Certinia, today released its 2026 Global Service Dynamics Report, based on an independent survey of 1,000 professional services and IT/technology leaders around the world. One of the report’s top conclusions is that the clearest predictor of performance in the sector this year isn’t how much a company has invested in AI or talent, but whether that business runs on a single, connected system across the organization.
Organizations reporting the strongest AI results, highest profit margins, and account expansion are consistently more likely to report full operational alignment across sales, delivery, finance, and customer success than those struggling on the same measures. Companies with successful AI outcomes are more than three times as likely to be fully integrated as those with mixed results (28% vs. 8%). Firms achieving peak profitability, with margins above 40%, are also three times more likely to have fully integrated operations compared with barely profitable competitors. And among organizations achieving net revenue expansion above 100%, 68% are aligned or fully integrated, well above the 22% sector-wide rate of full integration.
The report’s additional findings reveal further gaps in perception, hidden operational risk, and early shifts in how services businesses price and staff their work.
The Perception Gap
Executives and delivery teams are living in different realities: Executives consistently rate their own organizations’ performance more favorably than the people actually delivering the work. Leaders rate their forecasting confidence 24 points higher than practitioners do, their AI success 16 points higher, and their ability to grow without adding headcount 10 points higher.
Retention goals aren’t reaching the front lines: 62% of executive leadership teams have defined net revenue retention goals, compared with just 45% of services/delivery teams, despite these teams often being closest to the customer experience that drives retention.
Operational Blind Spots
Confidence collapses in the “messy middle”: Just 38% of partially aligned organizations report high confidence in their resource, demand, and revenue forecasts. This compares to 75% among fully siloed companies and 78% among fully integrated ones — evidence that half-finished tech connections carry the costs of interdependence without the benefits of a shared system.
Account expansion is a massive missed opportunity: Just 6% of organizations globally are achieving net revenue expansion above 100%. This untapped growth opportunity is highly regional; expansion rates above 100% are more than four times as common in North America (9%) as in Asia-Pacific (2%).
AI performance is unevenly distributed: Among organizations that have deployed AI, the share reporting moderate or significant success ranges wildly by sector — from just 43% among accounting, tax, and audit firms to 74% among IT service providers.
Shifting Business Models
Pricing is moving decisively toward outcomes: 75% of organizations expect to increase outcome-based pricing over the next 12 months, even as nearly one-third already report difficulty managing hybrid or complex billing models.
Hiring priorities are shifting toward AI expertise: 82% of leaders name AI and data specialists their top hiring priority for the year, even as 82% of organizations expect to grow revenue without a proportional increase in billable headcount.
The 2026 Global Service Dynamics (GSD) Report was conducted by Sapio Research on behalf of Certinia, surveying 1,000 professional services and IT/technology decision-makers across the US, Canada, UK, Australia/New Zealand, and Singapore in June 2026. The full report, including chapter-by-chapter analysis of operational alignment, AI maturity, pricing models, talent, and financial performance, is available for download at certinia.com/services-report.
The CISA orders federal agencies to patch actively exploited Oracle flaw by August 27
Posted in Commentary with tags CISA on August 25, 2026 by itnerdThe CISA has added a maximum-severity Oracle vulnerability, CVE-2026-21962, to its Known Exploited Vulnerabilities catalog after confirming active exploitation.
The flaw carries a CVSS score of 10.0 and affects Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in for Apache HTTP Server and IIS.
The vulnerability can be exploited remotely over HTTP without authentication or valid credentials, potentially allowing attackers to access, modify or delete critical data.
Oracle originally disclosed and patched CVE-2026-21962 on January 20, 2026, as part of its January Critical Patch Update. In March, researchers reported exploitation attempts after exploit code became publicly available.
CISA has ordered federal agencies to address the vulnerability by August 27.
Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs Had This To Say:
“CVE-2026-21962 had a patch on January 20, and CloudSEK recorded exploitation attempts against its honeypot on January 22, followed by broader automated scanning. CISA added it to the KEV catalog on August 24, 216 days after the patch. Federal agencies now have three days to remediate something attackers have had seven months to exploit.
“In January, agencies could have applied the Critical Patch Update inside a normal maintenance window and moved on. Seven months of delay while exploitation attempts and automated scanning were already being observed from rented VPS infrastructure changed the math. BOD 26-04 requires forensic triage at this severity tier, so agencies now have to assess whether compromise occurred during that seven-month exposure period alongside applying the patch.
“BOD 26-04’s 16-tier remediation matrix is well-designed for the problem it solves. For a vulnerability in the KEV, automatable, and yielding total control of a public-facing asset, the clock is three days with forensic triage. In this case, CISA’s August 24 KEV addition produced an August 27 federal remediation deadline, while CISA’s obligation is to update the catalog “as quickly as possible,” with no numerical SLA. EPSS ranked this in the top 1.4%, Shodan shows roughly 79,000 exposed Oracle HTTP Server instances, and CISA’s own SSVC record dates active exploitation to January 21 while classifying the vulnerability as automatable with total technical impact.
“Three days to remediate is the right call. Seven months to trigger it turned a maintenance window into a forensic investigation.”
This of course means update all the things ASAP. But we’re getting to a point where patching anything is a losing battle. Thus we need to think of something new when this avenue exhausts itself.
UPDATE: Also Commenting on this is Dan Moore, Sr. Director, CIAM Strategy & Identity Standards at FusionAuth:
“The thousands of organizations relying on Oracle WebLogic to provide secure access to their applications are at risk of data loss, manipulation, and exfiltration. The unauthenticated access allows an attacker to make application calls to read data, as well as insert their own unauthorized changes. This issue affects any server accessible to an attacker, which is extremely problematic for many internet exposed applications.”
Leave a comment »