Cobalt

78 STATS5 REPORTS

All Statistics

Server security misconfigurations: 34.9% in the financial services industry (versus 27.9% average in other industries).

Financial servicesPen testVulnerabilitiesMisconfigurationServer side misconfiguration

Sensitive data exposure: 10.5% in the financial services industry (versus 8.0% average in other industries).

Financial servicesPen testVulnerabilitiesSensitive data exposure

Components with known vulnerabilities: 6.1% in the financial services industry (versus 5.5% average in other industries).

Financial servicesPen testVulnerabilities

Approximately one-third of serious issues are never resolved by the organizations in the financial services industry, contributing to backlog and systemic risk.

Financial servicesPen testVulnerability resolutionVulnerabilities

Financial services firms demonstrate strengths in avoiding common, code-level flaws due to mature security programs and automated scanning (SAST/DAST). However, they struggle with vulnerabilities that require human-led testing.

Financial servicesPen testVulnerabilitiesMaturitySAST

Business logic flaws: 2.9% in the financial services industry (versus 2.3% average in other industries).

Financial servicesPen testVulnerabilitiesBusiness logic flaw

Server-side injection (Web/API): 4.2% in the financial services industry (versus 5.3% average in other industries).

Financial servicesPen testVulnerabilitiesServer-side injectionWeb

68% of financial services leaders highlight GenAI-related risks as a top concern.

Financial servicesPen testGenAI

46% of financial services leaders highlight insider threats as a top concern.

Financial servicesPen testInsider threat

The Median Time to Remediation (MTTR) for serious findings is 61 days in the financial services industry. This ranks financial services 11th of 13 industries measured.

Financial servicesPen testMTTR

78% of financial services firms report fixing critical vulnerabilities in business-critical assets within 14 days, indicating they narrowly meet strict internal SLA requirements.

Financial servicesPen testVulnerabilitiesBusiness-critical assetSLA

70% of financial services firms report that delays in scheduling pentests sometimes impact compliance or business timelines.

Financial servicesPen testCompliance

76% of financial services leaders highlight third-party software vulnerabilities as a top concern.

Financial servicesPen testVulnerabilitiesThird-party software

The half-life for serious findings is 147 days in the financial services industry. This metric, which accounts for unresolved vulnerabilities, places FS ninth overall out of the thirteen measured industries.

Financial servicesPen testHalf-lifeVulnerabilitiesVulnerability resolution

Cross-site scripting (Web/API): 5.0% in the financial services industry (versus 9.7% average in other industries).

Financial servicesPen testVulnerabilitiesCross-site scriptingWeb

Industries like hospitality resolve serious findings significantly faster than the financial services industry (61 days vs 20 days).

Financial servicesPen testMTTRHospitality

The financial services industry resolves about two-thirds (66.7%) of serious findings. This ranks the industry 10 out of the 13 industries Cobalt researched.

Financial servicesPen testVulnerability resolutionVulnerabilities

Healthcare resolved only 57.4% of serious pen test findings. This ranks healthcare 11th of 13 industries. By comparison, transportation led with 80.2%.

HealthcarePen testVulnerabilitiesTransportation

71% of healthcare leaders cited GenAI as the top risk.

HealthcareGenAI

14% of healthcare organizations resolve critical findings in business-critical within eight to 14 days.

HealthcarePen testVulnerabilities

68% of healthcare leaders cited third-party software as the top risk.

HealthcareThird-party risk

The 2025 breach at DaVita compromised over 900,000 patients' personal and clinical data.

HealthcareBreach

Just 13.3% of healthcare pentest findings qualify as “serious”. This ranks healthcare 6th-best out of 13 industries.

HealthcarePen testVulnerabilities

71% of healthcare leaders cited GenAI as the top risk.

HealthcareGenAI

43% of healthcare organizations resolve critical findings in business-critical assets in one to three days.

HealthcarePen testVulnerabilities

Healthcare’s half-life for serious pen test findings was 244 days. This ranks healthcare 11th of 13 industries. Transportation had a half-life of 43 days.

HealthcarePen testVulnerabilitiesTransportation

Healthcare’s median time to resolve serious pen test findings was 58 days. This ranks healthcare 10th of 13 industries. Hospitality led with 20 days.

HealthcarePen testVulnerabilitiesHospitality

Nearly 40% of healthcare SLAs require serious findings in business-critical assets to be fixed within three days. Another 40% require resolution within four to 14 days.

HealthcarePen testSLAVulnerabilities

37% of healthcare organizations resolve critical findings in business-critical assets within four to seven days.

HealthcarePen testVulnerabilities

68% of healthcare leaders cited third-party software as the top risk.

HealthcareThird-party risk

53% of respondents supplement their efforts with internal testing

TestingInternal testing

73% of security leaders reported receiving at least one notification of a software supply chain vulnerability or incident within the past year.

Supply chain riskSoftware supply chain

Nearly nine in 10 security leaders (88%) view penetration testing as an essential component of their overall security programme.

TestingPen testing

55% of respondents conduct independent code reviews.

Code review

46% of security leaders are uneasy about AI-driven features and large language models.

AI

55% of security leaders are constantly worried that a single employee mistake could put their entire organisation at risk.

Human error

60% of security leaders believe that attackers are evolving too quickly to maintain a truly resilient security posture.

Security postureAttacker capabilities

68% of security leaders are concerned about the risks associated with third-party software tools and components integrated into their tech stacks.

Supply chain riskThird-party softwareThird-party software tools

68% of security leaders state that their boards now view the secure deployment of generative AI as a critical priority.

Gen AI

More than half (58%) of respondents require third-party penetration test reports to validate software security.

TestingPen testingSoftware security

68% of CISOs consider supply chain risk and generative AI security to be top concerns, viewing them as intertwined challenges that are redefining the attack surface.

Supply chain riskGen AICybersecurity risk

45% of cybersecurity practitioners expressed concern about near-term operational genAI risks such as inaccurate outputs.

AIGen AI

33% of respondents are still not conducting regular security assessments, including penetration testing, for their Large Language Model (LLM) deployments.

AIGen AILLMPen testing

68% of cybersecurity practitioners expressed concern about long-term genAI threats like adversarial attacks.

AIGen AI

32% of LLM pentest findings are serious

AIGen AIPen testing

Overall, 69% of serious findings across all pentest categories are resolved.

AIGen AIPen testing

The resolution rate for high-severity vulnerabilities found in LLM pentests falls to just 21%.

AIGen AIPen testing

48% of security leaders believe a “strategic pause” is needed to recalibrate defenses against genAI-driven threats.

AIGen AI

36% of security leaders and practitioners admit that generative AI (genAI) is moving faster than their teams can manage.

AIGen AI

72% of security leaders cite genAI-related attacks as their top IT risk.

AIGen AI