Delinea
Reports
All Statistics
76% of employees say they have bypassed the required approval process for using AI at some point.
99.7% of organizations have a formal policy governing what data AI tools and agents can access.
About half of organizations check AI access against policy in real time.
Only 33% of cyber insurance policies cover lost revenue, and 45% cover ransomware negotiations or payment.
72% of organizations filed a cyber insurance claim in the past year, marking a 10-point increase from 2024.
45% of organizations reported that their cyber insurance policy could be voided if required security controls were not in place.
36% of IT leaders can always trace a sensitive AI access event back to a named human authorizer.
47% of organizations lack enforcement at the moment of action in at least two major environments.
87% of IT leaders say an AI tool or agent accessed sensitive data beyond its intended scope in the past year.
Fewer than one in five IT leaders can detect AI scope violation as it happens.
60% of employees say they have felt pressured to use AI on sensitive or confidential data even when they were unsure it was permitted.
55% of organizations take a full day or longer to detect when an AI agent steps outside its scope.
Nearly all organizations require named-individual approval for at least some sensitive AI use.
46% of organizations that filed claims reported that the incident triggering their claim was either identity-related or caused by a privileged account compromise.
86% of organizations reported that their insurers offered premium reductions or credits for their use of AI in security controls.
64% of organizations that experienced a decrease in overall cyber insurance costs in the past year credited AI adoption as a key factor.
70% of organizations reported an increase in their insurance costs in the past year.
51% of organizations were required to adopt an insurer’s preferred security solution or appliance to secure coverage.
97% of organizations indicated that identity-related controls influence their cyber insurance premiums or coverage terms in some way.
41% of organizations cited Privileged Access Management as the top differentiator in how underwriters viewed their insurability.