Absolute Security

43 stats5 reports

All Statistics

43% of CISOs report Employee Awareness Training is the top-ranked challenge for ransomware mitigation.

Human FactorsRansomware MitigationSecurity Training

58% of cybersecurity leaders would consider paying cybercriminals to end a ransomware attack.

RansomwareIncident ResponseRansom

53% of organizations have remote recovery capabilities in place.

Remote RecoveryOperational Resilience

Last year, 18% of connected devices stored sensitive data, 35% lacked encryption, and 26% were unaccounted for.

Absolute Security2026 Resilience Risk Index·5mo ago
Data SecurityConnected DevicesEncryptionAsset Management

Critical OS patching across PCs running Windows 10 and 11 is behind an average of 127 days, up from 56 days in 2025.

Absolute Security2026 Resilience Risk Index·5mo ago
PatchingEndpoint SecurityWindows 10Windows 11Critical Patching

Endpoint security tools fail 20% of the time.

Absolute Security2026 Resilience Risk Index·5mo ago
Endpoint Security

In 2025, 68% of CISOs agreed that their organization currently has a Cyber Resilience strategy in place.

Cyber Resilience

In 2025, 57% of CISOs reported that their organizations took more than 4.5 days on average for full remediation and recovery after a cyber incident.

Incident RecoveryIncident RemediationCyber IncidentUSUK

In 2025, not a single Chief Information Security Officer (CISO) reported being able to recover from a cyber incident within a day.

Incident RecoveryCyber IncidentUSUK

35% of enterprise PCs lack encryption.

PCEncryption

Enterprise PCs are logging millions of visits to popular generative AI platforms. Thousands of these visits are specifically landing on DeepSeek.

PCAIGen AI

18% of enterprise PCs store sensitive data.

PCSensitive data

15% of healthcare PCs fail security tests.

HealthcareSecurity test

Critical security controls were found to be either non-compliant with internal security and risk policies or missing from devices 15 percent of the time in the analysed healthcare PCs.

HealthcareSecurity controls

The average Windows endpoint in healthcare is 48 days behind on critical security patches.

HealthcareEndpoint

46% of cybersecurity leaders rank operational downtime as the most significant impact ransomware is likely to have on their organizations.

Operational ResilienceRansomwareBusiness ImpactOperational Downtime

57% of CISOs report taking as long as six days to recover from a ransomware attack.

Recovery TimeOperational ResilienceRansomware

20% of CISOs report taking as long as two weeks to recover from a ransomware attack.

Recovery TimeOperational ResilienceRansomware

58% of enterprise CISOs agree that a ransomware incident left endpoints inoperable.

Endpoint SecurityRansomwareOperational Resilience

83% of CISOs report being confident in their businesses' ability to recover from ransomware.

Operational ResilienceRansomware

42% of CISOs report legacy system patching is the second most challenging ransomware mitigation method.

Patch ManagementRansomware MitigationRansomware

No CISOs report the ability to recover from ransomware within a day.

Recovery TimeIncident ResponseRansomware

59% of organizations agree they must take physical possession of an endpoint to remediate and restore the device after an incident.

Incident ResponseEndpoint Security

Over the past 12–18 months, 57% of enterprise CISOs report their enterprises experienced an attack that originated on a remote, mobile, or hybrid device.

Endpoint SecurityRemote WorkCyber AttackDevice Security

Across all industries, 30% of connected devices lack encryption.

Absolute Security2026 Resilience Risk Index·5mo ago
EncryptionConnected Devices

Globally-distributed PCs are vulnerable to AI-driven attacks and cyber incidents up to 76 days per year.

Absolute Security2026 Resilience Risk Index·5mo ago
AI-Driven Attacks

10% of PCs run Windows 10, which Microsoft ended support for in October 2025.

Absolute Security2026 Resilience Risk Index·5mo ago
OSLegacy RiskWindows 10

Across all industries, 20% of connected devices store sensitive data.

Absolute Security2026 Resilience Risk Index·5mo ago
Data SecurityConnected DevicesSensitive Data

Across all industries, 25% of connected devices are unaccounted for.

Absolute Security2026 Resilience Risk Index·5mo ago
Asset ManagementConnected Devices

67% of CISOs stated they are the primary executive responsible for ensuring Cyber Resilience within their organization.

Cyber ResilienceCISOUKUS

In 2025, 98% of organizations reported spending between $1 and $5 million to recover from cyber incidents, with the average recovery cost per incident being $2.5 million.

Incident RecoveryRecovery CostsCISOUKUS

In 2025, 61% of CISOs indicated that their organization’s board and C-suite expect the cybersecurity group to guarantee zero breaches and ransomware incidents.

Board ExpectationsBreachRansomware USUK

72% of CISOs agreed that their role has evolved to include leading their organization’s ability to recover continuity following a cyberattack or security incident.

Incident RecoveryCyber IncidentCISOUKUS

65% of CISOs agreed that their organization prioritizes Cyber Resilience over traditional prevention, detection, and response.

Cyber ResiliencePreventionDetectionUKUS

In 2025, 83% of CISOs reported that Cyber Resilience was more critical for their organization than traditional cybersecurity measures, compared to 90% in the previous year.

Cyber ResilienceTraditional Cybersecurity MeasuresCISOUKUS

In 2025, 19% of CISOs indicated that recovery efforts from cyber incidents extended as long as two weeks.

Incident RecoveryCyber IncidentUSUK

In 2025, 55% of Chief Information Security Officers (CISOs) in the US and UK reported that their organization experienced a cyberattack, ransomware infection, compromise, or data breach that rendered mobile, remote, or hybrid endpoint devices inoperable.

RansomwareData BreachesEndpointUKUS

Critical patching for PCs running Windows 10 and 11 is delayed nearly two months on average across organisations.

PatchingPCWindows

Top endpoint security controls, including leading Endpoint Protection Platforms (EPP), Security Service Edge (SSE) solutions, and Vulnerability and Patch Management platforms, fail to maintain compliance with internal security and performance policies 22% of the time.

EndpointCompliance

Top endpoint security controls, including leading Endpoint Protection Platforms (EPP), Security Service Edge (SSE) solutions, and Vulnerability and Patch Management platforms, fail to maintain compliance with internal security and performance policies 22% of the time.

EndpointCompliance

Critical patching for PCs running Windows 10 and 11 is delayed nearly two months on average across organisations.

PatchingPCWindows

Enterprise PCs are logging millions of visits to popular generative AI platforms. Thousands of these visits are specifically landing on DeepSeek.

PCAIGen AI

26% of enterprise PCs are unaccounted for.

PCVisibility