Insider Threat vs Cyber Attack
Insider Threat
166
statistics from 28 sources
Cyber Attack
306
statistics from 73 sources
Latest Insider Threat
68% of business admins say employees entering sensitive data into AI is their biggest concern.
48% of security leaders rank AI agents operating with excessive, compromised, or unintended access as the greatest threat to their organization, while 28% rank external threat actors, 12% rank compromised insiders, and 12% rank malicious insiders.
47% of enterprise identity-based attacks are discovered manually: 22% via coworker reports, 15% via internal audits, and 10% via external notifications
Prior to day one, HR leaders claim ownership of identity risk in 53% of cases while IT and security teams claim 17%
Nearly 90% of HR leaders report heightened concern over hiring fraud
69% of UK CISOs identify human risk as their organisation's biggest cyber vulnerability, up from 60% in 2025.
Among UK organisations that experienced material data loss, compromised insiders were the leading cause at 48%, with malicious or criminal insiders cited by 44% and careless insiders by 37%.
95% of UK CISOs at organisations experiencing material data loss say departing employees played a role.
Insider wrongdoing events totaled 21 in the first half of 2026, a sevenfold increase over the three incidents in 2025.
50% of federal IT and cybersecurity decision makers list preventing unauthorized actions as a top concern for agentic AI deployments
41% of CISOs are concerned about malicious insiders using AI to support fraud, cybercrime or data theft.
68% of CISOs identify employees as their organisation’s biggest security risk as AI amplifies human-targeted attacks.
40% of CISOs fear employees are sharing sensitive information with generative AI platforms.
38% of security and IT leaders report attacker activity mirrors legitimate, authorized workflows and processes, delaying critical alerts.
12% of organizations maintain direct user-to-server administrative pathways, meaning a single compromised employee device can provide immediate access to high-value systems.
Latest Cyber Attack
45% of cybersecurity professionals expect a cyber-attack on their organization in the next year.
Enterprises face social engineering attacks (45%), vulnerabilities (39%), and remote access attacks (24%), with remote access increasing 5 percentage points from 2025.
35% of cybersecurity professionals report experiencing an increase in cyber-attacks compared to a year ago.
49% of UK SMBs report experiencing a cyber incident in the past year.
UK SMBs take just over four weeks on average to identify and recover from a breach.
46% of manufacturers experienced increase of operational cost and production downtime where incidents caused disruption.
31% of manufacturers affected by supplier cyber attacks reported delays to customer deliveries.
30% of manufacturers experienced a cyber incident in the past year, either directly or through their supply chain.
6% of reported cybercrime cases in Africa in 2025 involved cyber attacks on critical infrastructure.
10% of restaurant chains have temporarily or permanently closed a location following a cyberattack.
80% of leaders at quick service and fast casual restaurant chains experienced at least one cyber incident in the past 12 months.
84% of security decision-makers and practitioners agree that cyberattacks exploit known risks that are not prioritized.
1 in 5 suffered a serious incident linked to AI code
71% say AI has made security incidents harder to detect, investigate, or fix
Cyber is the leading cause of both IT downtime and data loss for the fourth consecutive year.