The #1 Breach Entry Point and What MSPs Should Do About It

June 8, 2026
Maddie Parker

Table of contents

  1. The patch wave the NCSC is warning about
  2. What Cyber Essentials requires
  3. Why this matters for MSPs specifically

Vulnerability Exploitation: The #1 Breach Entry Point

For the first time in 19 years, stolen credentials are no longer the most common way attackers gain access to organisations. According to Verizon's 2026 Data Breach Investigations Report, vulnerability exploitation now accounts for 31% of initial access vectors, up from 20% the previous year. Credential abuse has fallen to 13%.

The reason for the shift is in the remediation data. Only 26% of critical vulnerabilities listed in CISA's Known Exploited Vulnerabilities catalogue were fully remediated by organisations in Verizon's dataset during 2025, down from 38% the year before. The median time to patch rose to 43 days, up from 32. Remediation is slowing down at the same time that exploitation is speeding up.

The patch wave the NCSC is warning about

In May 2026, NCSC Chief Technology Officer Ollie Whitehouse set out a clear argument: AI can exploit technical debt across the software ecosystem at scale, leading to a forced correction: a high volume of updates across all software products that organisations must apply quickly. The practical recommendations are clear: identify and minimise internet-facing attack surfaces first, enable automatic updates, and operate with an update-by-default policy.

What Cyber Essentials requires

Cyber Essentials has a hard patching requirement. Software rated high or critical severity must be patched within 14 days of an update becoming available. Unsupported software must be removed or replaced. The median patching time of 43 days across Verizon's global dataset suggests a gap between current practices and what Cyber Essentials demands.

In May 2026, the ICO stated it expects organisations to have the five Cyber Essentials controls in place. The government named Cyber Essentials as the supply chain baseline in its Cyber Resilience Pledge at CYBERUK 2026.

Why this matters for MSPs specifically

Patch management across multiple client environments cannot be run manually. The volume is too high, and the consequences of missing critical updates are severe. For MSPs managing multiple clients, consistent compliance can only realistically be achieved through automation. Visibility into client environments is essential for demonstrating that the 14-day patching window is being met.

The ICO expects Cyber Essentials controls across organisations handling personal data, with clients in larger supply chains facing increased scrutiny.

Cyber Essentials Just Had a Big Week

April 28, 2026
Maddie Parker

Recent developments at CYBERUK 2026 include a £90 million government investment in cyber resilience, formally launching the Cyber Resilience Pledge and introducing significant changes to Cyber Essentials assessments.

The context behind the speech

Cyber resilience efforts are linked to the impact of cyber attacks on businesses. The government is positioning Cyber Essentials as a central pillar of its response to cyber threats, emphasizing basic cyber hygiene as a minimum expectation for any serious organisation.

What the Pledge actually commits organisations to

Signing organisations commit to:

  1. Make cyber a board responsibility: Implementing the Cyber Governance Code of Practice.
  2. Sign up to Early Warning: Register for the NCSC's Early Warning service within a month.
  3. Require Cyber Essentials across supply chains: Conduct a comprehensive audit of CE coverage across their entire supply chain, present findings to the board, and require CE from suppliers based on risk.

The Pledge is voluntary but listed signatories will be recognized, and those mandating Cyber Essentials from their third parties have seen up to an 80% reduction in cyber incidents.

Frontier AI is making the basics more important, not less

AI is enabling the discovery and exploitation of vulnerabilities. As AI simplifies attacks, good cyber hygiene becomes more essential. Cyber Essentials emphasizes basic controls that prevent unauthorized access, maintaining security as threats evolve.

How CyberSmart can help

As a leading Cyber Essentials certification body, CyberSmart supports the full certification lifecycle for MSPs, ensuring that clients remain compliant and prepared for emerging threats.

Closing Thoughts

Improving supply chain security involves recognizing the role of MSPs as critical infrastructure and ensuring they are held to high standards of accountability in the evolving digital landscape.