Government Cybersecurity Statistics

136 stats39 sources

Latest Statistics

24% of UK public sector IT professionals say AI governance is lagging behind the pace of adoption.

AI GovernancePublic SectorUK

30% of UK public sector IT professionals have a formal AI governance framework that is actively enforced.

AI GovernancePublic SectorUK

41% of UK public sector IT professionals identify insufficient visibility into AI tool behaviour and activity as a major AI cybersecurity vulnerability.

AI SecurityAI RisksVisibilityUKPublic Sector

The services sector experienced 45 disclosed attacks (15%) and government experienced 30 disclosed attacks (10%) in Q2 2026.

Services SectorGovernmentRansomware

28% of federal IT and cybersecurity decision makers express high confidence in their ability to deploy AI agents securely

AI AdoptionGovernment TechnologyFederal agenciesAgentic AI

58% of federal IT and cybersecurity decision makers report their agencies have deployed or are piloting AI agents

AI AdoptionGovernment TechnologyFederal agenciesAgentic AI

Passaic County, New Jersey received an $800,000 ransom demand in March 2026.

RansomGovernmentRansomware

German municipal transport company Verkehrsgesellschaft Main-Tauber took 11 weeks to recover from its January 2026 ransomware attack.

Incident ResponseGovernmentRansomwareRansomware Recovery

The most prolific ransomware strains by number of claims against government organizations were The Gentlemen (22), Qilin (21), LockBit (14), APT73/BASHE (12), and INC (10).

RansomwareGovernmentThe GentlemenQilinThreat Actors

72% of local and state government organizations paid the ransom, the highest payment rate among sectors.

GovernmentRansomware

Vulnerabilities account for 56.4% of critical exposures in Government.

VulnerabilitiesGovernmentExposure Management

20% of Public Sector credential revocations are performed manually, which is more than double the manual revocation rate in the IT/Technology sector.

Public SectorCredential ManagementIdentity SecurityCredential RevocationTechnology Sector

43% of Public Sector organizations experience access revocation failures.

Public SectorAccess ManagementIdentity SecurityAccess Revocation

Energy, oil/gas, and utilities reported an 80% breach rate and federal/central government report a 78% breach rate, the highest across industries surveyed.

Critical InfrastructureGovernmentIdentity Attack

Government entities experienced 32 publicly disclosed ransomware attacks (12%) and the technology sector experienced 28 attacks (11%) in Q1 2026.

RansomwareGovernmentTechnology Sector

63% of CISOs describe themselves as not very confident in the ability of local government and public higher education to secure public data, up from 35% in 2022.

Data SecurityHigher EducationLocal GovernmentPublic SectorUS

Roughly one-fifth of CISOs indicate their states are moving toward a "whole-of-state" approach to cybersecurity.

CybersecurityPublic SectorUS

49% of state CISOs name implementing effectiveness metrics as a top cybersecurity initiative, up from 25% in 2024 and 15% in 2022.

Performance MetricsPublic SectorUS

36% of financial services organisations and 36% of IT & technology organisations report modernising most or all core systems, compared with 12% of public sector organisations and 19% of industrial organisations

Legacy SystemsModernizationFinancial ServicesPublic SectorIndustrial

Government services have 40% consumer trust

ConsumerGovernment ServicesConsumer Trust

Between January 1 and December 31, 2025, government organizations worldwide faced the highest number of threat campaigns, with 274 attacks targeting various federal, state, and municipal bodies.

2026 In the Wild Threat ReportHPE·6mo ago
GovernmentThreat Campaign

Government’s share of total attacks increased from 5% to 12% year-over-year, with an average attack size of 5.5 Gbps.

DDoSGovernment

The government sector ranked as the second most targeted industry in February, with organizations experiencing 2,714 weekly attacks on average, reflecting a 2% year‑over‑year increase.

GovernmentCyber Attack

Government services are the primary target in 38.8% of all claimed hactivism attacks.

HacktivismGovernment

The most impacted industries by initial access brokers in LATAM in 2025 were national government, agriculture and food and beverage production and education.

LATAMInitial Access BrokerIABGovernmentAgriculture

1.6% of public sector agencies report broad AI deployment across departments.

Euna SolutionsState of AI in the Public Sector·7mo ago
Public SectorAIAI Deployment

57% of public sector agencies are actively exploring and learning about AI.

Euna SolutionsState of AI in the Public Sector·7mo ago
Public SectorAIAI Adoption

78% of security leaders in government, defense, and critical services cite outdated infrastructure as a primary source of cyber vulnerability.

InfrastructureOperational RiskGovernmentDefenseCritical Services

53% of government IT security leaders rely on manual data transfer processes.

Manual Data TransferGovernment Security

45% of security leaders in government, defense, and critical services cite managing identity and authentication across multiple domains as the biggest challenge to securing access to mission data.

Identity And AccessGovernmentDefenseCritical ServicesMission Data