Catch up with Phoenix’s SOC Team as they unpack the key findings from our Threat Report 2026, and what they mean for your organisation.
- Why identity compromise has overtaken traditional exploitation as the leading way attackers get in
- How ransomware groups are operating, and why the threat continues to grow despite law enforcement action
- The threat groups and nation state activity shaping the current landscape, and who they target
- Practical, prioritised recommendations your team can act on straight away
- Answers to real audience questions, covered in an extended Q&A with our SOC Team
Watch our on demand session on the Threat Report 2026. Find out what the findings mean for your organisation’s security posture, with extended Q&A from the live session.
Introduction
Meet Fred, Luke and Ryan from our SOC team, and find out why this year’s threat landscape matters for organisations of every size and sector.
The state of the threat landscape
Explore the surge in exploit activity, the continued dominance of ransomware, and how identity compromise has overtaken traditional exploitation as the leading way in.
Threat groups and nation state activity
A look at the groups shaping the current landscape, how they operate, and who they target.
What this means for your organisation
Practical, prioritised recommendations your team can act on straight away to strengthen resilience.
Extended Q&A
Most of this session covered open Q&A, where our SOC Team answered real questions from attendees, offering direct, practical guidance.
The first quarter of 2026 brought a marked shift in the threat landscape. Exploit activity surged by 247%, and ransomware remained the most disruptive threat category. Identity compromise overtook traditional exploitation as the leading route into organisations.
Watch to get direct insight from the Phoenix SOC Team behind the report. Most of the hour was spent answering audience questions, now available to watch in full.
Meet the speakers:
Fred Astfeldt
Head of Managed Security Solutions
Luke Walker
Senior SOC Analyst
Ryan Groom
SOC Development Manager

