Fortinet

113 stats5 reports

All Statistics

71% of organizations reported between one and nine intrusions, up from 47% the previous year.

Intrusion Detection

2% of organizations reported more than 10 intrusions, unchanged from the previous year.

Intrusion Detection

89% of organizations expect increased regulation within five years or less, up from 66% in 2025.

RegulationCompliance

There were 7,831 confirmed ransomware victims globally, a 389% year-over-year increase from approximately 1,600 victims previously.

Ransomware

Brute force attempts decreased 22% year-over-year.

Brute Force

Within dark web "database" activity, stealer logs comprised 67.12% of advertised/shared datasets, combolists 16.47%, and leaked credentials 5.96%.

Dark WebLeaked CredentialsCombolistStealer Log

Only 15% of organizations feel fully prepared to handle the movement of sensitive data through SaaS and Shadow IT tools.

Fortinet2025 Insider Risk Report·10mo ago
Insider riskSensitive dataSaaSShadow IT

21% of security professionals are concerned about whistleblowers sharing or exposing data.

Fortinet2025 Insider Risk Report·10mo ago
Insider riskData exposure

35% say insufficient budget is the biggest barrier to maturing their insider risk program.

Fortinet2025 Insider Risk Report·10mo ago
Insider riskMaturityBudget

In 2025, 78% of organisations in the critical sector use four or fewer OT vendors for cybersecurity.

Critical sectorOT security

81% of organisations in the critical sector self-assess their OT cybersecurity maturity at Level 3 or 4 on a five-level scale (0–4).

Critical sectorOT security

Among critical sector organisations at Level 4 maturity, 65% reported zero intrusions in the past year.

Critical sectorOT security

In cloud environments, in 70% of observed incidents, attackers gained access through logins from unfamiliar geographies.

Cloud

Over 100 billion compromised records were shared on underground forums in 2024. This represents a 42% year-over-year spike.

Dark web

1.7 billion stolen credential records were shared in underground forums.

CredentialsDark web

Approximately 23% of organizations have visibility into about half of their OT environment.

VisibilityAsset Management

24% of organizations reported intrusions in both IT and OT systems, down from 60% in 2025 and the lowest since 2022.

IT/OT SegmentationIntrusion Detection

60% of organizations report the CISO has ultimate responsibility for OT cybersecurity, down from 69% in 2025.

OT CybersecurityCISO Responsibilities

81% of organizations plan to assign OT cybersecurity to the CISO within the next year, up from 80% in 2025.

OT CybersecurityCISO Responsibilities

Organizations' OT cybersecurity maturity ratings at Level 0 increased to 5%, up from 1% in 2025.

OT CybersecurityOT Cybersecurity Maturity Assessment

Organizations' OT cybersecurity maturity ratings at Level 1 increased to 17%, up from 5% in 2025.

OT CybersecurityOT Cybersecurity Maturity Assessment

Organizations' OT cybersecurity maturity ratings at Level 4 fell to 17%, down from 49% in 2025.

OT CybersecurityOT Cybersecurity Maturity Assessment

Level 4 maturity for OT security solutions declined to 14%, down from 19% in 2025.

OT CybersecurityOT Cybersecurity Maturity Assessment

76% of organizations reported phishing as an intrusion.

Phishing

50% of organizations reported ransomware intrusions, down from 54% in 2025.

Ransomware

There is a 20-point increase in organizations expecting new regulations within two to five years rather than beyond five years.

RegulationCompliance

40% of organizations report their ICS systems are less than five years old, up from 20% in 2025.

Industrial Control Systems

Organizations' OT cybersecurity maturity ratings at Level 2 increased to 27%, up from 13% in 2025.

OT CybersecurityOT Cybersecurity Maturity Assessment

14% of organizations have full visibility into OT systems, up from 5% in 2025.

VisibilityAsset Management

Credential-stealer infections were dominated by RedLine with 911,968 infections (50.80%), Lumma with 499,784 infections (27.84%), and Vidar with 236,778 infections (13.19%).

MalwareCredential TheftInfostealer

The top three targeted sectors by ransomware victims were manufacturing (1,284), business services (824), and retail (682).

RansomwareManufacturingRetailBusiness Services

Ransomware victims concentrate geographically with the U.S. at 3,381, Canada at 374, and Germany at 291.

RansomwareUSCanadaGermany

Global exploitation attempts increased 25.49% year-over-year.

Exploitation

Time-to-exploit (TTE) is 24–48 hours for critical outbreaks, compared to 4.76 days previously.

Time to Exploit

72% of organizations say their budgets for insider risk or data protection are increasing.

Fortinet2025 Insider Risk Report·10mo ago
Insider riskBudgetInvestment

77% of organizations experienced insider-driven data loss in the past 18 months.

Fortinet2025 Insider Risk Report·10mo ago
Insider riskData loss

When asked which egress channels for the outflow of sensitive data does your organization worry most about, 56% said Generative AI tools like ChatGPT.

Fortinet2025 Insider Risk Report·10mo ago
Insider riskEgress channelGenAI

43% of security professionals are concerned about disgruntled employees.

Fortinet2025 Insider Risk Report·10mo ago
Insider riskDisgruntled employees

42% say organizational silos (e.g., Security vs HR vs Legal) is the biggest barrier to maturing their insider risk program.

Fortinet2025 Insider Risk Report·10mo ago
Insider riskMaturitySilos

55% of security professionals are concerned about departing employees.

Fortinet2025 Insider Risk Report·10mo ago
Insider risk

• 21% of organizations faced more than 20 insider-related data loss incidents in the past 18 months.

Fortinet2025 Insider Risk Report·10mo ago
Insider riskData loss

When asked which egress channels for the outflow of sensitive data does your organization worry most about, 44% said messaging apps.

Fortinet2025 Insider Risk Report·10mo ago
Insider riskEgress channelMessaging app

17% of insider incidents involved personal healthcare information.

Fortinet2025 Insider Risk Report·10mo ago
Insider riskData lossHealthcare information

73% of security professionals are concerned about careless, negligent, or uninformed employees.

Fortinet2025 Insider Risk Report·10mo ago
Insider risk

53% of insider incidents involved customer records.

Fortinet2025 Insider Risk Report·10mo ago
Insider riskData lossCustomer records

43% of security professionals are concerned about third-party partners or contractors with access to their environment.

Fortinet2025 Insider Risk Report·10mo ago
Insider riskThird-party partnersThird-party contractors

12% of detected insider incidents could not be attributed, underscoring challenges in detection.

Fortinet2025 Insider Risk Report·10mo ago
Insider risk

When asked which egress channels for the outflow of sensitive data does your organization worry most about, 69% said email.

Fortinet2025 Insider Risk Report·10mo ago
Insider riskEgress channelEmail

40% of insider incidents involved business-sensitive financial and strategic information.

Fortinet2025 Insider Risk Report·10mo ago
Insider riskData lossFinancial data

47% of insider incidents involved personal information or Personally Identifiable Information (PII).

Fortinet2025 Insider Risk Report·10mo ago
Insider riskData lossPII