| 1 | Threat / Category Advisory operating model Security assessments need to end in an owned 12-to-18-month roadmap[6]Evidence dated Jul 6, 2026 | Why it mattersKroll describes a conversation-heavy assessment process that translates policy, technology, and process findings into recommendations. The value is not the questionnaire; it is a governed sequence of risk-reduction decisions. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Kroll exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 2 | Threat / Category AI-speed exposure management Discovery is becoming abundant; remediation velocity is the scarce resource[3]Evidence dated Jun 17, 2026 | Why it mattersKroll argues that AI compresses vulnerability discovery and weaponization timelines. Leaders need inventory, ownership, prioritization, remediation, verification, and board-ready evidence that exposure actually decreased. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Kroll exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 3 | Threat / Category Governance The second line must challenge whether cyber risk is actually controlled[5]Evidence dated Jun 5, 2026 | Why it mattersKroll applies the Three Lines of Defense model to cyber speed and complexity: operations own risk, the second line independently challenges and monitors it, and audit supplies objective assurance. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Kroll exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 4 | Threat / Category Threat economics Attackers are industrializing known weaknesses instead of waiting for exotic zero-days[2]Evidence dated May 18, 2026 | Why it mattersKroll identifies weak identity, poor authentication, misconfiguration, social engineering, and automation as the scalable attack engine. A disciplined known-exposure program can therefore remove more risk than novelty-driven prioritization. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Kroll exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 5 | Threat / Category Identity risk Non-human identities can survive a human credential reset[2]Evidence dated May 18, 2026 | Why it mattersKroll highlights API keys, service accounts, and machine credentials as privileged, persistent, and often weakly monitored. Incident containment that resets only employee credentials may leave a durable access path. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Kroll exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 6 | Threat / Category Resilience survey Cyber strategy and business priorities remain misaligned[4]Evidence dated Mar 18, 2026 | Why it mattersIn Kroll's survey of 1,000 decision-makers across 10 countries, 72% reported a gap between cybersecurity strategy and business priorities. Governance must translate security work into business outcomes and accepted risk. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Kroll exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 7 | Threat / Category Incident economics The reported average financial impact exceeds $20.9 million[4]Evidence dated Mar 18, 2026 | Why it mattersKroll's surveyed organizations reported average potential financial impact above $20.9 million. The figure is a survey result, not a universal loss average, but it supports explicit scenario quantification. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Kroll exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 8 | Threat / Category Response readiness Plans are widespread, but rapid response confidence is not[4]Evidence dated Mar 18, 2026 | Why it mattersKroll reports that 99% of surveyed organizations have an incident-response plan, while only 19% believe they can respond within minutes. Exercises should measure mobilization, containment, decision, and recovery time rather than document existence. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Kroll exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 9 | Threat / Category Enterprise-risk integration Threat exposure management now belongs to the CISO, CFO, General Counsel, CRO, and board[3]Evidence dated Jun 17, 2026 | Why it mattersKroll frames exposure as a shared enterprise-risk discipline requiring technical reachability, financial impact, legal posture, ownership, documentation, and defensible decisions. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Kroll exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 10 | Threat / Category Human attack surface AI can turn fragmented public and breached data into executive-grade social engineering[2]Evidence dated May 18, 2026 | Why it mattersKroll warns that AI can aggregate records, credentials, and social context into targeted fraud and extortion. Executive protection and high-risk transaction verification should be treated as cyber controls. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Kroll exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 11 | Threat / Category Published threat baseline BEC, phishing, ransomware and crypto theft were converging into one monetization landscape[7]Evidence dated Aug 22, 2025 | Why it mattersKroll's first-half 2025 threat report describes BEC as prominent, phishing as the leading initial-access path, and Akira, PLAY and LockBit as persistent ransomware operations. The report is retained as the rolling year's opening baseline; its underlying observations predate part of this card's window. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Kroll exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 12 | Threat / Category Browser and crypto abuse CLEARFAKE and EtherHiding showed how trusted web traffic could carry credential and wallet theft[7]Evidence dated Aug 22, 2025 | Why it mattersKroll connects compromised websites, fake browser-update prompts and blockchain-hosted instructions to infostealer delivery and crypto theft. The useful control is to detect browser-to-script execution and wallet or credential access, not merely block one domain. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Kroll exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 13 | Threat / Category Software supply chain Shai-Hulud 2.0 moved npm compromise into pre-install execution, cloud-secret theft and destructive fallback[8]Evidence dated Nov 25, 2025 | Why it mattersKroll reports a wider second wave that targeted npm, GitHub and cloud credentials, used pre-install execution and could attempt destructive deletion when exfiltration failed. Package counts and repositories do not equal unique victim organizations. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Kroll exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 14 | Threat / Category Retail disruption Scattered Spider and Cl0p made identity abuse and third-party software risk board-level retail dependencies[9]Evidence dated Nov 26, 2025 | Why it mattersKroll's retail analysis connects social engineering and help-desk abuse with mass-exploitation campaigns and prolonged operational disruption. Retail continuity plans must assume identity compromise, supplier outages and trading interruption can arrive together. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Kroll exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 15 | Threat / Category Post-incident disclosure A breach changed how sampled companies described cyber risk for years afterward[10]Evidence dated Jan 23, 2026 | Why it mattersAcross annual reports from 12 breached firms, Kroll found cyber and incident language increased sharply after disclosure and remained elevated. The finding argues for decision-ready evidence, materiality governance and a durable remediation narrative before an incident forces the issue. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Kroll exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 16 | Threat / Category Retail resilience Retail defense has to protect the transaction, workforce identity and operating schedule—not only payment data[11]Evidence dated Feb 6, 2026 | Why it mattersKroll's retail guidance emphasizes social engineering, third-party access, business interruption and crisis coordination. Seasonal staffing and thin change windows make tested escalation and recovery capacity part of day-to-day loss prevention. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Kroll exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |