Fortinet
Reports
All Statistics
2% of organizations reported more than 10 intrusions, unchanged from the previous year.
89% of organizations expect increased regulation within five years or less, up from 66% in 2025.
Approximately 23% of organizations have visibility into about half of their OT environment.
Time-to-exploit (TTE) is 24–48 hours for critical outbreaks, compared to 4.76 days previously.
Credential-stealer infections were dominated by RedLine with 911,968 infections (50.80%), Lumma with 499,784 infections (27.84%), and Vidar with 236,778 infections (13.19%).
The top three targeted sectors by ransomware victims were manufacturing (1,284), business services (824), and retail (682).
43% of security professionals are concerned about third-party partners or contractors with access to their environment.
Only 33% of organizations using DLP agree they gained immediate insight into data usage.
37% of organizations reported detecting between 6 and 20 insider-related data loss incidents in the past 18 months.
Only 5% of 2025 organisations in the critical sector stated that OT security is owned by the VP or lower, compared to 59% in 2022.
50% of critical sector organisations reported experiencing one or more cybersecurity incidents.
Over 95% of the surveyed organisations in the critical sector have elevated OT security to the C-suite level since 2022.
In terms of geography for attacks on critical sectors, the United States bore the brunt of attacks (61%), followed by the United Kingdom (6%) and Canada (5%).
Over 40,000 new vulnerabilities were added to the National Vulnerability Database in 2024. This marks a 39% rise from 2023.
In cloud environments, in 70% of observed incidents, attackers gained access through logins from unfamiliar geographies.
71% of organizations reported between one and nine intrusions, up from 47% the previous year.
24% of organizations reported intrusions in both IT and OT systems, down from 60% in 2025 and the lowest since 2022.
81% of organizations plan to assign OT cybersecurity to the CISO within the next year, up from 80% in 2025.
Organizations' OT cybersecurity maturity ratings at Level 0 increased to 5%, up from 1% in 2025.
Organizations' OT cybersecurity maturity ratings at Level 1 increased to 17%, up from 5% in 2025.
Organizations' OT cybersecurity maturity ratings at Level 4 fell to 17%, down from 49% in 2025.
Level 4 maturity for OT security solutions declined to 14%, down from 19% in 2025.
76% of organizations reported phishing as an intrusion.
50% of organizations reported ransomware intrusions, down from 54% in 2025.
There is a 20-point increase in organizations expecting new regulations within two to five years rather than beyond five years.
40% of organizations report their ICS systems are less than five years old, up from 20% in 2025.
60% of organizations report the CISO has ultimate responsibility for OT cybersecurity, down from 69% in 2025.
Organizations' OT cybersecurity maturity ratings at Level 2 increased to 27%, up from 13% in 2025.
14% of organizations have full visibility into OT systems, up from 5% in 2025.
Brute force attempts decreased 22% year-over-year.
There were 7,831 confirmed ransomware victims globally, a 389% year-over-year increase from approximately 1,600 victims previously.
Within dark web "database" activity, stealer logs comprised 67.12% of advertised/shared datasets, combolists 16.47%, and leaked credentials 5.96%.
Ransomware victims concentrate geographically with the U.S. at 3,381, Canada at 374, and Germany at 291.
Global exploitation attempts increased 25.49% year-over-year.
41% of organizations reported financial losses between $1 million and $10 million for their most significant insider incident.
Only 18% of organizations report achieving Maturity Level 3 (Optimized: Unified strategy, cross-functional governance, behavioral analytics, and integrated enforcement).
Only 27% of organizations using DLP can identify which users are putting data at risk.
61% of security leaders are very concerned about credential compromise being used for insider activity over the next 12 months.
61% of security leaders prioritize "Day-one" data visibility across environments in a next-generation solution.
Only 15% of organizations feel fully prepared to handle the movement of sensitive data through SaaS and Shadow IT tools.
53% of insider incidents involved customer records.
21% of security professionals are concerned about whistleblowers sharing or exposing data.
35% say insufficient budget is the biggest barrier to maturing their insider risk program.
72% of organizations say their budgets for insider risk or data protection are increasing.
77% of organizations experienced insider-driven data loss in the past 18 months.
40% of insider incidents involved business-sensitive financial and strategic information.
43% of security professionals are concerned about disgruntled employees.
When asked which egress channels for the outflow of sensitive data does your organization worry most about, 56% said Generative AI tools like ChatGPT.
42% say organizational silos (e.g., Security vs HR vs Legal) is the biggest barrier to maturing their insider risk program.
55% of security professionals are concerned about departing employees.