Absolute Security

23 STATS3 REPORTS

All Statistics

72% of CISOs agreed that their role has evolved to include leading their organization’s ability to recover continuity following a cyberattack or security incident.

Absolute SecurityThe Resilient CISO: The State of Enterprise Cyber Resilience·Jan 8, 2026
Incident RecoveryCyber IncidentCISOUKUS

67% of CISOs stated they are the primary executive responsible for ensuring Cyber Resilience within their organization.

Absolute SecurityThe Resilient CISO: The State of Enterprise Cyber Resilience·Jan 8, 2026
Cyber ResilienceCISOUKUS

In 2025, 83% of CISOs reported that Cyber Resilience was more critical for their organization than traditional cybersecurity measures, compared to 90% in the previous year.

Absolute SecurityThe Resilient CISO: The State of Enterprise Cyber Resilience·Jan 8, 2026
Cyber ResilienceTraditional Cybersecurity MeasuresCISOUKUS

In 2025, 68% of CISOs agreed that their organization currently has a Cyber Resilience strategy in place.

Absolute SecurityThe Resilient CISO: The State of Enterprise Cyber Resilience·Jan 8, 2026
Cyber Resilience

In 2025, 57% of CISOs reported that their organizations took more than 4.5 days on average for full remediation and recovery after a cyber incident.

Absolute SecurityThe Resilient CISO: The State of Enterprise Cyber Resilience·Jan 8, 2026
Incident RecoveryIncident RemediationCyber IncidentUSUK

In 2025, not a single Chief Information Security Officer (CISO) reported being able to recover from a cyber incident within a day.

Absolute SecurityThe Resilient CISO: The State of Enterprise Cyber Resilience·Jan 8, 2026
Incident RecoveryCyber IncidentUSUK

65% of CISOs agreed that their organization prioritizes Cyber Resilience over traditional prevention, detection, and response.

Absolute SecurityThe Resilient CISO: The State of Enterprise Cyber Resilience·Jan 8, 2026
Cyber ResiliencePreventionDetectionUKUS

In 2025, 98% of organizations reported spending between $1 and $5 million to recover from cyber incidents, with the average recovery cost per incident being $2.5 million.

Absolute SecurityThe Resilient CISO: The State of Enterprise Cyber Resilience·Jan 8, 2026
Incident RecoveryRecovery CostsCISOUKUS

In 2025, 55% of Chief Information Security Officers (CISOs) in the US and UK reported that their organization experienced a cyberattack, ransomware infection, compromise, or data breach that rendered mobile, remote, or hybrid endpoint devices inoperable.

Absolute SecurityThe Resilient CISO: The State of Enterprise Cyber Resilience·Jan 8, 2026
RansomwareData BreachesEndpointUKUS

In 2025, 61% of CISOs indicated that their organization’s board and C-suite expect the cybersecurity group to guarantee zero breaches and ransomware incidents.

Absolute SecurityThe Resilient CISO: The State of Enterprise Cyber Resilience·Jan 8, 2026
Board ExpectationsBreachRansomware USUK

In 2025, 19% of CISOs indicated that recovery efforts from cyber incidents extended as long as two weeks.

Absolute SecurityThe Resilient CISO: The State of Enterprise Cyber Resilience·Jan 8, 2026
Incident RecoveryCyber IncidentUSUK

Critical patching for PCs running Windows 10 and 11 is delayed nearly two months on average across organisations.

Absolute SecurityAbsolute Security Resilience Risk Index 2025·Jun 4, 2025
PatchingPCWindows

35% of enterprise PCs lack encryption.

Absolute SecurityAbsolute Security Resilience Risk Index 2025·Jun 4, 2025
PCEncryption

Enterprise PCs are logging millions of visits to popular generative AI platforms. Thousands of these visits are specifically landing on DeepSeek.

Absolute SecurityAbsolute Security Resilience Risk Index 2025·Jun 4, 2025
PCAIGen AI

18% of enterprise PCs store sensitive data.

Absolute SecurityAbsolute Security Resilience Risk Index 2025·Jun 4, 2025
PCSensitive data

Top endpoint security controls, including leading Endpoint Protection Platforms (EPP), Security Service Edge (SSE) solutions, and Vulnerability and Patch Management platforms, fail to maintain compliance with internal security and performance policies 22% of the time.

Absolute SecurityAbsolute Security Resilience Risk Index 2025·Jun 4, 2025
EndpointCompliance

Top endpoint security controls, including leading Endpoint Protection Platforms (EPP), Security Service Edge (SSE) solutions, and Vulnerability and Patch Management platforms, fail to maintain compliance with internal security and performance policies 22% of the time.

Absolute SecurityAbsolute Security Resilience Risk Index 2025·Jun 4, 2025
EndpointCompliance

Critical patching for PCs running Windows 10 and 11 is delayed nearly two months on average across organisations.

Absolute SecurityAbsolute Security Resilience Risk Index 2025·Jun 4, 2025
PatchingPCWindows

Enterprise PCs are logging millions of visits to popular generative AI platforms. Thousands of these visits are specifically landing on DeepSeek.

Absolute SecurityAbsolute Security Resilience Risk Index 2025·Jun 4, 2025
PCAIGen AI

26% of enterprise PCs are unaccounted for.

Absolute SecurityAbsolute Security Resilience Risk Index 2025·Jun 4, 2025
PCVisibility

15% of healthcare PCs fail security tests.

Absolute SecurityResilience Obstacles in the Healthcare Industry, Q1 2025·Mar 3, 2025
HealthcareSecurity test

Critical security controls were found to be either non-compliant with internal security and risk policies or missing from devices 15 percent of the time in the analysed healthcare PCs.

Absolute SecurityResilience Obstacles in the Healthcare Industry, Q1 2025·Mar 3, 2025
HealthcareSecurity controls

The average Windows endpoint in healthcare is 48 days behind on critical security patches.

Absolute SecurityResilience Obstacles in the Healthcare Industry, Q1 2025·Mar 3, 2025
HealthcareEndpoint