BreachLock

6 STATS1 REPORTS

All Statistics

APIs in technology & SaaS providers' environments saw a 400% spike in critical vulnerabilities.

BreachLock2025 Penetration Testing Intelligence Report·Aug 11, 2025
APIsVulnerabilitiesCritical vulnerabilitiesTechnologySaaS

70% of vulnerabilities detected in healthcare systems were categorised as Medium and High severity issues.

BreachLock2025 Penetration Testing Intelligence Report·Aug 11, 2025
HealthcareVulnerabilities

Broken Access Control accounted for 32% of high-severity findings across 4,200+ pen tests, making it the most prevalent and critical vulnerability.

BreachLock2025 Penetration Testing Intelligence Report·Aug 11, 2025
Broken Access Control

Approximately 40% of financial firms have increased their penetration testing frequency to quarterly or continuous testing.

BreachLock2025 Penetration Testing Intelligence Report·Aug 11, 2025
Penetration testingFinancial sector

Cloud misconfigurations and excessive permissions vulnerabilities were found in 42% of cloud environments that were pen tested.

BreachLock2025 Penetration Testing Intelligence Report·Aug 11, 2025
CloudMisconfigurationPen testing

Nearly 7 in 10 retail & consumer goods organizations had APIs with misconfigured authorizations or data exposure issues. These retail & consumer goods APIs averaged 15 vulnerabilities per API.

BreachLock2025 Penetration Testing Intelligence Report·Aug 11, 2025
APIsMisconfigurationData exposureRetailConsumer goods