GOVERNMENTS emerged as the sector most affected by cyber threats in 2026, accounting for 27% of observed activity and increasingly targeted by nation‑state actors. The Microsoft Digital Defense Report highlights that governments sit at the centre of networks spanning agencies, contractors, technology providers and critical infrastructure, making them attractive and high‑value targets.
Dwell time—the interval from initial access to detection and response—also rose across sectors, with attackers often blending in as legitimate activity. Phishing remained a dominant entry point, responsible for 23% of observed intrusions in 2026, up from 7% in 2025, underscoring the continuing risk of credential compromise.
The report argues that resilience in the AI era requires rethinking security as an ecosystem challenge rather than a series of isolated incidents.
It sets out five priorities for strengthening government preparedness: (1) prepare for a faster threat environment, recognising that vulnerabilities can move from discovery to weaponization in under 24 hours and that 72,000 publicly disclosed CVEs are projected for 2026; (2) build security into the AI ecosystem with secure‑by‑design practices, stronger supply chain protections,
transparency and international cooperation; (3) plan for incidents to spread, ensuring response plans account for how intrusions can evolve and cross boundaries; (4) enable timely, two‑way public–private information sharing to derive actionable intelligence and coordinated response; and (5) prepare essential services to operate through disruption, using tabletop exercises and shared service models to extend capabilities beyond central governments.