SecurityBrief Australia - Technology news for CISOs & cybersecurity decision-makers
Australia
Professional services face highest cyber intrusion volume

Professional services face highest cyber intrusion volume

Thu, 20th Aug 2026 (Today)
Mark Tarre
MARK TARRE News Chief

SonicWall has published research showing that professional services firms faced the highest volume of cyber intrusion activity among the industries it tracks. The sector recorded 3 billion intrusion prevention system events in the first half of 2026.

The findings cover law firms, accountancies, consulting practices, engineering firms, and managed service providers. In SonicWall's data, 460 organisations in the sector were actively detecting ransomware campaigns, the broadest exposure of any vertical it tracks.

The research draws on information from more than one million security sensors across SonicWall's global network. Professional services also recorded 69.9 million ransomware hits during the period, again more than any other monitored sector.

Attack patterns in the report point to a concentration of well-known exploitation methods rather than entirely new techniques. Directory traversal, malformed request probes, and remote code execution signatures accounted for 72% of all intrusion prevention volume seen in professional services.

Apache Log4j2, commonly known as Log4Shell, generated 107 million hits in the sector despite the vulnerability having been publicly disclosed and widely patched more than two years earlier. SIPVicious VoIP exploitation accounted for 332 million combined hits, with the relevant signatures ranking third and sixth by volume in the sector.

Ransomware activity was spread across several groups. SonicWall identified 10 active ransomware families operating against professional services firms at the same time, including Filecoder with 19.1 million hits across 113 organisations, Gandcrab with 11.9 million hits, and Ryuk with 10.5 million hits.

Privileged data

The report argues that the sector is a particularly attractive target because of the information it holds. Professional services businesses often manage active legal files, financial records, privileged communications, and, in the case of managed service providers, administrative credentials that can open access to clients' systems.

"Professional services holds the kind of data that carries built-in leverage," said Michael Crean, Senior Vice President of Managed Services at SonicWall. "Client records tied to active legal matters, financial transactions, privileged communications, and for MSPs, administrative credentials into dozens of other organizations' networks. We're not talking about harmless background data. For the client, it represents massive financial, legal, and reputational risk. Attackers know this value, and the data bears that out."

Managed service providers stand out because an attack on one supplier can extend far beyond its own systems. Administrative access to multiple customers can make an MSP a route into many organisations at once, increasing the potential value of a single compromise.

"An MSP breach is not one breach, it's potential access to every client environment that MSP manages," Crean said. "Ryuk and Sodinokibi don't show up in professional services by accident. They specifically target organizations that hold administrative access to other organizations, because one compromised credential can cascade into dozens of networks at once. That's not spray-and-pray, that's a calculated market decision."

Sector exposure

The figures add to a wider picture of growing cyber pressure on industries that handle sensitive third-party information. Professional services groups often combine large stores of confidential data with systems designed for routine sharing, including client portals, billing platforms, document management tools, and collaboration software.

That mix can leave firms exposed if older infrastructure remains in place or if access controls are too broad. SonicWall pointed to a case involving XimpleIT, a Colourado-based managed service provider focused on legal clients, which moved its law firm customer base to a different access model after a breach linked to an unpatched legacy virtual private network.

The shift replaced broad network trust with application-level access that requires continuous verification. It was intended to limit lateral movement across client environments, an issue that has become more significant where suppliers manage multiple customer estates.

Juan Serna, Founder and IT Director at XimpleIT, described the operational side of the company's relationship with SonicWall in a customer comment included in the announcement. "Having somebody, a real person, who checks in regularly, provides assistance implementing new solutions, and helps us win deals is a big differentiator," Serna said. "That is rare. SonicWall gives us the platform and the partnership to walk into a law firm and tell them, with confidence, that their data is protected, not just monitored."

The findings suggest that for professional services firms, cyber risk is being shaped as much by persistent weaknesses in widely used systems as by the value of the data they hold. SonicWall's dataset shows attackers continuing to rely on established routes into networks even as activity against the sector remains higher than in any other industry it tracks.