First, a caveat about the numbers
Yeh says this year's report covers threat activity Microsoft observed between July 2025 and June 2026. When this article was prepared, Microsoft's public Digital Defense Report page still showed the 2025 edition as the latest. That page offers insights into the latest cyberthreat landscape trends, including cybercrime as a service and the rise of hybrid ransomware and phishing, and the 2024, 2023, 2022 and 2021 reports appear below it as archives. No 2026 report was listed.
So every 2026 figure below comes from Yeh's post. None of it could be checked against the full report, its methodology or its sample sizes. Treat the numbers as Microsoft's own telemetry claims until the report is published.
Section summary: The recommendations are clearly sourced. The statistics come from Microsoft and haven't yet been independently confirmed.
What Microsoft says it saw
Yeh's post makes these claims:
- Government was the most-hit sector. Government agencies and services made up 27% of observed cyber-threat activity in 2026, up from 17% in 2025. Microsoft also calls government the sector nation-state actors target most often.
- Dwell time went up. This is the gap between an attacker getting in and defenders finding and stopping them. Microsoft says it grew across several sectors. Organizations responded faster once they spotted an intrusion, but spotting it early stayed hard.
- Phishing jumped. Microsoft says phishing accounted for 23% of observed intrusions in 2026, compared with 7% in 2025. Yeh ties this to stolen identities serving as the way in for larger attacks.
- Weaponization is getting faster. According to the post, a vulnerability found being exploited in the wild can be weaponized in well under 24 hours. Publicly disclosed CVEs are projected to hit a record 72,000 in 2026. The post doesn't say how that projection was calculated.
- Valid accounts lead to more theft. Microsoft found that 52.2% of intrusions involving valid accounts led to further credential theft.
That last figure is easy to mix up with a different one from last year. A summary of the 2025 report by Kings Research says over 52 percent of cyberattacks with known motivations are driven by extortion and ransomware, whereas espionage accounts for just 4 percent. The two numbers measure different things. One is about attacker motive. The other is about what happens after someone logs in with a real account. Don't cite one as if it were the other.
Section summary: Microsoft's picture of 2026 is more pressure on government, attackers staying hidden longer, and identity as the main way in.
The theme hasn't changed: attackers log in
If the identity angle sounds familiar, it should. Microsoft has been making this point for a while. Reviewing the 2025 report, consultancy Professional Advantage described a shift from traditional "break‑in" attacks toward credential‑based access. It added that stolen passwords, hijacked tokens, and compromised workloads are now the primary entry points.
Its explanation of why that matters also explains the dwell-time problem: when an attacker logs in using valid credentials, the activity can look "normal", making detection significantly harder. If an intruder signs in with a real employee's account, the security system may see nothing unusual. In practice, that's why rising phishing rates and longer dwell times tend to show up together.
The five priorities
1. Plan for less time to react
Microsoft says AI is shrinking the time defenders have to act. Yeh argues that the governments best placed to cope will be those that can quickly gather information, make decisions, coordinate across institutions and communicate during a crisis. That depends on clear responsibilities and trusted relationships being in place before an incident starts. Nobody wants to be looking up who owns the incident bridge while ransomware spreads.
2. Build security into the AI ecosystem
Yeh treats AI security as a resilience problem, not just a technical one. AI systems rely on infrastructure, data, models, applications, suppliers and governance processes. Microsoft wants governments to encourage:
- secure-by-design development
- testing and evaluation
- stronger supply-chain protections
- transparency and accountability
- international cooperation on AI risk
Notably, Microsoft argues against a separate AI security agenda. It wants AI folded into existing critical-infrastructure protection and national resilience work.
3. Assume incidents will spread
The post makes a practical point here. In the first hours of an incident, a government may not know whether it's dealing with criminals, a state actor or something else. Both kinds of attacker increasingly use the same entry points: compromised identities, exposed applications, social engineering and legitimate admin tools.
Yeh therefore wants incidents judged by where they could lead, not just how they started. A compromise that looks contained can turn into ransomware, espionage, data theft or an outage of essential services. Response plans should include the suppliers, partners and service providers behind critical functions.
4. Make information sharing go both ways
Microsoft wants threat-intelligence sharing to be timely, trusted and bidirectional. Companies reporting to government isn't enough. Agencies need to send back intelligence, guidance and warnings that organizations can act on. Yeh suggests policymakers back this with:
- protections for good-faith sharing
- common anonymization standards
- investment in shared threat-intelligence and detection capabilities
He also says sharing should lead to investigations, disruption efforts and accountability.
5. Keep essential services running during an attack
The last priority goes beyond government's own systems. It covers transportation, communications, schools, universities and infrastructure operators. Microsoft says planning documents alone aren't enough. It calls for regular tabletop exercises that bring together policymakers, operational leaders, law enforcement, infrastructure operators and private partners.
Yeh cites Microsoft's Advancing Regional Cybersecurity (ARC) program, most recently in Kenya, as an example of scenario-based exercises. The post gives no dates, participants or results for that work. He also recommends shared services to extend security capacity to local governments that can't build it themselves.
Section summary: All five priorities are about coordination rather than products: decide who does what, map your dependencies, share in both directions, and rehearse.
Reading the post critically
This is policy writing from a company with a lot at stake. Microsoft sells identity, threat-detection and cloud security products to the governments it is advising. It is also a vendor whose own security incidents have drawn government scrutiny in past years. None of that makes the advice wrong. Tabletop exercises, mapping dependencies and two-way sharing are widely accepted resilience practices, and they don't require Microsoft products.
Some things are missing, though. There's no breakdown by country, no definition of "observed activity," and nothing on how much of the rise in government activity reflects Microsoft's growing visibility into public-sector networks rather than more attacks. A sector's share of threats can rise because a vendor sees more of that sector. Those questions should be answerable once the full report is out.
What Windows and IT admins can do with this
The post is aimed at policymakers, but most of it applies to anyone running a Windows estate for a public body or a government contractor. The following is general industry practice, not steps taken from Microsoft's post:
- Treat identity as the perimeter. Professional Advantage recommends tools that detect unusual sign‑ins and analytics that flag oddities such as impossible travel, mass download activity.
- Go after dwell time. The same review suggests you consolidate logs across cloud and on‑premises systems for full visibility. You can't catch an intruder hiding in logs you aren't collecting.
- Automate containment. Protiviti, discussing the 2025 report, argues that automatic account disablement, rapid endpoint isolation, and immediate containment of suspicious behavior must become the norm.
- Map your supply chain. List which suppliers, managed service providers and admin tools can reach your critical systems, and include them in incident plans.
- Run a tabletop exercise. Use a scenario in which a phished account turns into credential theft across the domain, and see where decisions stall.
The bottom line
Yeh's post works better as a policy roadmap than as a threat report, at least until the 2026 Digital Defense Report itself appears. If Microsoft's numbers hold up, government's share of observed threat activity rose by ten points in a year, phishing's share of intrusions roughly tripled, and attackers stayed hidden longer. The five priorities aren't new, but they hang together well: prepare before the crisis, assume a breach will spread, share intelligence in both directions and keep services running. Whether governments act on them is a separate question, and the full report should show whether the statistics stand up.
References
- Preparing governments for an era of interconnected cyber risk - blogs.microsoft.com blogs.microsoft.com · 2026-10-01T14:01:14+00:00
- Microsoft Digital Defense Report and Security Intelligence Insights microsoft.com
- Microsoft Digital Defense Report and Security Intelligence Insights microsoft.com