Intruder

50 stats3 reports

All Statistics

More than two-thirds of organizations operate multi-cloud environments.

Multi-CloudCloud Security

87% of AWS S3 buckets do not enforce HTTPS.

Cloud StorageAWS S3HTTPS

84% of AWS accounts have permissive ingress to sensitive ports.

Cloud SecurityAWS

26% of organizations leave MySQL databases exposed to the internet.

MySQL DatabaseInternet-facingExposure

More than 1 in 7 organizations expose API documentation to the internet.

API SecurityAttack SurfaceInternet-facingExposure

Midmarket organizations average 56 days to remove exposures, nearly four times slower than smaller enterprises.

RemediationMidmarketVulnerability Management

51% of midmarker security leaders say it would take approximately a week to assess their exposure to a critical zero-day.

MidmarketCritical Zero-Day

38% of midmarket security leaders say their digital estate grew significantly over the past 24 months.

MidmarketDigital Estate

44% of midmarket organizations describe a stack that is either outgrown or fragmented.

MidmarketStackTechTools

55% of Azure accounts contain Entra users without multifactor authentication (MFA).

EntraAzureMFA

76% of AWS accounts have publicly exposed services, compared to 64% of Azure accounts and 8% of Google Cloud accounts.

Public ExposureCloud SecurityAWSAzureGoogle Cloud

Organizations with 1,000–5,000 employees take 35 days to remediate cloud issues.

RemediationCloud Security

Weak IAM controls affect 87% to 97% of accounts across AWS, Azure, and Google Cloud.

IAMCloud SecurityAWSAzureGoogle Cloud

75% of Google Cloud accounts are missing OS Login controls.

IAMGoogle Cloud

IAM weaknesses occur in 87% of SMEs, 95% of midmarket organizations, and 98% of large enterprises.

IAMSMEsMidmarketEnterprise

AWS leads in prevalence across five of the six misconfiguration categories.

Cloud SecurityAWSMisconfiguration

83% of AWS accounts have IAM policies that allow privilege escalation.

IAMAWSIAMPrivilege Escalation

Smaller organizations remediate cloud issues in 8 to 16 days.

Incident ResponseRemediationCloud Security

Azure's top three misconfigurations affect between 61% and 67% of Azure accounts.

Cloud StorageAzureMisconfigurations

Permissive firewalls affect 83% of AWS accounts, 45% of Azure accounts, and 34% of Google Cloud accounts.

Network SecurityFirewallAWSAzureGoogle Cloud

Organizations with 10,000+ employees remediate cloud issues in 10 days.

RemediationEnterpriseCloud Security

15% of organizations leave WordPress admin panels internet-facing.

Internet-facingWordPressExposure

Organizations with over 5,000 employees manage almost 35 times more external assets than small enterprises with 51–250 employees.

Asset ManagementEnterprise Security

8% of organizations leave phpMyAdmin internet-facing.

phpMyAdminInternet-facingExposure

8% of organizations expose UPnP on the public internet.

UPnPInternet-facingNetwork Security

9% of organizations expose SNMP on the public internet.

SNMPInternet-facingNetwork Security

49% of organizations expose risky ports and services.

Network SecurityPorts and Services

Retail firms average 10 days to remediate exposures.

RetailRemediationVulnerability Management

Small organizations remediate vulnerabilities fastest, averaging 14–18 days to fix exposures.

Vulnerability ManagementRemediation

Organizations in the 5,000–10,000 employee range average 56 days to remediate exposures.

Vulnerability ManagementEnterprise Security

Banks remediate exposures in 11 days on average.

BankingRemediationVulnerability Management

The insurance sector requires nearly 50 days to remediate exposures.

InsuranceRemediationVulnerability Management

Financial service organizations outside of banking require 24 days to remediate exposures.

Financial ServicesRemediationVulnerability Management

Automotive and pharmaceutical sectors average 43 days to remediate exposures.

AutomotivePharmaceuticalVulnerability ManagementRemediation

Organizations with over 5,000 employees manage more than twice as many external assets as organizations with 1,000–5,000 employees.

Asset ManagementEnterprise Security

46% of midmarket organizations say enterprise platforms assume more staff, budget, or complexity than they can support.

MidmarketEnterprise Platforms

The dominant investment priorities for midmarket organizations are AI and automation (49%) and adding new solutions (33%).

MidmarketBudgetInvestmentAIAutomation

91% of midmarket security leaders say their digital estate grew over the past 24 months.

MidmarketDigital Estate

86% of SaaS midmarket organizations kept headcount at pace with their digital estate, with only 10% growing more slowly.

MidmarketSaaSHeadcountDigital Estate

Only 9% of midmarket organizations discuss cyber risk at board level.

MidmarketBoard

Around 70% of midmarket security leaders say headcount has kept pace with their digital estate.

MidmarketHeadcountDigital Estate

29% of midmarket organizations say SME tools no longer meet their needs.

MidmarketSME Tools

41% of respondents report using AI pentesting, and it appears in the top five most-adopted tools for fintech, manufacturing, and retail.

MidmarketAI Pen TestingFintechManufacturingRetail

89% of midmarket security leaders report increasing budgets.

MidmarketBudget

64% of midmarket security leaders feel their posture scaled appropriately with growth.

MidmarketSecurity Posture

Only 51% of healthcare midmarket organizations kept headcount at pace with their digital estate, and 26% grew more slowly.

MidmarketHeadcountDigital EstateHealthcare

94% of midmarket security leaders are confident in their ability to identify and remediate critical risks before attackers exploit them.

MidmarketRisk Identification and RemediationCritical Risks

Only 30% of midmarket organizations grew headcount faster than their digital estate.

MidmarketHeadcountDigital Estate

36% of midmarket respondents acknowledge their security posture hasn't scaled appropriately with digital estate growth.

MidmarketSecurity Posture

44% of midmarket organizations have either outgrown their stack or stitched it together from point solutions that don't provide a unified view.

MidmarketStackPoint SolutionsVisibility