Kaspersky: many organisations host intrusions that have run for years

Kaspersky has summarised the findings from its 2025 compromise assessments. The picture is that many organisations carry ongoing or old incidents that neither standard security tooling nor a one-off incident response engagement catches. Threats frequently remain undetected for months or years, malware can survive in backups, and attackers routinely use legitimate administration tools that blend into normal operations.

What this means for your organisation

An absence of alerts is not the same as an absence of attackers. When a compromise has gone unnoticed for a long time, both the starting point for recovery and the value of the backups are weakened. For entities in scope of NIS2 this is also a compliance question, because the duty to detect and handle incidents assumes that somebody is actually looking.

Berigo recommends

  • Commission an independent compromise assessment of your critical environments, not just a technical vulnerability scan.
  • Establish regular threat hunting with defined hypotheses rather than waiting for tooling to raise alarms.
  • Test restoration from backup using a scenario where the backups themselves may be infected.
  • Log and follow up on the use of administration tools, particularly outside working hours and from unusual accounts.

Source

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch