There is a version of cybersecurity that looks impressive and a version that works. They are rarely the same thing.
The habits that prevent the most incidents are unremarkable. A password used in one place only. Multifactor authentication turned on. Updates installed when they appear. A device that locks when you step away. A question asked before an unusual request gets acted on. None of it is interesting, and all of it is where the data keeps pointing.
What the Numbers Favor
The 2026 Verizon Data Breach Investigations Report tracked a meaningful shift this year. Exploitation of vulnerabilities has become the most common initial access vector for breaches at 31 percent, overtaking credential abuse, which fell to 13 percent.
That shift is a warning about where attackers are finding the easiest path in. Credential abuse remains a major threat, but vulnerability exploitation has overtaken it as the most common initial access vector. At the same time, remediation data shows organizations are struggling to keep pace with known exploited vulnerabilities. Only 26 percent of CISA Known Exploited Vulnerabilities were fully remediated by organizations in the dataset, down from 38 percent the year before, while the median time to full resolution increased from 32 to 43 days.
Most of that work belongs to IT teams. The part that belongs to you is the update prompt you keep dismissing on your laptop, your phone, and your browser.
Passwords Still Decide a Lot of Outcomes
In education breaches involving hacking actions, stolen credentials appeared in 65 percent of cases. Attackers often do not need to crack passwords when they can use credentials that have already been stolen. Reusing passwords across accounts makes that risk considerably worse.
Current NIST guidance has moved away from the rules most of us learned. Length matters more than complexity, so a long passphrase beats a short password with a few symbols wedged into it. Forced periodic changes are no longer recommended without evidence of compromise, because they push people toward predictable variations of what they already had. Screening passwords against lists of known-compromised credentials does more good than any composition rule.
The practical translation is short. Make it long, make it unique, and let a password manager carry the ones you cannot remember.
Why MFA Earns Its Place
Multifactor authentication is what keeps a stolen password from becoming a compromised account. It is also the control most likely to be only half implemented. In third-party cloud environments, just 23 percent of organizations fully remediated missing or improperly configured MFA, and problems involving weak passwords and permission misconfigurations took close to eight months to resolve in half of cases.
Turn MFA on everywhere it is offered, not only where it is required. Where you get a choice of method, an authenticator app or a security key is stronger than a code sent by text message.
The Rest of the Table
Ransomware appeared in 48 percent of all breaches this year, up from 44 percent. More encouragingly, 69 percent of victims chose not to pay. Backups, current patches, and early reporting are what make refusing to pay a realistic option rather than a brave one.
The Habits Worth Building
- Use a unique passphrase for every account, and a password manager to keep track of them.
- Turn on multifactor authentication everywhere it is available, and choose an app or security key over text messages when you can.
- Install updates on your devices, browsers, and applications when prompted instead of deferring them.
- Lock your screen whenever you walk away, at the office and at home.
- Keep university work on managed, supported devices.
- Back up anything you cannot afford to lose, and confirm occasionally that the backup is actually running.
- Report anything that looks wrong early, even when you are not certain it is anything at all.
If Something Goes Wrong
If you reused a password that has since turned up in a breach, entered credentials on a page you are unsure about, or approved an MFA prompt you did not initiate, change the password and report it right away. An approved prompt you did not request means someone already has the password, and that is worth acting on the same day.
For questions about an account, a login, or a suspicious prompt, the Office of Information Security would rather hear from you early than late. For device or access issues, contact your campus help desk. A full list of campus contacts is available on the Universities of Wisconsin IT Help Desks page.