Contrast Security
Reports
All Statistics
The average application carries 106 vulnerability findings, including 22 rated High or Critical.
54% of CVE instances observed in third-party production code come from CVEs published more than a year ago.
Scanning a 2 million-line codebase consumes roughly $315 in tokens while triaging the resulting findings costs approximately $128,000.
On average, applications contain 30 serious vulnerabilities.
It takes an average of 84 days to patch even the most critical flaws in applications.
Attackers exploit new application vulnerabilities in just 5 days.
64% of financial sector respondents reported experiencing cybersecurity incidents in the past 12 months.
43% of financial sector respondents cited dwell time as a key concern.
61% of financial sector respondents consider their WAFs to be effective.
A single AI scanner reproduces only 17% of its own findings when run three times against the same code.
More than 60% of applications see fewer than 3,000 attacks per month.
An average of 42 monthly attacks per application are viable, meaning exploitation attempts reach and trigger real vulnerable code.
SQL injection appears in the top five viable attack techniques for every industry vertical analyzed.
More than a quarter of applications absorb upward of 30,000 attacks per month.
Three AI scanners analyzing the same codebase agree on only 5% of findings.
Critical vulnerabilities in custom code take an average of 92 days to remediate.
Attackers touch the average application 11,382 times per month, roughly once every four minutes.
The average application is exposed to 81 confirmed, viable attacks each month that evade other defences
Developer teams remediate, on average, 6 application vulnerabilities per month.
The average application is targeted by attackers once every 3 minutes.
Applications face an average of 17 new application vulnerabilities per month.
Fewer than 25% of financial sector respondents are confident that their current security controls could mitigate a zero-day attack.
Over two-thirds of financial sector respondents experienced attacks focused on stealing non-public market information.
Over half of financial institutions experienced a supply chain attack.
60% of financial sector respondents said their investments in XDR did not provide visibility into behavioural anomalies at the application layer.
38% of financial sector respondents reported a lack of visibility into the application layer as a concern.
82% of financial institutions overrely on web application firewalls (WAF).
Financial sector respondents reported a 12.5% increase in destructive cyber attacks.
71% of of financial sector respondents reported zero-day attacks as the key concern for safeguarding applications and APIs.