Fortinet

113 stats5 reports

All Statistics

2% of organizations reported more than 10 intrusions, unchanged from the previous year.

Intrusion Detection

89% of organizations expect increased regulation within five years or less, up from 66% in 2025.

RegulationCompliance

Approximately 23% of organizations have visibility into about half of their OT environment.

VisibilityAsset Management

Time-to-exploit (TTE) is 24–48 hours for critical outbreaks, compared to 4.76 days previously.

Time to Exploit

Credential-stealer infections were dominated by RedLine with 911,968 infections (50.80%), Lumma with 499,784 infections (27.84%), and Vidar with 236,778 infections (13.19%).

MalwareCredential TheftInfostealer

The top three targeted sectors by ransomware victims were manufacturing (1,284), business services (824), and retail (682).

RansomwareManufacturingRetailBusiness Services

43% of security professionals are concerned about third-party partners or contractors with access to their environment.

Fortinet2025 Insider Risk Report·11mo ago
Insider riskThird-party partnersThird-party contractors

Only 33% of organizations using DLP agree they gained immediate insight into data usage.

Fortinet2025 Insider Risk Report·11mo ago
Insider riskDLP

37% of organizations reported detecting between 6 and 20 insider-related data loss incidents in the past 18 months.

Fortinet2025 Insider Risk Report·11mo ago
Insider riskData loss

Only 5% of 2025 organisations in the critical sector stated that OT security is owned by the VP or lower, compared to 59% in 2022.

Critical sectorOT security

50% of critical sector organisations reported experiencing one or more cybersecurity incidents.

Critical sectorOT security

Over 95% of the surveyed organisations in the critical sector have elevated OT security to the C-suite level since 2022.

Critical sectorOT security

In terms of geography for attacks on critical sectors, the United States bore the brunt of attacks (61%), followed by the United Kingdom (6%) and Canada (5%).

USUKCanadaSecurity incident

Over 40,000 new vulnerabilities were added to the National Vulnerability Database in 2024. This marks a 39% rise from 2023.

Vulnerabilities

In cloud environments, in 70% of observed incidents, attackers gained access through logins from unfamiliar geographies.

Cloud

71% of organizations reported between one and nine intrusions, up from 47% the previous year.

Intrusion Detection

24% of organizations reported intrusions in both IT and OT systems, down from 60% in 2025 and the lowest since 2022.

IT/OT SegmentationIntrusion Detection

81% of organizations plan to assign OT cybersecurity to the CISO within the next year, up from 80% in 2025.

OT CybersecurityCISO Responsibilities

Organizations' OT cybersecurity maturity ratings at Level 0 increased to 5%, up from 1% in 2025.

OT CybersecurityOT Cybersecurity Maturity Assessment

Organizations' OT cybersecurity maturity ratings at Level 1 increased to 17%, up from 5% in 2025.

OT CybersecurityOT Cybersecurity Maturity Assessment

Organizations' OT cybersecurity maturity ratings at Level 4 fell to 17%, down from 49% in 2025.

OT CybersecurityOT Cybersecurity Maturity Assessment

Level 4 maturity for OT security solutions declined to 14%, down from 19% in 2025.

OT CybersecurityOT Cybersecurity Maturity Assessment

76% of organizations reported phishing as an intrusion.

Phishing

50% of organizations reported ransomware intrusions, down from 54% in 2025.

Ransomware

There is a 20-point increase in organizations expecting new regulations within two to five years rather than beyond five years.

RegulationCompliance

40% of organizations report their ICS systems are less than five years old, up from 20% in 2025.

Industrial Control Systems

60% of organizations report the CISO has ultimate responsibility for OT cybersecurity, down from 69% in 2025.

OT CybersecurityCISO Responsibilities

Organizations' OT cybersecurity maturity ratings at Level 2 increased to 27%, up from 13% in 2025.

OT CybersecurityOT Cybersecurity Maturity Assessment

14% of organizations have full visibility into OT systems, up from 5% in 2025.

VisibilityAsset Management

Brute force attempts decreased 22% year-over-year.

Brute Force

There were 7,831 confirmed ransomware victims globally, a 389% year-over-year increase from approximately 1,600 victims previously.

Ransomware

Within dark web "database" activity, stealer logs comprised 67.12% of advertised/shared datasets, combolists 16.47%, and leaked credentials 5.96%.

Dark WebLeaked CredentialsCombolistStealer Log

Ransomware victims concentrate geographically with the U.S. at 3,381, Canada at 374, and Germany at 291.

RansomwareUSCanadaGermany

Global exploitation attempts increased 25.49% year-over-year.

Exploitation

41% of organizations reported financial losses between $1 million and $10 million for their most significant insider incident.

Fortinet2025 Insider Risk Report·11mo ago
Insider riskInsider incident consequences

Only 18% of organizations report achieving Maturity Level 3 (Optimized: Unified strategy, cross-functional governance, behavioral analytics, and integrated enforcement).

Fortinet2025 Insider Risk Report·11mo ago
Insider riskMaturity

Only 27% of organizations using DLP can identify which users are putting data at risk.

Fortinet2025 Insider Risk Report·11mo ago
Insider riskDLP

61% of security leaders are very concerned about credential compromise being used for insider activity over the next 12 months.

Fortinet2025 Insider Risk Report·11mo ago
Insider riskCredential compromise

61% of security leaders prioritize "Day-one" data visibility across environments in a next-generation solution.

Fortinet2025 Insider Risk Report·11mo ago
Insider riskDLP

Only 15% of organizations feel fully prepared to handle the movement of sensitive data through SaaS and Shadow IT tools.

Fortinet2025 Insider Risk Report·11mo ago
Insider riskSensitive dataSaaSShadow IT

53% of insider incidents involved customer records.

Fortinet2025 Insider Risk Report·11mo ago
Insider riskData lossCustomer records

21% of security professionals are concerned about whistleblowers sharing or exposing data.

Fortinet2025 Insider Risk Report·11mo ago
Insider riskData exposure

35% say insufficient budget is the biggest barrier to maturing their insider risk program.

Fortinet2025 Insider Risk Report·11mo ago
Insider riskMaturityBudget

72% of organizations say their budgets for insider risk or data protection are increasing.

Fortinet2025 Insider Risk Report·11mo ago
Insider riskBudgetInvestment

77% of organizations experienced insider-driven data loss in the past 18 months.

Fortinet2025 Insider Risk Report·11mo ago
Insider riskData loss

40% of insider incidents involved business-sensitive financial and strategic information.

Fortinet2025 Insider Risk Report·11mo ago
Insider riskData lossFinancial data

43% of security professionals are concerned about disgruntled employees.

Fortinet2025 Insider Risk Report·11mo ago
Insider riskDisgruntled employees

When asked which egress channels for the outflow of sensitive data does your organization worry most about, 56% said Generative AI tools like ChatGPT.

Fortinet2025 Insider Risk Report·11mo ago
Insider riskEgress channelGenAI

42% say organizational silos (e.g., Security vs HR vs Legal) is the biggest barrier to maturing their insider risk program.

Fortinet2025 Insider Risk Report·11mo ago
Insider riskMaturitySilos

55% of security professionals are concerned about departing employees.

Fortinet2025 Insider Risk Report·11mo ago
Insider risk