Google Cloud Blog
Follow
Key findings from the 2026 Public Sector M-Trends report and beyond
The public sector is no longer defending a traditional perimeter, but rather a complex web of interconnected trust relationships against adversaries operating at machine speed. The 2026 Public Sector Threat Landscape report highlights key findings from over 500,000 hours of frontline incident investigations conducted by Mandiant in 2025. One alarming trend is the 22-second hand-off between an initial access broker and a ransomware operator, rendering traditional triage methods obsolete. Adversaries are exploiting emerging boundaries of trust, including the persistence paradox, where state-sponsored actors remain undetected for years, and the virtualization stack, where attackers target the virtualization management plane. The report also notes the SaaS domino effect, where a single compromise can trigger a chain reaction across an agency network, and the vishing surge, where voice phishing attacks target government help desks. To combat these threats, a cultural pivot to continuous verification is necessary, where trust is never assumed and must be constantly re-validated. Google provides technical architecture to support continuous verification through three core capabilities: identity as the new perimeter, agentic defense, and hardened infrastructure. The company's security technology has been successfully implemented in various public sector agencies, such as the Pasco Sheriff's Office and the State of Connecticut. These agencies have shifted from manual triage to agentic defense, improving efficiency and community safety. The 2026 Public Sector Threat Landscape report and related resources, such as the Gemini for Government webinar, offer strategic recommendations and insights for public sector leaders to secure their future.