Corporate & Thought Leadership

Objection Overruled: Professional Services Has a Bigger Target on Its Back Than Anyone Realizes

by Jordan Riddles

3 billion IPS events, 70 million ransomware hits and a phone system attackers have quietly turned into an entrance.

Professional services doesn’t often garner the same cybersecurity headlines as healthcare or finance. But it probably should.

In the first half of 2026, the sector generated more IPS events than any other vertical SonicWall tracks. 

Not more per device. 

More in total. 

3 billion events across law firms, accountancies, consulting practices, engineering firms and MSPs. And the reason isn’t that professional services firms are uniquely careless. It’s that they collectively hold exactly what attackers want: client records, privileged communications, financial data, and in the case of MSPs, administrative access to the infrastructure of dozens of other organizations. And they’re built to be accessible by design.

That accessibility is the product. It’s also the vulnerability.

Your Phone System Is an “Open” Sign

Here’s the finding in SonicWall’s 2026 Professional Services Protect Brief that should stop any IT professional in this sector mid-scroll: 332 million SIPVicious hits in the first half of 2026. Professional services is the only vertical where this signature appears at this scale. Not one of the top verticals. The only one.

SipVicious_Chart_2.png

SIPVicious is a tool used to scan and exploit Session Initiation Protocol (SIP) infrastructure, the protocol that runs most Voice over Internet Protocol (VoIP) phone systems. An exposed SIP endpoint doesn’t just enable call fraud (though, that’s also pretty bad). It provides a foothold into every system that shares network access with the phone infrastructure. For a law firm or consulting practice where the phone system sits on the same network as client portals and document management platforms, that foothold is uh, kind of a big deal.

The reason professional services is uniquely exposed here is structural. These firms run distributed phone infrastructure, often across multiple offices and remote workers, with SIP endpoints that are by design reachable from outside the network. What they frequently lack is the authentication enforcement and network segmentation that would limit what an attacker can reach once they’ve found their way in through a SIP exploit.

332 million attempts is not a theoretical risk. It’s an active, systematic campaign against an exposure the sector has largely treated as a telecom issue rather than a security one.

One Breach, Dozens of Victims

The VoIP story is alarming. The Managed Security Provider (MSP) story is the one that keeps security professionals up at night.

Professional services recorded 69.9 million ransomware hits in the first half of 2026, more than any other industry. Ten active families operated simultaneously across 460 organizations. That breadth matters as much as the volume. This isn’t a handful of high-profile targets absorbing most of the hits. It’s a distributed campaign across the sector, running automated and human-operated intrusions at the same time.

The presence of Ryuk and Sodinokibi in that picture isn’t coincidental. These aren’t commodity ransomware tools running automated campaigns. They’re groups with documented strategies for targeting organizations that have administrative access to other organizations. Which is a precise description of every MSP in the professional services landscape.

An MSP breach isn’t one breach. It’s potential access to every client environment that MSP manages. A single set of compromised administrative credentials doesn’t unlock one firm’s billing system. It unlocks the network of every organization that trusts that MSP with their infrastructure. Ransomware groups have done the arithmetic on that multiplier, and the data shows they’re acting on it.

The Architecture Problem Behind Both Threats

What the VoIP exposure and the MSP ransomware story have in common is an architectural assumption that no longer holds: that a valid credential or a reachable endpoint equals legitimate access to everything behind it.

Traditional VPN-based access grants broad network trust the moment authentication succeeds. In a professional services environment, that means a compromised SIP credential, a stolen portal login or a phished MSP administrator account doesn’t just expose one system. It exposes the network. Application-level Zero Trust access changes that equation. Access is scoped to specific applications, identity and device posture are verified continuously, and a compromised credential stops being a skeleton key.

The full data is in SonicWall’s 2026 Professional Services Protect Brief, including the complete ransomware breakdown, the VoIP exposure analysis and a five-point action plan for reducing attack surface in this sector.

Share This Article

An Article By

Jordan Riddles

Content & Copywriting Specialist

Jordan Riddles is a Content & Copywriting Specialist at SonicWall, where he helps bring complex cybersecurity topics to life through clear, engaging content. Since joining the team in 2023, he’s written everything from blogs and email campaigns to case studies, threat briefs and threat reports—always with an eye toward making technical info accessible and interesting. Before SonicWall, Jordan worked as an editor and copywriter in the publishing world. He’s a proud graduate of Northeastern State University in Tahlequah, Oklahoma.

Related Articles

  • Wind River VxWorks et URGENT/11 : Appliquez le correctif maintenant
    Read More
  • Les SonicWall Partner Awards célèbrent l’excellence de nos partenaires en 2023
    Read More
  • Découvrez comment le tout nouveau programme partenaires SecureFirst place les partenaires au premier plan
    Read More