Cloud Security Alliance
Reports
All Statistics
82% of organizations cannot see AI runtime behavior in real time.
Only 9% of organizations remediate critical or high-severity vulnerabilities in production within 24 hours.
74% of organizations remediate critical or high-severity vulnerabilities in production within 1 to 7 days.
SaaS security is a top priority for 86% of organisations, with 76% increasing their budgets this year.
46% of organisations are struggling to monitor non-human identities (NHIs).
79% of organisations expressed confidence in their security programs.
70% of organizations have AI-powered components in production.
73% of organizations would adopt virtual patching that reliably blocks production exploits with minimal false positives.
42% of organizations plan to invest more in runtime security over the next 24 months.
Organizations that remediate vulnerabilities in 4–7 days are breached by a known vulnerability at a 97% rate.
92% of organizations prioritizing risk identification before deployment experience a known-vulnerability incident in the past year.
Organizations that patch vulnerabilities within 24 hours are breached by a known vulnerability at a 77% rate.
91% of organizations that report being "very confident" in their AppSec strategy still experience a production incident that bypasses pre-production controls.
54% of organisations lacked automation for lifecycle management.
55% of respondents shared that employees are adopting SaaS tools without security's involvement.
63% of organizations report external data oversharing and 56% say employees upload sensitive data to unauthorized SaaS apps.
56% of organisations concerned with over-privileged API access.
Too many organisations are relying on fragmented strategies, such as vendor-native tools (69%), general-purpose solutions like Cloud Access Security Brokers (CASBs) (43%), and manual audits (46%)
58% of respondents said enforcing proper privilege levels was difficult.
57% of organisations reported they are grappling with fragmented SaaS security administration.