Compromised credentials continue to drive a majority of incidents. Why? home PCs and infostealers.
MS Recall got the shite kicked out of it because it would have been a disaster for exactly this reason, we don't need to pour petrol on that already raging and unsolved fire.
Bruteforcing of VPNs and exploitation of network border vulnerabilities continues to be a major (and growing) problem.
Bang for buck: Concentrate on MFA everything, patch everything internet facing, monitor bruteforce.