Cobalt
Reports
All Statistics
77% of organizations conduct regular security assessments and pentests for AI-powered products, an increase of 11 percentage points from last year.
60% of security professionals state they require stronger LLM testing capabilities.
47% of organizations favor automation for low-risk environments, up 22 percentage points.
94% of organizations explicitly see the importance of keeping humans in the loop for offensive security programs.
60% of organizations expect analysts to shift from executing offensive security tasks to supervising autonomous workflows.
53% of organizations say point-in-time penetration testing becomes outdated before results can be acted upon.
57% of C-suite executives believe their organization consistently meets remediation SLAs, yet only 15% of security practitioners agree.
97% of security professionals state they are adding AI capabilities to their software and services.
The typical organization ultimately resolves 86% of its high-risk findings, but only 52% of high-risk findings are remediated within a five-year time frame.
30% of all bug bounty submissions are invalid or low-value "noise."
98% of professional pen testers prefer the PTaaS model over bug bounties.
15% of professional pentesters rank public bug bounties as the most effective model for uncovering complex vulnerabilities.
Business logic flaws: 2.9% in the financial services industry (versus 2.3% average in other industries).
76% of financial services leaders highlight third-party software vulnerabilities as a top concern.
Approximately one-third of serious issues are never resolved by the organizations in the financial services industry, contributing to backlog and systemic risk.
Healthcare resolved only 57.4% of serious pen test findings. This ranks healthcare 11th of 13 industries. By comparison, transportation led with 80.2%.
Healthcare’s half-life for serious pen test findings was 244 days. This ranks healthcare 11th of 13 industries. Transportation had a half-life of 43 days.
Nearly 40% of healthcare SLAs require serious findings in business-critical assets to be fixed within three days. Another 40% require resolution within four to 14 days.
53% of respondents supplement their efforts with internal testing
68% of security leaders are concerned about the risks associated with third-party software tools and components integrated into their tech stacks.
Nearly nine in 10 security leaders (88%) view penetration testing as an essential component of their overall security programme.
76% of security leaders (C-suite and VP level) are more concerned about long-term genAI threats like adversarial attacks.
45% of cybersecurity practitioners expressed concern about near-term operational genAI risks such as inaccurate outputs.
36% of security leaders expressed concern about near-term operational genAI risks such as inaccurate outputs.
Median time to resolve issues of all criticalities stretches to 67 days.
Since 2017, the median time to resolve serious vulnerabilities has decreased dramatically—from 112 days down to 37 days last year.
This represents a cut of 75 days, or two-thirds.
42% of security professionals plan to increase human-led red team operations.
The meantime to resolve (MTTR) for AI/LLM security issues is 36 days, up from 19 days in 2025.
Support for hybrid testing models increased by 22 percentage points to 47%.
78% of organizations experienced fully automated scanning tools missing critical vulnerabilities and returning false negatives.
Among organizations with confirmed AI-related security incidents, Shadow AI contributed to 44% of incidents, data or model poisoning 41%, improper output handling 41%, supply chain vulnerabilities 35%, and prompt injection 34%.
9% of organizations rely entirely on AI automation for testing, down from 29%, while 47% prefer a hybrid testing model.
82% of security professionals report that their teams are dedicating significantly more effort into AI security initiatives.
32% of AI-related pentest findings were classified as high risk, compared to 12% of all pentest findings overall.
38% of LLM vulnerabilities were fixed while 62% remain open.
58% of organizations utilize pentesting-as-a-service (PTaaS) for continuous testing.
88% of organizations plan to increase offensive security spending over the next 12 months, with 65% planning moderate increases and 23% planning significant increases.
LLMs have the lowest resolution rate of all application types, with just 38% of high-risk issues being fixed.
One in five organizations experienced an LLM security incident in the last year, while a further 18% are unsure and 19% preferred not to answer.
33% of organizations reported significant security budget growth in the past year, while 50% saw incremental increases.
Security teams' confidence in their ability to keep up with the security implications of AI adoption declined from 64% to 51%.
Top-performing organizations have a high-risk finding half-life of 10 days, while bottom-tier organizations have a 249-day half-life—an eight-month gap in exposure.
32% of AI/LLM findings are rated as high risk, nearly 2.7x the overall high-risk rate of 12%.
61% of security professionals want a "strategic pause" to calibrate defenses against AI-driven threats, up from 48% last year.
1% of professional pentesters believe AI-only scanning is effective for uncovering high-impact, exploitable vulnerabilities.
58% of professional pentesters rank PTaaS as the most effective model for uncovering complex vulnerabilities.
54% of professional pentesters report having discovered a Zero-Day or N-Day vulnerability that had no existing public patch or advisory.
51% of professional pentesters cite the pressure to be the first to submit a finding as their primary frustration with bug bounty programs.
The half-life for serious findings is 147 days in the financial services industry. This metric, which accounts for unresolved vulnerabilities, places FS ninth overall out of the thirteen measured industries.