Cobalt

112 stats9 reports

All Statistics

47% of organizations favor automation for low-risk environments, up 22 percentage points.

Risk ManagementAutomationTestingOffensive Security

60% of security professionals state they require stronger LLM testing capabilities.

AI SecurityLLM TestingOffensive Security

42% of security professionals plan to increase human-led red team operations.

Red TeamingOffensive SecurityAI Security

94% of organizations explicitly see the importance of keeping humans in the loop for offensive security programs.

Offensive SecurityAI Security

60% of organizations expect analysts to shift from executing offensive security tasks to supervising autonomous workflows.

AutomationOffensive Security

53% of organizations say point-in-time penetration testing becomes outdated before results can be acted upon.

Offensive SecurityPenetration TestingContinuous Testing

97% of security professionals state they are adding AI capabilities to their software and services.

AI AdoptionSoftware Development

The typical organization ultimately resolves 86% of its high-risk findings, but only 52% of high-risk findings are remediated within a five-year time frame.

Vulnerability RemediationLong-Term Remediation

LLMs have the lowest resolution rate of all application types, with just 38% of high-risk issues being fixed.

LLM TestingVulnerability Remediation

98% of professional pen testers prefer the PTaaS model over bug bounties.

PTaaSBug BountyPenetration Testing

30% of all bug bounty submissions are invalid or low-value "noise."

Bug BountySecurity OperationsVulnerability Triage

15% of professional pentesters rank public bug bounties as the most effective model for uncovering complex vulnerabilities.

Bug BountyVulnerability DiscoveryPenetration Testing

The half-life for serious findings is 147 days in the financial services industry. This metric, which accounts for unresolved vulnerabilities, places FS ninth overall out of the thirteen measured industries.

Financial servicesPen testHalf-lifeVulnerabilitiesVulnerability resolution

Cross-site scripting (Web/API): 5.0% in the financial services industry (versus 9.7% average in other industries).

Financial servicesPen testVulnerabilitiesCross-site scriptingWeb

Server security misconfigurations: 34.9% in the financial services industry (versus 27.9% average in other industries).

Financial servicesPen testVulnerabilitiesMisconfigurationServer side misconfiguration

Nearly 40% of healthcare SLAs require serious findings in business-critical assets to be fixed within three days. Another 40% require resolution within four to 14 days.

HealthcarePen testSLAVulnerabilities

Healthcare’s half-life for serious pen test findings was 244 days. This ranks healthcare 11th of 13 industries. Transportation had a half-life of 43 days.

HealthcarePen testVulnerabilitiesTransportation

Healthcare resolved only 57.4% of serious pen test findings. This ranks healthcare 11th of 13 industries. By comparison, transportation led with 80.2%.

HealthcarePen testVulnerabilitiesTransportation

53% of respondents supplement their efforts with internal testing

TestingInternal testing

73% of security leaders reported receiving at least one notification of a software supply chain vulnerability or incident within the past year.

Supply chain riskSoftware supply chain

55% of respondents conduct independent code reviews.

Code review

33% of respondents are still not conducting regular security assessments, including penetration testing, for their Large Language Model (LLM) deployments.

AIGen AILLMPen testing

68% of cybersecurity practitioners expressed concern about long-term genAI threats like adversarial attacks.

AIGen AI

76% of security leaders (C-suite and VP level) are more concerned about long-term genAI threats like adversarial attacks.

AIGen AI

Larger organisations take over a month longer (61 days) than smaller ones (27 days) to resolve serious findings in pentests.

TestingPen testingOffensive securitySecurity assessmentVulnerability remediation

69% of the highest-risk (serious) vulnerabilities are resolved.

VulnerabilitiesVulnerability managementVulnerability remediation

94% of security leaders agree that pentesting is foundational to security.

TestingPen testingOffensive security

The meantime to resolve (MTTR) for AI/LLM security issues is 36 days, up from 19 days in 2025.

Incident ResponseAI SecurityMTTRLLM Security

Support for hybrid testing models increased by 22 percentage points to 47%.

Hybrid TestingOffensive Security

78% of organizations experienced fully automated scanning tools missing critical vulnerabilities and returning false negatives.

Vulnerability ManagementFalse NegativesAutomationOffensive Security

77% of organizations conduct regular security assessments and pentests for AI-powered products, an increase of 11 percentage points from last year.

Pen TestingAI SecuritySecurity AssessmentsOffensive Security

Among organizations with confirmed AI-related security incidents, Shadow AI contributed to 44% of incidents, data or model poisoning 41%, improper output handling 41%, supply chain vulnerabilities 35%, and prompt injection 34%.

AI SecurityAttack VectorsSupply ChainShadow AI

9% of organizations rely entirely on AI automation for testing, down from 29%, while 47% prefer a hybrid testing model.

AI TestingHybrid TestingOffensive Security

82% of security professionals report that their teams are dedicating significantly more effort into AI security initiatives.

AI Security

32% of AI-related pentest findings were classified as high risk, compared to 12% of all pentest findings overall.

Pen TestingAI SecurityRisk ClassificationOffensive Security

38% of LLM vulnerabilities were fixed while 62% remain open.

AI SecurityVulnerability ManagementLLM VulnerabilitiesOffensive Security

58% of organizations utilize pentesting-as-a-service (PTaaS) for continuous testing.

Penetration TestingOffensive SecurityPTaaS

88% of organizations plan to increase offensive security spending over the next 12 months, with 65% planning moderate increases and 23% planning significant increases.

Security SpendingOffensive SecuritySecurity BudgetsSecurity Investment

One in five organizations experienced an LLM security incident in the last year, while a further 18% are unsure and 19% preferred not to answer.

Security IncidentsLLM Security IncidentOrganizational Risk

57% of C-suite executives believe their organization consistently meets remediation SLAs, yet only 15% of security practitioners agree.

GovernanceSLAsSecurity Operations

33% of organizations reported significant security budget growth in the past year, while 50% saw incremental increases.

Security BudgetsFundingRisk Management

Security teams' confidence in their ability to keep up with the security implications of AI adoption declined from 64% to 51%.

Security ConfidenceAI SecurityAI Adoption

Top-performing organizations have a high-risk finding half-life of 10 days, while bottom-tier organizations have a 249-day half-life—an eight-month gap in exposure.

Vulnerability RemediationRisk ExposureOperational Performance

32% of AI/LLM findings are rated as high risk, nearly 2.7x the overall high-risk rate of 12%.

AI TestingLLM TestingVulnerabilities

61% of security professionals want a "strategic pause" to calibrate defenses against AI-driven threats, up from 48% last year.

AI SecurityAI-Driven ThreatsSecurity Strategy

1% of professional pentesters believe AI-only scanning is effective for uncovering high-impact, exploitable vulnerabilities.

AI SecurityVulnerability DiscoveryOffensive SecurityPenetration Testing

58% of professional pentesters rank PTaaS as the most effective model for uncovering complex vulnerabilities.

Penetration TestingPTaaSVulnerability Discovery

54% of professional pentesters report having discovered a Zero-Day or N-Day vulnerability that had no existing public patch or advisory.

Zero-DayVulnerability DiscoveryOffensive SecurityPenetration Testing

51% of professional pentesters cite the pressure to be the first to submit a finding as their primary frustration with bug bounty programs.

Bug BountyOffensive SecurityPenetration Testing

Sensitive data exposure: 10.5% in the financial services industry (versus 8.0% average in other industries).

Financial servicesPen testVulnerabilitiesSensitive data exposure