Skip to main content

The Vilkas Wire

The 2026 Security Budget: Stop Buying Shiny Toys and Fix the Foundation

Oct 7, 2025 · By Ben Rollin

Pentest
cyber broken chain

Every year, new security products and services promise to solve the latest digital threats, yet the same basic vulnerabilities keep surfacing in corporate networks. In 2025, internal penetration tests continue to expose the same weaknesses highlighted in last year’s Top 10 Findings, proof that many companies still haven’t addressed foundational security gaps. As teams head into 2026 budget planning, it's more important than ever to ask: Are the basics finally covered, or are critical risks still lingering beneath the surface, waiting to be exploited?

In our Top 10 Internal Penetration Test Findings of 2024 post we covered the following 10 issues. These flaws have cropped up time and time again during internal penetration tests in 2025 against companies of varying sizes, across all industries.

  1. LLMNR/NBT-NS Response Spoofing
  2. Default ms-DS-MachineAccountQuota
  3. Administrative Password Reuse
  4. Active Directory Certificate Services (AD CS) - ESC1 Attack
  5. Weak Active Directory Passwords Allowed
  6. SMB Signing Not Enabled
  7. Default Credentials
  8. Weak Kerberos Authentication Configuration (Kerberoasting)
  9. DNS Spoofing via IPv6
  10. SMB Null Session

I'll throw in one of the honorable mentions, LDAP Signing/Channel Binding Disabled, because it still facilitates many of our footholds or one-shot attacks to domain compromise on a weekly basis.

These are not zero days or complex attack chains, many are issues that have been known to penetration testers and reported for a decade or more yet we keep seeing them. At this point you would think no single item on this top 10 list (or honorable mention) would be present in Active Directory environments yet they persist. Often 4-5 in a single report, sometimes more. These are companies that have been pentested year after year. Are penetration testers not up to the task and missing these basics? Are they being reported and the report just gets filed away as a checkbox requirement never to see the light of day again?

These are not issues that require a significant investment of time or money to remediate, yet we see them in companies using enterprise-grade EDR and third-party SOCs. While our attacks are often detected and sometimes blocked during non-evasive tests, we often see companies waiting hours to take any action on the alerts or alerts arriving very delayed. In that time a real-world attacker could likely already have made off with the crown jewels they came for, installed persistence, deployed ransomware, etc.


The Fundamentals Still Matter

There is always some hype in the infosec industry, lately AI driven tools. These advanced tools are great, when set on top of a strong foundation. But when the foundation is a house of cards, and everything comes crashing due to a very basic attack, what good are these tools? Vendors make bold promises, and we see companies rushing to spend money on these tools yet often penetration testing budgets are small and companies look to economize. You get what you pay for. Companies won't risk paying the least expensive attorney to draft up their contracts, so why do they often look for the best bargain when looking at penetration testing vendors?

A good penetration tester, well-versed in a multitude of attacks with the ability to quickly uncover issues and move effortlessly through a network has often spent a decade or more honing their craft. Their work, which in the end is typically just represented in the report deliverable, should be high priority for the company to remediate. If a penetration tester gets into a network where the fundamentals are properly accounted for, they will have to get noisier and noisier, leading to detection. The same goes for attackers.


The Risks of Overlooking the Basics

There have been many high-profile breaches in 2024 and 2025 and they're often caused by a breakdown in the fundamentals. Default credentials, Kerberoasting, weak passwords, you name it, these are all issues that must be addressed before deploying the latest and greatest tool. If your Enterprise Admin password is Welcome1 and stored in the description field in LDAP, how well will these tools truly protect you when it matters?

If you metaphorically lock the door but leave the keys under the mat, the attacker's job is easy. With a weak, clear text password, they can often blend in with standard network traffic and if they are detected at all, it may be too late.

One of our consultants recently performed an internal penetration test in which they were able to perform NBT-NS Response Spoofing and relay privileged user credentials to the LDAP service on a domain controller, resulting in domain compromise. This happened within the first 10 minutes of connecting to the network. The SOC only noticed credential dumping 5 hours later, and likely only due to it being done in the most noisy way possible.


Budget Planning for 2026: Key Questions to Ask

When planning for 2026, organizations should take a step back and ensure that the basics are being covered, and validated by a skilled penetration tester. Below are some key questions we believe every company should be asking:

  • Have basic controls been verified?
  • Are recurring vulnerabilities actually fixed?
  • Is staff security awareness training current?
  • Are legacy systems inventoried and monitored?
  • Is privileged access regularly reviewed?
  • Is patch management automated and enforced?

The Case for Foundational Security Investments

At Vilkas we believe every company should be prioritizing budget on the basics: secure configuration management, regular assessments, training, asset management. Advanced solutions (i.e., XDR/MDR) have their place and should be layered in, but on top of a strong security foundation. Some companies we test are doing this well, but many are not. This trend has been going on for well over a decade and there needs to be a fundamental shift in thinking back to the basics, prioritizing skilled manual testing and in lieu of timeboxed, scoped down, compliance checkbox assessments that provide little to no value.


Action Plan: Making 2026 Secure

Below are some actionable steps for CISOs/IT leaders for 2026 and beyond:

  • Schedule a baseline security assessment with an independent consultant.
  • Allocate budget for recurring vulnerability and penetration testing.
  • Implement continuous monitoring of basic controls before investing further in complex solutions.
  • Use a recurring issue list such as this post as an annual checklist to be sure the basics are being covered, and no issues that were remediated in the past pop up again.

Closing Thoughts

Don’t let expensive technology blind you to foundational risks. We can shout about the basics from the rooftops all day long, but if they are not taken seriously then we will continue to see battered networks with expensive bandages covering them.

Make it difficult for your penetration tester to gain a foothold. If they have to ask for standard domain user credentials after a day or so of attempting to gain a foothold, great. If they are unable to move laterally or escalate privileges in the domain once they receive credentials, then you are likely doing many things right. If they are unable to move at all and your internal or third-party SOC detects them every step of the way then you have built a strong foundation and layered controls on top effectively.

Don't rely solely on EDR, as we are seeing ransomware gangs who are able to disable it at the kernel level, rendering it blind. If they're able to get in because of human error or a breakdown in the basics its often already too late. Don't make it easy for them either.


Have a question about this article or a security challenge of your own?

Vilkas Cybersecurity helps organizations uncover and fix real-world exposures, not just theoretical ones. Fill out the form and we'll get back to you shortly.

Loading form…