Intruder
Reports
All Statistics
More than two-thirds of organizations operate multi-cloud environments.
87% of AWS S3 buckets do not enforce HTTPS.
84% of AWS accounts have permissive ingress to sensitive ports.
26% of organizations leave MySQL databases exposed to the internet.
More than 1 in 7 organizations expose API documentation to the internet.
Midmarket organizations average 56 days to remove exposures, nearly four times slower than smaller enterprises.
51% of midmarker security leaders say it would take approximately a week to assess their exposure to a critical zero-day.
38% of midmarket security leaders say their digital estate grew significantly over the past 24 months.
44% of midmarket organizations describe a stack that is either outgrown or fragmented.
55% of Azure accounts contain Entra users without multifactor authentication (MFA).
76% of AWS accounts have publicly exposed services, compared to 64% of Azure accounts and 8% of Google Cloud accounts.
Organizations with 1,000–5,000 employees take 35 days to remediate cloud issues.
Weak IAM controls affect 87% to 97% of accounts across AWS, Azure, and Google Cloud.
75% of Google Cloud accounts are missing OS Login controls.
IAM weaknesses occur in 87% of SMEs, 95% of midmarket organizations, and 98% of large enterprises.
AWS leads in prevalence across five of the six misconfiguration categories.
83% of AWS accounts have IAM policies that allow privilege escalation.
Smaller organizations remediate cloud issues in 8 to 16 days.
Azure's top three misconfigurations affect between 61% and 67% of Azure accounts.
Permissive firewalls affect 83% of AWS accounts, 45% of Azure accounts, and 34% of Google Cloud accounts.
Organizations with 10,000+ employees remediate cloud issues in 10 days.
15% of organizations leave WordPress admin panels internet-facing.
Organizations with over 5,000 employees manage almost 35 times more external assets than small enterprises with 51–250 employees.
8% of organizations leave phpMyAdmin internet-facing.
8% of organizations expose UPnP on the public internet.
9% of organizations expose SNMP on the public internet.
49% of organizations expose risky ports and services.
Retail firms average 10 days to remediate exposures.
Small organizations remediate vulnerabilities fastest, averaging 14–18 days to fix exposures.
Organizations in the 5,000–10,000 employee range average 56 days to remediate exposures.
Banks remediate exposures in 11 days on average.
The insurance sector requires nearly 50 days to remediate exposures.
Financial service organizations outside of banking require 24 days to remediate exposures.
Automotive and pharmaceutical sectors average 43 days to remediate exposures.
Organizations with over 5,000 employees manage more than twice as many external assets as organizations with 1,000–5,000 employees.
46% of midmarket organizations say enterprise platforms assume more staff, budget, or complexity than they can support.
The dominant investment priorities for midmarket organizations are AI and automation (49%) and adding new solutions (33%).
91% of midmarket security leaders say their digital estate grew over the past 24 months.
86% of SaaS midmarket organizations kept headcount at pace with their digital estate, with only 10% growing more slowly.
Only 9% of midmarket organizations discuss cyber risk at board level.
Around 70% of midmarket security leaders say headcount has kept pace with their digital estate.
29% of midmarket organizations say SME tools no longer meet their needs.
41% of respondents report using AI pentesting, and it appears in the top five most-adopted tools for fintech, manufacturing, and retail.
89% of midmarket security leaders report increasing budgets.
64% of midmarket security leaders feel their posture scaled appropriately with growth.
Only 51% of healthcare midmarket organizations kept headcount at pace with their digital estate, and 26% grew more slowly.
94% of midmarket security leaders are confident in their ability to identify and remediate critical risks before attackers exploit them.
Only 30% of midmarket organizations grew headcount faster than their digital estate.
36% of midmarket respondents acknowledge their security posture hasn't scaled appropriately with digital estate growth.
44% of midmarket organizations have either outgrown their stack or stitched it together from point solutions that don't provide a unified view.