Abnormal AI

38 STATS4 REPORTS

All Statistics

97% of security and IT pros surveyed believe behavioral AI can help prevent accidental data loss before it occurs.

Email riskMisdirected emailBehavioral AIData loss

95% of organizations surveyed reported measurable business impact due to misdirected email, including remediation costs, compliance violations, or damage to customer trust.

Email riskMisdirected emailMisdirected email consequences

98% of security leaders consider misdirected email a significant risk.

Email riskMisdirected email

The average enterprise spends over 400 hours per year managing false positive alerts from data loss prevention (DLP) or email security tools.

Email riskMisdirected emailDLPFalse positives

Misdirected emails contributed to over $1.2 billion in fines worldwide last year.

Email riskMisdirected emailGDPR fines

47% of security and IT professionals learn of misdirected emails from recipients rather than from security tools.

Email riskMisdirected emailSecurity tools

Misdirected emails accounted for 27% of all data protection incidents under the GDPR last year.

Email riskMisdirected emailData protection incidentGDPR

96% of organizations surveyed experienced data loss or exposure from misdirected email in the past year.

Email riskMisdirected emailData lossData exposure

75% of analysts indicate that AI tools are already improving their job satisfaction by reducing alert fatigue and automating repetitive triage tasks.

SOCAIAnalystsAlert fatigueAutomation

100% of security professionals—including both leaders and analysts—state that implementing AI in the Security Operations Centre (SOC) is their top business objective.

SOCAI

96% of leaders report they have no plans to reduce headcount as AI adoption accelerates.

SOCAIStaffHeadcount

Over the next 3–5 years, both leaders and analysts expect autonomous SOC operations to become the norm

SOCAI

63% of analysts state that AI is improving the accuracy of investigations. This figure rises to 69% among daily AI users regarding improved investigation accuracy.

SOCAIAnalysts

Conversely, EMEA organisations show the highest reporting rate for BEC, at 4.22%

Vendor email compromiseVECHuman errorEMEABEC

Telecommunications saw the highest VEC engagement rate at 71.3%.

Vendor email compromiseVECHuman errorTelecommunications

In EMEA, the VEC engagement rate exceeds Business Email Compromise (BEC) by 90%.

Vendor email compromiseVECHuman errorEMEA

Junior sales staff were among the most vulnerable roles, engaging with read VEC attacks at a rate of 86%.

Vendor email compromiseVECHuman error

The overall reporting rate for advanced text-based email threats was just 1.46%.

Vendor email compromiseVECHuman errorReporting

7% of VEC engagements came from employees who had engaged with a previous attack.

Vendor email compromiseVECHuman error

Employees in large enterprises engaged with malicious vendor messages 72% of the time after reading them, taking follow-up actions such as replying or forwarding.

Vendor email compromiseVECHuman error

Repeat engagement with VEC in EMEA is the highest of any region, over twice that of BEC.

Vendor email compromiseVECHuman errorEMEABEC

The second-ranked industry for VEC engagement rate was the energy/utilities sector (56%).

Vendor email compromiseVECHuman errorEnergyUtilities

EMEA organisations demonstrate the lowest reporting rate for VEC, at 0.27%.

Vendor email compromiseVECHuman errorEMEA

In just 12 months, attackers attempted to steal more than $300 million via VEC.

Vendor email compromiseVECHuman error

Employees in large enterprises engaged with malicious vendor messages 72% of the time after reading them, taking follow-up actions such as replying or forwarding.

Vendor email compromiseVECHuman error

The overall reporting rate for advanced text-based email threats was just 1.46%.

Vendor email compromiseVECHuman errorReporting

While 99% of organizations experienced incidents tied to human error, the vast majority stated they struggle to implement effective, scalable SAT programs.

Human errorSecurity awareness training

99% of organizations see value in using AI to support automatically generating training campaigns and workflows.

Human errorSecurity awareness trainingAI

More than half (53%) of respondents agreed that the effort required to run their current SAT tools outweighs their impact.

Human errorSecurity awareness training

Nearly all of the organizations surveyed (99%) are in favour of including AI in future SAT tools and workflows.

Human errorSecurity awareness trainingAI

83% of respondents agreed that their current SAT tools require substantial effort to operate and maintain.

Human errorSecurity awareness training

95% of organizations see value in using AI to Automatically create individualized attack simulations based on individual user profiles.

Human errorSecurity awareness trainingAI

95% of organizations see value in using AI to Automate the creation of training videos.

Human errorSecurity awareness trainingAI

99% of organizations experienced security incidents linked to avoidable human error.

Human errorSecurity awareness training

Many SAT programmes exist primarily to satisfy regulatory or insurance requirements.

Human errorSecurity awareness training

95% of organizations see value in using AI to Conduct conversational coaching by leveraging LLMs.

Human errorSecurity awareness trainingLLM

96% of organizations see value in using AI to Create dynamic risk scores based on past user behaviour and the types of attacks targeting certain types of users.

Human errorSecurity awareness trainingAI

75% of organizations require employees to complete security awareness training at least quarterly.

Human errorSecurity awareness training