Guardz 2026 State of MSP Threat Report: AI and cybersecurity landscape

Guardz outlines how AI is influencing cybersecurity, with the report highlighting identity-related issues and vulnerabilities affecting MSPs, based on findings from its latest threat report.

Guardz has released its 2026 State of MSP Threat Report, outlining how artificial intelligence (AI) is changing the cybersecurity landscape. The report highlights vulnerabilities in identity, authentication, and cloud security that attackers are actively exploiting.

Based on SMB environments, the report notes that while AI has increased the speed and scale of cyberattacks, underlying security gaps remain. It highlights that attackers are exploiting weaknesses in identity and authentication systems, as well as misconfigured cloud environments.

Key findings of the report:

  • Identity compromise: 89% of SMBs had users with confirmed credential compromises.
  • Session hijacking: A 23% increase in session hijacking incidents, with attackers bypassing security measures such as MFA.
  • Rise of non-human identities: Machine identities exceed human identities in some environments, creating additional attack vectors.
  • Ransomware and fileless attacks: A 190% increase in ransomware detections, with a shift towards “living-off-the-land” techniques.
  • Business Email Compromise (BEC): BEC incidents continue to result in significant and increasing financial losses.

The report also highlights Managed Service Providers (MSPs) as being increasingly exposed, as their attack surface expands across multiple clients. It notes that misuse of remote monitoring and management (RMM) tools has become a leading endpoint threat vector, enabling potential unauthorised access across client environments.

According to the findings, attackers are increasingly focusing on maintaining and extending existing access, using techniques such as session-based attacks and OAuth misuse. The report states that traditional defences alone may not be sufficient, and discusses the role of AI in supporting detection and response at scale.

The report concludes that security entry points remain vulnerable and are being actively targeted. It also states that for MSPs, AI is becoming an important part of cybersecurity infrastructure in responding to evolving threats.

As AI continues to influence cybersecurity approaches, the report emphasises the importance of identifying and addressing security gaps within MSP environments.

inforcer introduces Copilot Manager to support MSPs in delivering AI services, including features related to monitoring and managing Shadow AI usage.

Kaseya launches Agentic IT management platform

Posted 1 hour ago by Sophie Milburn
Kaseya has introduced an autonomous IT management system that uses AI and unified data to support IT operations and security management.
Westcon-Comstor has integrated its value-added services into the Microsoft Marketplace, aiming to support partner operations and improve scalability.

Opus Technology achieves B Corp certification

Posted 21 hours ago by Sophie Milburn
Opus Technology has earned B Corp status, joining a global community aiming for ethical and sustainable business practices.
Cisco has announced its Sovereign Critical Infrastructure portfolio targeting organisations in Europe, the Middle East, and Africa.
CloudClevr is entering a new growth phase following the completion of its integration programme, heading into FY27 with a strengthened operational...

Westcon-Comstor strengthens ties at RISK Conference 2026

Posted 6 days ago by Sophie Milburn
Westcon-Comstor outlines its role in RISK Conference 2026, emphasising regional collaboration and cybersecurity advancements in the Balkans.
OpenText has made its enterprise data solutions available on the AWS European Sovereign Cloud, with the aim of supporting security and governance...