Security leaders should prioritize anomalous-activity detection and zero-trust principles, a new report recommends.