes it in. Done properly, there are three steps that build on each other:
1. Segment – Wall each part of the network off from the rest, with controls that are actually enforced, not VLANs that exist only on a diagram.
2. Pinhole – Let every system reach only what it genuinely needs. A door-access server talks to its door controllers and nothing else. Its route to a domain controller is closed entirely.
3. Alert – The moment a device tries to reach something it should never touch, block the connection and flag it. That single alert is often the earliest sign an attacker is inside.
Get those three right and an intrusion that would have shut down the business becomes a handful of reimaged machines and an afternoon’s work. This is why a breach on a well-built network can be over in hours rather than months, and why, across the clients we have rebuilt and retained, none has suffered a repeat attack. Fortinet recognised that work across 48 firewall deployments with no subsequent breach. It also explains why a configuration and design audit tells you more than a penetration test. A pen test tells you that you are patched today. An audit of how your network is built tells you what happens on the day you are not, which, as we have seen, is the day that eventually comes for everyone.
Start With What You Can Check This Week
None of this requires a full audit to begin. The fastest way to find out where you stand is to ask the questions that reveal configuration gaps rather than missing tools. A few worth putting to your own team or yourself:
– When were your switches and routers last patched? Not your firewall. Your switches.
– Do you have an inventory of every internet-facing IoT and OT device and a patch path for each one?
– How many enabled accounts in Active Directory belong to people who have already left?
– Is SMB v1 disabled across all your domain controllers?
– If a device on your CCTV or OT network tried to reach a domain controller tonight, would you get an alert or a silent allow?
If any of those gave you pause, that is the point. These are the everyday gaps we find on almost every network we are called into, usually in businesses that were confident their tools had them covered. Join us for Keeping the Supply Chain Moving: Cyber Resilience in Transport and Logistics, where we’ll look at what happens when cyber incidents hit the systems your operation depends on, drawing on real-world attacks and our own experience responding to and recovering from incidents across the industry.