Kaseya has released its 2026 Cybersecurity Report: Building Security That Survives Human Error, based on responses from 1,132 managed service providers (MSPs) and IT professionals across more than 60 countries.
The survey found human error — including social engineering and distraction — was the top threat vector for 68% of respondents over the next 12 months, followed by email at 55%. Among organisations that reported a security incident in the past three years, four of the top five contributing factors were people-related, led by poor user practices or gullibility (41%) and a lack of end-user cybersecurity training (40%).
“People aren’t perfect, and everyone knows it. Yet much of cybersecurity still depends on people making the right decision every time,” said David Baggett, SVP and GM, Security Suite, Kaseya. “The path to true cyber resilience isn’t about eliminating mistakes. It’s about building an organisation that can withstand them. Expect mistakes, account for constraints and engineer around them.”
On compliance, nearly 65% of respondents said they could pass a compliance audit without preparation. However, when asked what could create problems during an audit, 49% cited incomplete documentation or policies, 34% cited security controls that were not fully implemented, and 33% pointed to a lack of employee security awareness or training.
The report also points to resourcing gaps. Only 20% of IT departments said their cybersecurity budget was growing in line with risk, while 77% described themselves as under-resourced. Respondents attributed the shortfall to budgets being held flat while threats grow (23%), budgets growing too slowly to keep pace (30%), or being under-resourced and aware of it (24%). MSPs reported similar patterns among their clients, with 65% saying clients were underinvested in cybersecurity relative to their risk.
Kaseya said it is introducing an MSP resilience assessment, defining high and low performers by whether they met both revenue and growth goals over the last two quarters. The company said the assessment found higher-performing MSPs were more likely to test incident response plans quarterly (almost 30% versus 18% among low performers), and less likely to report having no incident response plan (11% versus 25%). Across all MSPs surveyed, 15% reported not having an incident response plan.
The report also compared security tool adoption between groups. It found higher-performing MSPs reported higher adoption of SIEM (48% versus 31% among low performers), NDR (52% versus 27%), and cloud security/CNAPP (32% versus 13%).
The report concludes with a five-part playbook focused on designing controls around expected mistakes, making the case for investment before an incident, reducing operational friction, using AI to extend overstretched teams, and treating compliance as continuous work rather than a once-a-year effort.
You can read the full report here.

