Cobalt
Reports
All Statistics
47% of organizations favor automation for low-risk environments, up 22 percentage points.
60% of security professionals state they require stronger LLM testing capabilities.
42% of security professionals plan to increase human-led red team operations.
94% of organizations explicitly see the importance of keeping humans in the loop for offensive security programs.
60% of organizations expect analysts to shift from executing offensive security tasks to supervising autonomous workflows.
53% of organizations say point-in-time penetration testing becomes outdated before results can be acted upon.
97% of security professionals state they are adding AI capabilities to their software and services.
The typical organization ultimately resolves 86% of its high-risk findings, but only 52% of high-risk findings are remediated within a five-year time frame.
LLMs have the lowest resolution rate of all application types, with just 38% of high-risk issues being fixed.
98% of professional pen testers prefer the PTaaS model over bug bounties.
30% of all bug bounty submissions are invalid or low-value "noise."
15% of professional pentesters rank public bug bounties as the most effective model for uncovering complex vulnerabilities.
The half-life for serious findings is 147 days in the financial services industry. This metric, which accounts for unresolved vulnerabilities, places FS ninth overall out of the thirteen measured industries.
Cross-site scripting (Web/API): 5.0% in the financial services industry (versus 9.7% average in other industries).
Server security misconfigurations: 34.9% in the financial services industry (versus 27.9% average in other industries).
Nearly 40% of healthcare SLAs require serious findings in business-critical assets to be fixed within three days. Another 40% require resolution within four to 14 days.
Healthcare’s half-life for serious pen test findings was 244 days. This ranks healthcare 11th of 13 industries. Transportation had a half-life of 43 days.
Healthcare resolved only 57.4% of serious pen test findings. This ranks healthcare 11th of 13 industries. By comparison, transportation led with 80.2%.
53% of respondents supplement their efforts with internal testing
73% of security leaders reported receiving at least one notification of a software supply chain vulnerability or incident within the past year.
55% of respondents conduct independent code reviews.
33% of respondents are still not conducting regular security assessments, including penetration testing, for their Large Language Model (LLM) deployments.
68% of cybersecurity practitioners expressed concern about long-term genAI threats like adversarial attacks.
76% of security leaders (C-suite and VP level) are more concerned about long-term genAI threats like adversarial attacks.
Larger organisations take over a month longer (61 days) than smaller ones (27 days) to resolve serious findings in pentests.
69% of the highest-risk (serious) vulnerabilities are resolved.
94% of security leaders agree that pentesting is foundational to security.
The meantime to resolve (MTTR) for AI/LLM security issues is 36 days, up from 19 days in 2025.
Support for hybrid testing models increased by 22 percentage points to 47%.
78% of organizations experienced fully automated scanning tools missing critical vulnerabilities and returning false negatives.
77% of organizations conduct regular security assessments and pentests for AI-powered products, an increase of 11 percentage points from last year.
Among organizations with confirmed AI-related security incidents, Shadow AI contributed to 44% of incidents, data or model poisoning 41%, improper output handling 41%, supply chain vulnerabilities 35%, and prompt injection 34%.
9% of organizations rely entirely on AI automation for testing, down from 29%, while 47% prefer a hybrid testing model.
82% of security professionals report that their teams are dedicating significantly more effort into AI security initiatives.
32% of AI-related pentest findings were classified as high risk, compared to 12% of all pentest findings overall.
38% of LLM vulnerabilities were fixed while 62% remain open.
58% of organizations utilize pentesting-as-a-service (PTaaS) for continuous testing.
88% of organizations plan to increase offensive security spending over the next 12 months, with 65% planning moderate increases and 23% planning significant increases.
One in five organizations experienced an LLM security incident in the last year, while a further 18% are unsure and 19% preferred not to answer.
57% of C-suite executives believe their organization consistently meets remediation SLAs, yet only 15% of security practitioners agree.
33% of organizations reported significant security budget growth in the past year, while 50% saw incremental increases.
Security teams' confidence in their ability to keep up with the security implications of AI adoption declined from 64% to 51%.
Top-performing organizations have a high-risk finding half-life of 10 days, while bottom-tier organizations have a 249-day half-life—an eight-month gap in exposure.
32% of AI/LLM findings are rated as high risk, nearly 2.7x the overall high-risk rate of 12%.
61% of security professionals want a "strategic pause" to calibrate defenses against AI-driven threats, up from 48% last year.
1% of professional pentesters believe AI-only scanning is effective for uncovering high-impact, exploitable vulnerabilities.
58% of professional pentesters rank PTaaS as the most effective model for uncovering complex vulnerabilities.
54% of professional pentesters report having discovered a Zero-Day or N-Day vulnerability that had no existing public patch or advisory.
51% of professional pentesters cite the pressure to be the first to submit a finding as their primary frustration with bug bounty programs.
Sensitive data exposure: 10.5% in the financial services industry (versus 8.0% average in other industries).