---
title: "Hackers Are Spoilt for Choice: It’s Time to Focus on Data-Centric Security"
description: Enhance your data protection strategy by focusing on data-centric security. Learn from the latest Verizon DBIR trends and secure sensitive information with automated tools and advanced protection measures.
image: https://insights.comforte.com/hubfs/comforte%20AG_Hackers%20Are%20Spoilt%20for%20Choice_%20It%E2%80%99s%20Time%20to%20Focus%20on%20Data-Centric%20Security.png
---

[![Hubspot_blog_logo](https://insights.comforte.com/hs-fs/hubfs/Hubspot_blog_logo.png?width=295&name=Hubspot_blog_logo.png)](http://www.comforte.com)

[![Subscribe](https://no-cache.hubspot.com/cta/default/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0.png)](https://cta-redirect.hubspot.com/cta/redirect/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0)

[![comforte AG - Hackers Are Spoilt for Choice: It’s Time to Focus on Data-Centric Security ](https://insights.comforte.com/hubfs/comforte%20AG_Hackers%20Are%20Spoilt%20for%20Choice_%20It%E2%80%99s%20Time%20to%20Focus%20on%20Data-Centric%20Security.png)](https://insights.comforte.com/hackers-are-spoilt-for-choice-its-time-to-focus-on-data-centric-security)

[Dan Simmons](https://insights.comforte.com/author/dan-simmons) l May 8, 2025 l [Data Protection](https://insights.comforte.com/tag/data-protection), [Research, Trends, and Predictions](https://insights.comforte.com/tag/research-trends-and-predictions)

# Hackers Are Spoilt for Choice: It’s Time to Focus on Data-Centric Security

Getting actionable intelligence about the data breach landscape isn’t always easy. Fortunately, the annual [Verizon Data Breach Investigations Report](https://www.verizon.com/business/resources/T23a/reports/2025-dbir-data-breach-investigations-report.pdf) (DBIR) is an exception to the rule. Based on the tech firm’s incident response engagements, as well as those of numerous third-party partners, it’s as good an annual snapshot as you’re likely to get. This year’s report features analysis of over 22,000 security incidents, including 12,195 confirmed data breaches.

The big takeaway for 2025 is that threats are rising on multiple fronts. It reminds us that the average corporate attack surface remains extensive, human error is an ever-present and supply chains are a constant source of risk. Faced with such odds, the best way of mitigating threats to corporate data is to secure it at source.

## What the DBIR says

Among the main trends highlighted in this year’s report are:

- A doubling in EMEA of “system intrusion” events, to account for 57% of all breaches in the region. These are sophisticated attacks using malware or hacking techniques
- A 37% annual increase in ransomware, which is now present in 44% of breaches globally
- Information-stealing malware on the rise: over half of ransomware victims had their domains appear in infostealer logs
- BYOD risks increase: 46% of systems compromised with an infostealer with possible corporate login data were non-managed devices
- Credential abuse (22%) exploitation of vulnerabilities (20%) and phishing (19%) were the top three initial access vectors for breaches
- Vulnerability exploitation (as a source of data breaches) increased 34% annually, thanks to a rise in zero-day threats
- The human element: employees were involved in 60% of breaches—around the same as last year—with credential abuse and phishing a major challenge
- Supplier risks: data breaches involving third parties doubled annually to 30%

## Financial services and retail faring no better

Breach rates in financial services and retail firms assessed in the report remained relatively stable compared to the previous year. In the former, threat actors were successful “about a third of the time.” Notably, in financial services, more breaches this year involved not just a financial motive but also one of espionage; indicating that more sophisticated actors may be targeting the sector. System intrusion, social engineering and “basic web application attacks” represented three-quarters (74%) of breaches.

In the retail sector, there was a notable rise in espionage-driven attacks compared to last year. As per financial services firms, organizations in this sector need to worry most about system intrusion, social engineering and basic web application attacks, which accounted for 93% of all breaches. In web app attacks, credential reuse by negligent employees was a major source of risk, Verizon says.

## Protecting what matters most

All of which points to one simple truth: threat actors have multiple avenues via which to reach sensitive enterprise data, and many techniques to get them there. Even when it comes to credential compromise, it’s more than simple username/password combos that they’re after. The report says that secrets related to web applications, CI/CD development environments, cloud infrastructure and databases were also targeted.

So how should IT and security leaders go about mitigating data breach risk? The first obvious step is to protect the data itself. The larger and more dynamic the data environment, the greater the need for automated tooling to continuously discover and classify such data, before protecting it in line with policy. In terms of protection, tokenization is increasingly favored as it allows enterprises to continue leveraging it in cloud-based analytics platforms without exposing it to compromise or compliance risk.

By all means, layer up defenses on top of this, including:

- Roles-based access controls, least privilege policies and multi-factor authentication
- Network monitoring
- Strong data governance
- Cloud workload protection
- Cyber-hygiene, including risk-based patching

However, none of these steps is a silver bullet. They may deter rudimentary attacks, but not necessarily determined, sophisticated threat actors. That’s why, in order to mitigate data breach risk, it pays to adopt a mantra of data-centric security.

---

comforte is offering your business a 30-day free trial of comforte Data Discovery and Classification, which features a new SaaS console manager. During the period, you’ll get a close-up look at how the product works *in situ*, and obtain a detailed understanding of where security and compliance risk exists across the organization. Most importantly, you’ll be able to see how the product could help to streamline your PCI DSS 4.0 compliance processes.

*[Get in touch](https://offer.comforte.com/free-30-day-health-check-for-sensitive-payment-data?hsLang=en) today to start your free trial. We’re here to take the pain away from PCI DSS compliance.*

---

| Share this:  | [![LinkedIn](https://insights.comforte.com/hubfs/Social%20Icons/linkedin%20icon.png)](https://www.linkedin.com/shareArticle?mini=true&url=https://insights.comforte.com/hackers-are-spoilt-for-choice-its-time-to-focus-on-data-centric-security&utm_medium=social&utm_source=linkedin) | [![Bluesky](https://insights.comforte.com/hubfs/Social%20Icons/bluesky_logo.png)](https://bsky.app/intent/compose?url=https://insights.comforte.com/hackers-are-spoilt-for-choice-its-time-to-focus-on-data-centric-security&utm_medium=social&utm_source=Bluesky) | ![Twitter](https://insights.comforte.com/hubfs/Social%20Icons/twitter_x_logo-1.png) | [![XING](https://insights.comforte.com/hubfs/Social%20Icons/xing-color2.png)](https://www.xing.com/spi/shares/new?url=https://insights.comforte.com/hackers-are-spoilt-for-choice-its-time-to-focus-on-data-centric-security&utm_medium=social&utm_source=xing) | [![Email](https://insights.comforte.com/hubfs/Social%20Icons/email%20icon.png)](mailto:?subject=Check%20out%20https://insights.comforte.com/hackers-are-spoilt-for-choice-its-time-to-focus-on-data-centric-security&utm_medium=social&utm_source=email%20&body=Check%20out%20https://insights.comforte.com/hackers-are-spoilt-for-choice-its-time-to-focus-on-data-centric-security&utm_medium=social&utm_source=email) |
| --- | --- | --- | --- | --- | --- |

## Free 30-Day Health Check for Sensitive Payment Data 

Accelerate PCI Compliance with Automatic Discovery and Classification of PANs and Cardholder Data

[![Start Your Free Trial Today](https://no-cache.hubspot.com/cta/default/4026697/b524802b-4c2a-4a07-8630-c282723556aa.png)](https://cta-redirect.hubspot.com/cta/redirect/4026697/b524802b-4c2a-4a07-8630-c282723556aa)

### Related posts

![Reuse, Reward: How Banks Can Safely Unlock the Value of Their Data](https://insights.comforte.com/hubfs/comforte%20AG_%20Reuse%20Reward_%20How%20Banks%20Can%20Safely%20Unlock%20the%20Value%20of%20Their%20Data_03.2025.png)

 Mar 12, 2026 l [Data Protection](https://insights.comforte.com/tag/data-protection) , [Payments Transformation](https://insights.comforte.com/tag/payments-transformation) , [Business Value](https://insights.comforte.com/tag/business-value)

### [Reuse, Reward: How Banks Can Safely Unlock the Value of Their Data](https://insights.comforte.com/reuse-reward-how-banks-can-safely-unlock-the-value-of-their-data?hsLang=en)

The financial world is awash with data. But too few organizations are able to use it effectively. In [Bank Director’s *2025 Technology Survey*](https://www.bankdirector.com/wp-content/uploads/2025/09/2025TechReport-OpenVersion.pdf), one-third of US banking leaders cite an inability to harness data as a top technology challenge facing their...

[Read more](https://insights.comforte.com/reuse-reward-how-banks-can-safely-unlock-the-value-of-their-data?hsLang=en)

![Delivering a Secure, Trusted Foundation for Cloud Growth at LGT](https://insights.comforte.com/hubfs/comforte%20AG_Delivering%20a%20Secure%2c%20Trusted%20Foundation%20for%20Cloud%20Growth%20at%20LGT_01.2026.png)

 Jan 15, 2026 l [Data Protection](https://insights.comforte.com/tag/data-protection) , [Business Value](https://insights.comforte.com/tag/business-value)

### [Delivering a Secure, Trusted Foundation for Cloud Growth at LGT](https://insights.comforte.com/delivering-a-secure-trusted-foundation-for-cloud-growth-at-lgt?hsLang=en)

There’s a world of difference between retail and private banking. While the former is transactional and focused on the mass market, the latter is built on trust and personal relationships. That trust can be hard won, but is easily lost, especially...

[Read more](https://insights.comforte.com/delivering-a-secure-trusted-foundation-for-cloud-growth-at-lgt?hsLang=en)

![Top Indicators You Have a Cybersecurity Problem—and What to Do About It](https://insights.comforte.com/hubfs/comforte%20AG_Top%20Indicators%20You%20Have%20a%20Cybersecurity%20Problem_and%20What%20to%20Do%20About%20It.png)

 May 22, 2025 l [Data Protection](https://insights.comforte.com/tag/data-protection) , [Digital Enablement](https://insights.comforte.com/tag/digital-enablement)

### [Top Indicators You Have a Cybersecurity Problem—and What to Do About It](https://insights.comforte.com/top-indicators-you-have-a-cybersecurity-problem-and-what-to-do-about-it?hsLang=en)

Data is both blessing and curse to the modern enterprise. Yes, when analyzed effectively it can surface intelligence to improve decision making, customer engagement, process efficiency and, ultimately, drive revenue. But it also represents a major...

[Read more](https://insights.comforte.com/top-indicators-you-have-a-cybersecurity-problem-and-what-to-do-about-it?hsLang=en)

### Service

- [Contact](https://www.comforte.com/contact/)
- [About us](https://www.comforte.com/company/)
- [Blog](https://insights.comforte.com/)
- [Press Releases](https://www.comforte.com/company/press-releases/)
- [Career](https://www.comforte.com/company/career/)
- [Resources](https://www.comforte.com/resources/)

### Germany

comforte AG  
Abraham-Lincoln-Str. 22   
65189 Wiesbaden  
Germany

Phone: + 49 611 93199 00  
Fax: + 49 611 93199 05

### Australia

comforte PTY  
Suite 20, 1 Rivett Road  
North Ryde  
NSW 2113  
Australia

Postal Address:   
PO Box 1710  
Lane Cove  
NSW 1595  
Australia

Phone: +61 2 8197 0272

### USA

comforte Inc.  
30 Wall Street, 8th Floor  
New York, NY 10005-2205  
USA

Phone: +1-646-438-5716

### Singapore

comforte Asia Pte. Ltd.   
1 Raffles Place, #19-61 Tower 2   
Singapore 048616

Phone: +65 6808 5507

- [Sitemap](https://www.comforte.com/sitemap/)
- [Legal Notice](https://www.comforte.com/legal-notice/)
- [Privacy Policy](https://www.comforte.com/privacy-policy/)

© comforte AG 2026

<https://x.com/comforteag> <https://www.youtube.com/c/comforte-ag> <https://www.linkedin.com/company/comforte-ag/>