Filigran
Reports
All Statistics
61% of organizations say they cannot determine which vulnerabilities are most likely to be exploited in real-world attacks.
German security teams report spending just 27% of their time on low-priority or non-exploitable risks.
94% say a proactive cybersecurity posture in 2026 will depend on integrating threat intelligence with exposure management.
Only 41% of organizations have a fully consolidated view of cyber risk exposure.
Organizations deploy an average of 14 different threat intelligence feeds.
52% of North American organizations report having a fully consolidated view of cyber risk exposure.
Concern about disrupting systems (49%), excessive manual effort (46%), and poor integration with existing security processes (42%) are the top barriers to validating whether threats are exploitable.
Currently, 37% of exposure management processes are AI-driven and organizations expect this to reach 59% within two years.
56% say AI and automation would most help in understanding which threats are relevant to their specific environment.
93% agree that delaying improvements to how they manage cyber risk increases the likelihood of serious incidents.
EMEA organizations report 37% having a fully consolidated view of exposure and 35% using continuous, automated validation.
APAC organizations report 31% having a fully consolidated view of exposure and 27% using continuous, automated validation.
84% of security decision-makers and practitioners agree that cyberattacks exploit known risks that are not prioritized.
Security teams spend 42% of their time investigating risks that later prove low priority or non-exploitable.
Germany leads surveyed countries with 58% adoption of automated validation.
88% of security teams acknowledge that periodic assessments cannot keep pace with the speed of change in their environments.
95% of organizations agree greater automation would improve their confidence that teams are focused on the most important risks.
Three-quarters of organizations plan to invest in both cyber risk quantification tools and exposure assessment capabilities over the next 12–24 months.
58% of U.S. organizations report a fully established CTEM program.
51% of North American organizations use threat intelligence within a continuous, automated validation process.
Only 38% of organizations use threat intelligence within a continuous, fully automated validation process.
Organizations outside North America are roughly 20 percentage points behind North America on both consolidated cyber risk visibility and continuous automated validation.
88% of security teams agree that without greater automation, they cannot keep up with the volume of risks they must assess.
59% say AI and automation would most help detect vulnerabilities, misconfigurations, and exposures.
89% say reducing alert noise would help identify which alerts represent real business risk.
Nearly 9 in 10 security decision-makers and practitioners agree that threat intelligence alone does not reduce risk unless it is continuously validated against actual exposure.
54% say AI and automation would most help in validating whether exposures are realistically exploitable.
27% of security professionals would prioritise automating the conversion of threat intelligence into actionable priorities.
52% of security professionals say threat intelligence helps inform decisions but still requires significant human judgement.
44% of security professionals say a human should always remain in the loop for security decisions.
16% of security professionals say supply chain and third-party risk is the boardroom cyber priority boards ask about most.
15% of security professionals say cloud and infrastructure exposure is the boardroom cyber priority boards ask about most.
21% of security professionals say the volume of threat intelligence information often creates more noise than clarity.
38% of security professionals would trust AI only for low-risk, routine security decisions.
11% of security professionals are still experimenting with AI-driven decision-making.
28% of security professionals say their organisation has a continuous, proactive exposure management programme in place.
13% of security professionals say delays waiting for other teams to act on findings wastes the most time in their security team.
19% of security professionals completely trust threat intelligence to tell them what to fix first.
19% of security professionals say regulatory compliance (including NIS2 and DORA) is the boardroom cyber priority boards ask about most.
32% of security professionals say AI-driven threats and organisational preparedness are the top issues boards ask about most.
8% of security professionals would trust AI to make security decisions without human approval.
41% of cybersecurity professionals identify AI-powered attacks at scale as their biggest security concern, compared with 21% citing supply chain risk and 21% citing unknown threats.
25% of security professionals say validating whether risks are real wastes the most time in their security team.
26% of security professionals say chasing false positives and low-priority alerts wastes the most time in their security team.
17% of security professionals say manually stitching together data from multiple security tools wastes the most time in their security team.
In 2025, data breaches accounted for 64% of security incidents affecting financial institutions.
In 2025, 90% of breaches affecting financial institutions were financially motivated.
In 2025, ransomware accounted for 36% of security incidents affecting financial institutions.
Third-party involvement occurs in 30% of financial-sector breaches.
In 2025, approximately 12.8% of B2B financial organizations experienced ransomware.