CyCognito
Reports
All Statistics
In one analysis, health care & insurance had 16% of vulnerable assets across cloud, APIs, and web applications.
In one analysis, education had 17.6% vulnerable cloud assets.
In one analysis, the services sector had 10.6% vulnerable APIs.
Critical vulnerabilities (CVSS 9.0 or higher) were detected on assets hosted by all cloud providers, though uncommon.
38% of assets hosted by Google Cloud were vulnerable to at least one security issue or misconfiguration. This rate for Google Cloud was over 2.5x more than assets hosted by AWS.
Assets hosted by Azure showed 0.07% with critical vulnerabilities.
In one analysis, construction had 18% of vulnerable assets across cloud, APIs, and web applications.
19.6% of all analyzed web apps are vulnerable.
In one analysis, professional services had 28% of vulnerable assets across cloud, APIs, and web applications.
In one analysis, media had 21% of vulnerable assets across cloud, APIs, and web applications.
In one analysis, energy had 18% of vulnerable assets across cloud, APIs, and web applications.
13.6% of all analyzed cloud assets are vulnerable.
Top 5 industries by web‑app vulnerability: Education: 35.3%, Retail: 30.9%, Government: 30.4%, Professional Services: 30.1%, Media: 25.7%.
In one analysis, transport had 12% of vulnerable assets across cloud, APIs, and web applications.
In one analysis, the government sector had 30.4% vulnerable web applications.
In one analysis, the services sector had 25% vulnerable cloud assets.
In one analysis, hospitality had 15% of vulnerable assets across cloud, APIs, and web applications.
Top 5 industries by API vulnerability: Education: 37.7%, Retail: 29.8%, Media: 18.8%, Government: 18.5%, Professional Services: 10.6%.
In one analysis, retail had 27% of vulnerable assets across cloud, APIs, and web applications.
In one analysis, the services sector had 30.1% vulnerable web applications.
In one analysis, the media sector had 25.7% vulnerable web applications.
In one analysis, government had 26% of vulnerable assets across cloud, APIs, and web applications.
In one analysis, technology had 15% of vulnerable assets across cloud, APIs, and web applications.
In one analysis, retail had 29.8% vulnerable APIs.
In one analysis, education had 37.7% vulnerable APIs.
In one analysis, telecommunications had 15% of vulnerable assets across cloud, APIs, and web applications.
In one analysis, education had 31% of vulnerable assets across cloud, APIs, and web applications.
In one analysis, education had 35.3% vulnerable web applications.
In one analysis, the media sector had 18.8% vulnerable APIs.
In one analysis, the government sector had 18.4% vulnerable cloud assets.
In one analysis, the media sector had 13.8% vulnerable cloud assets.
In one analysis, the government sector had 18.5% vulnerable APIs.
Top 5 industries by cloud‑asset vulnerability: Professional Services: 25.0%, Retail: 23.3%, Government: 18.4%, Education: 17.6%, Media: 13.8%.
In one analysis, retail had 30.9% vulnerable web applications.
In one analysis, finance had 5% of vulnerable assets across cloud, APIs, and web applications.
In one analysis, retail had 23.3% vulnerable cloud assets.
20.8% of all APIs analyzed are vulnerable.
In one analysis, manufacturing had 19% of vulnerable assets across cloud, APIs, and web applications.
15% of assets hosted by AWS were vulnerable to at least one security issue or misconfiguration.
27% of assets hosted by Azure were vulnerable to at least one security issue or misconfiguration.
AWS showed the lowest rate for assets with both critical and easily exploitable issues at 0.02%.
Assets with both critical and easily exploitable issues were found across all cloud providers.
10% of assets on hosting providers other than AWS, Google, and Azure had easily exploitable vulnerabilities. This compares to 5 percent hosted on Google Cloud with easily exploitable vulnerabilities and just 2 percent on AWS and Azure with easily exploitable vulnerabilities.
Assets hosted by cloud providers other than AWS, Google, and Azure showed approximately 10 times higher rates of critical vulnerabilities compared to AWS, Google Cloud, and Azure.
Alternative cloud and hosting providers showed rates ten times higher than AWS for assets with both critical and easily exploitable issues
Assets hosted by AWS and Google Cloud showed 0.04% with critical vulnerabilities.