Cobalt

110 stats9 reports

All Statistics

77% of organizations conduct regular security assessments and pentests for AI-powered products, an increase of 11 percentage points from last year.

Pen TestingAI SecuritySecurity AssessmentsOffensive Security

60% of security professionals state they require stronger LLM testing capabilities.

AI SecurityLLM TestingOffensive Security

47% of organizations favor automation for low-risk environments, up 22 percentage points.

Risk ManagementAutomationTestingOffensive Security

94% of organizations explicitly see the importance of keeping humans in the loop for offensive security programs.

Offensive SecurityAI Security

60% of organizations expect analysts to shift from executing offensive security tasks to supervising autonomous workflows.

AutomationOffensive Security

53% of organizations say point-in-time penetration testing becomes outdated before results can be acted upon.

Offensive SecurityPenetration TestingContinuous Testing

57% of C-suite executives believe their organization consistently meets remediation SLAs, yet only 15% of security practitioners agree.

GovernanceSLAsSecurity Operations

97% of security professionals state they are adding AI capabilities to their software and services.

AI AdoptionSoftware Development

The typical organization ultimately resolves 86% of its high-risk findings, but only 52% of high-risk findings are remediated within a five-year time frame.

Vulnerability RemediationLong-Term Remediation

30% of all bug bounty submissions are invalid or low-value "noise."

Bug BountySecurity OperationsVulnerability Triage

98% of professional pen testers prefer the PTaaS model over bug bounties.

PTaaSBug BountyPenetration Testing

15% of professional pentesters rank public bug bounties as the most effective model for uncovering complex vulnerabilities.

Bug BountyVulnerability DiscoveryPenetration Testing

Business logic flaws: 2.9% in the financial services industry (versus 2.3% average in other industries).

Financial servicesPen testVulnerabilitiesBusiness logic flaw

76% of financial services leaders highlight third-party software vulnerabilities as a top concern.

Financial servicesPen testVulnerabilitiesThird-party software

Approximately one-third of serious issues are never resolved by the organizations in the financial services industry, contributing to backlog and systemic risk.

Financial servicesPen testVulnerability resolutionVulnerabilities

Healthcare resolved only 57.4% of serious pen test findings. This ranks healthcare 11th of 13 industries. By comparison, transportation led with 80.2%.

HealthcarePen testVulnerabilitiesTransportation

Healthcare’s half-life for serious pen test findings was 244 days. This ranks healthcare 11th of 13 industries. Transportation had a half-life of 43 days.

HealthcarePen testVulnerabilitiesTransportation

Nearly 40% of healthcare SLAs require serious findings in business-critical assets to be fixed within three days. Another 40% require resolution within four to 14 days.

HealthcarePen testSLAVulnerabilities

53% of respondents supplement their efforts with internal testing

TestingInternal testing

68% of security leaders are concerned about the risks associated with third-party software tools and components integrated into their tech stacks.

Supply chain riskThird-party softwareThird-party software tools

Nearly nine in 10 security leaders (88%) view penetration testing as an essential component of their overall security programme.

TestingPen testing

76% of security leaders (C-suite and VP level) are more concerned about long-term genAI threats like adversarial attacks.

AIGen AI

45% of cybersecurity practitioners expressed concern about near-term operational genAI risks such as inaccurate outputs.

AIGen AI

36% of security leaders expressed concern about near-term operational genAI risks such as inaccurate outputs.

AIGen AI

Median time to resolve issues of all criticalities stretches to 67 days.

VulnerabilitiesVulnerability managementVulnerability remediation

Since 2017, the median time to resolve serious vulnerabilities has decreased dramatically—from 112 days down to 37 days last year.

VulnerabilitiesVulnerability remediationVulnerability management

This represents a cut of 75 days, or two-thirds.

VulnerabilitiesVulnerability remediationVulnerability management

42% of security professionals plan to increase human-led red team operations.

Red TeamingOffensive SecurityAI Security

The meantime to resolve (MTTR) for AI/LLM security issues is 36 days, up from 19 days in 2025.

Incident ResponseAI SecurityMTTRLLM Security

Support for hybrid testing models increased by 22 percentage points to 47%.

Hybrid TestingOffensive Security

78% of organizations experienced fully automated scanning tools missing critical vulnerabilities and returning false negatives.

Vulnerability ManagementFalse NegativesAutomationOffensive Security

Among organizations with confirmed AI-related security incidents, Shadow AI contributed to 44% of incidents, data or model poisoning 41%, improper output handling 41%, supply chain vulnerabilities 35%, and prompt injection 34%.

AI SecurityAttack VectorsSupply ChainShadow AI

9% of organizations rely entirely on AI automation for testing, down from 29%, while 47% prefer a hybrid testing model.

AI TestingHybrid TestingOffensive Security

82% of security professionals report that their teams are dedicating significantly more effort into AI security initiatives.

AI Security

32% of AI-related pentest findings were classified as high risk, compared to 12% of all pentest findings overall.

Pen TestingAI SecurityRisk ClassificationOffensive Security

38% of LLM vulnerabilities were fixed while 62% remain open.

AI SecurityVulnerability ManagementLLM VulnerabilitiesOffensive Security

58% of organizations utilize pentesting-as-a-service (PTaaS) for continuous testing.

Penetration TestingOffensive SecurityPTaaS

88% of organizations plan to increase offensive security spending over the next 12 months, with 65% planning moderate increases and 23% planning significant increases.

Security SpendingOffensive SecuritySecurity BudgetsSecurity Investment

LLMs have the lowest resolution rate of all application types, with just 38% of high-risk issues being fixed.

LLM TestingVulnerability Remediation

One in five organizations experienced an LLM security incident in the last year, while a further 18% are unsure and 19% preferred not to answer.

Security IncidentsLLM Security IncidentOrganizational Risk

33% of organizations reported significant security budget growth in the past year, while 50% saw incremental increases.

Security BudgetsFundingRisk Management

Security teams' confidence in their ability to keep up with the security implications of AI adoption declined from 64% to 51%.

Security ConfidenceAI SecurityAI Adoption

Top-performing organizations have a high-risk finding half-life of 10 days, while bottom-tier organizations have a 249-day half-life—an eight-month gap in exposure.

Vulnerability RemediationRisk ExposureOperational Performance

32% of AI/LLM findings are rated as high risk, nearly 2.7x the overall high-risk rate of 12%.

AI TestingLLM TestingVulnerabilities

61% of security professionals want a "strategic pause" to calibrate defenses against AI-driven threats, up from 48% last year.

AI SecurityAI-Driven ThreatsSecurity Strategy

1% of professional pentesters believe AI-only scanning is effective for uncovering high-impact, exploitable vulnerabilities.

AI SecurityVulnerability DiscoveryOffensive SecurityPenetration Testing

58% of professional pentesters rank PTaaS as the most effective model for uncovering complex vulnerabilities.

Penetration TestingPTaaSVulnerability Discovery

54% of professional pentesters report having discovered a Zero-Day or N-Day vulnerability that had no existing public patch or advisory.

Zero-DayVulnerability DiscoveryOffensive SecurityPenetration Testing

51% of professional pentesters cite the pressure to be the first to submit a finding as their primary frustration with bug bounty programs.

Bug BountyOffensive SecurityPenetration Testing

The half-life for serious findings is 147 days in the financial services industry. This metric, which accounts for unresolved vulnerabilities, places FS ninth overall out of the thirteen measured industries.

Financial servicesPen testHalf-lifeVulnerabilitiesVulnerability resolution