Every day, the CyberMaxx TRT responds to attacks that don’t fit neatly into categories. A user clicks a phishing link. Email should have stopped it. It didn’t. Now the attacker has credentials. Identity systems should flag the unusual login. The organization isn’t monitoring identity in real time. The attacker creates an inbox rule to hide further emails. Enrolls a device under the compromised account. By the time anyone notices, the foothold is deep.

These aren’t hypothetical. They’re the patterns we’re seeing across our customer base right now.

The Q2 2026 Ransomware Research Report shows ransomware threats are accelerating with 2,579 attacks in Q2, up 13 percent from Q1. The number of active ransomware groups hit 106, a 53.6 percent jump from last quarter. The landscape is fragmenting faster, and attackers are chaining exploits differently. What the report data doesn’t show is equally as important: how attacks move silently across your infrastructure when defenses operate independently.

The Pattern We Keep Seeing

Inbound phishing campaigns hit organizations regularly. An accounting firm is targeted. Fifty users get a phishing email. Two fall for it. One gets caught by email security. The other bypasses it, lands in the inbox, and the user clicks. Now the attacker has valid credentials.

What happens next depends on what you’re monitoring.

You’re watching email only. The incident stops. You flag it; the user resets their password; you move on. You never see what the attacker does with those credentials in the next 48 hours before the reset propagates everywhere.

You’re watching identity. You catch the impossible travel or the geographic anomaly. Except half your customer base isn’t monitoring identity in real time. They’re monitoring endpoints and betting threats show up there.

You’re watching the endpoint. You might catch malware. You won’t catch an attacker using valid credentials to move through your environment and create an inbox rule to hide further emails. You won’t catch PowerShell obfuscation or reconnaissance tools getting downloaded. You’ll see the alert, respond, and think it’s contained. You’ll miss the lateral movement happening on the network.

This is what we’re responding to in the TRT. Attackers who exploit the gaps between the monitoring zones.

What the Incidents Reveal

Over the past months, we’ve escalated incidents hitting multiple vectors at once. A financial services organization got hit with a BEC campaign targeting 37 users. Two were compromised. The attacker used those accounts to enroll new devices. Endpoint monitoring sees the enrollment. Identity monitoring sees nothing. Now your investigation is incomplete. Email monitoring never flagged the BEC in the first place, so you don’t know the entry point.

We’ve seen OAuth device code anomalies targeting executives. These attacks live at the intersection of email, identity, and cloud. A user gets a phishing email with a device code link. They consent. The attacker now has a token to access cloud resources. Never touched the endpoint. Traditional endpoint-focused detection sees nothing.

We’ve investigated PowerShell obfuscation alerts. The host was compromised. But the network layer tells you something else. There’s SSH enumeration. There’s lateral movement to systems without visibility. By the time you’re done with the endpoint investigation, you’ve missed the scope.

We’ve caught malicious inbox rule creation. Not malware. Not a vulnerability. An attacker with valid credentials creating a rule to hide emails. The inbox rule is an identity attack. It leads to exfiltration through email. It hides the trail. Single-vector monitoring catches the rule. It doesn’t catch the credential compromise that enabled it.

We’ve responded to Teams-based social engineering. External threat actor calls a user posing as IT, fishing for credentials. Email monitoring doesn’t see Teams calls. Identity monitoring sees the login attempt. But if you’re not correlating across vectors, you’re analyzing a Teams incident in isolation. You’re not seeing it as part of a broader campaign targeting multiple users across email, Teams, and identity.

The Business Cost of Gaps

Every one of these incidents has a cost structure tied to dwell time. The longer an attacker operates undetected, the further they move. The broader they spread, the more expensive containment becomes. The more systems they touch, the harder remediation gets.

A compromised account sitting dormant for 48 hours costs more to investigate than one caught in four. Lateral movement that reaches your network infrastructure before you spot it costs more than catching it at the endpoint. A cloud environment where an attacker has overprovisioned access costs more to remediate than catching the unauthorized API call in real time.

That’s why “zero-latency response” isn’t marketing. It’s an operational necessity. An attacker moving across five vectors needs to be interrupted at every layer. If you’re defending three, the math works in their favor. By the time you’ve figured out the scope, the damage is compounding.

For organizations that can’t staff five separate monitoring teams, the gap gets worse. You pick two vectors. You hope attackers don’t find the other three. Most of the time, they do.

What Changes with Layered Coverage

The incidents we manage differently are the ones where monitoring spans email, identity, endpoint, network, and cloud at the same time.

The phishing email arrives. Email security catches it pre-delivery, or it lands and gets reported. Identity monitoring watches for the credential compromise. Endpoint monitoring looks for malware or obfuscated scripts. Network monitoring tracks lateral movement. Cloud monitoring alerts on unauthorized API calls. An attacker triggers an alert at any layer, and the response team sees the full chain, not a single event.

The BEC campaign hit 37 users. Email alerts. Identity shows which accounts were actually compromised. Endpoint shows what actions those accounts took. Network shows if they moved laterally. Scope is clear. The response is surgical.

OAuth anomaly surfaces as an identity alert. You know immediately which account was compromised, when, and from where. Cloud monitoring shows what resources got accessed. You revoke tokens. You contain access. You respond to the full scope once. Not the identity piece first, then the cloud piece, then the email piece three days later when someone notices.

PowerShell obfuscation alerts on an endpoint. Doesn’t stop at “kill the process.” Network monitoring shows if that process tried external communication. Identity shows if it authenticated as another user. Cloud shows if it accessed resources. You’re not remediating an endpoint infection. You’re remediating an attack with tentacles across your infrastructure.

The Strategic Move

The Q2 data tells us something clear: the threat landscape is expanding, fragmenting, and becoming more accessible to threat actors. Your incident volume is rising. Your complexity is rising. Your resources are staying flat.

Hoping attackers trigger an alert at one of your monitoring points isn’t strategy. It’s luck.

Organizations that move to cross-vector detection now will handle fewer incidents next year. They’ll catch attacks earlier and on a broader scope. They’ll spend less time investigating and more time responding. They’ll know what happened, where, and how to fix it before persistence sets in.

Organizations that wait will keep seeing incidents in silos. Endpoint alert first. Email alert three hours later. On Thursday you realize the lateral movement never got flagged at all.

CyberMaxx TRT is already operating this way. The incidents we manage most effectively are the ones where we see all five vectors at once. The incidents that escalate to DFIR, that require forensics, that cost the most to remediate are the ones where one or more vectors went dark.

The choice isn’t between monitoring email or endpoints. It’s between defending the attack surface your attackers are actually using or defending only the portions you hope they’ll stick to.

Given what we’re seeing in your incident stream, hope isn’t a strategy.

Moving From Coverage Gaps to Comprehensive Defense

Organizations ready to close these gaps don’t need to do it alone. Partnership with a mature MDR provider means taking concrete action across each vector.

Identity: granting the MDR engineering team direct access to Entra ID credentials and Azure AD telemetry, so identity monitoring isn’t limited by API constraints or delayed log delivery. Real-time identity monitoring requires real-time access.

Email: integrating a managed email security platform as a core component of the MDR solution, not bolting it on separately. When email detection feeds directly into the same investigation and response workflow as endpoint and network alerts, phishing campaigns become traceable attack chains instead of isolated incidents.

Endpoint: deploying best-in-class EDR solutions—not because endpoint monitoring is sufficient, but because EDR is the foundation. Pairing that with Novel Detections tuned to current adversary TTPs fills the gaps that vendor rule-based detection misses. ClickFix, PowerShell obfuscation, device enrollment abuse—these require detection logic built for today’s attacks, not yesterday’s.

Network: moving beyond endpoint-only MDR. Lateral movement, C2 communication, and east-west traffic are invisible to tools that only see individual hosts. Network monitoring requires deployment of collection infrastructure and analysis tooling that understands traffic patterns at scale.

Cloud: granting the MDR team access to ingest cloud audit logs directly. AWS CloudTrail, Azure Activity Logs, GCP Audit Logs, and M365/Entra telemetry should flow into the same SOC that monitors the other four vectors. Cloud misconfigurations and unauthorized API activity only get caught when someone is actually looking.

None of this requires ripping out existing tools or replacing your security stack. It requires making the deliberate choice to extend coverage where it’s missing, then giving your MDR partner the access, and integration points they need to defend comprehensively. The organizations handling fewer incidents next year will be the ones that made that choice now.