LevelBlue
Reports
All Statistics
Only 25% of retailers reported being prepared for AI-powered threats, despite 45% expecting such threats to occur.
60% of retail executives indicated that their cybersecurity team is integrated with lines of business.
47% of retail executives reported having very low to moderate visibility into their software supply chain.
Globally, Europe is the most prepared region for AI-driven attacks with 66% saying they are prepared.
Just 32% of organizations have enlisted training and awareness experts to help educate their workforce on social engineering attacks over the past 12 months.
56% of organizations noted preparedness for business email compromise.
The number of cybersecurity incidents observed between January 1 and May 31 2025 nearly tripled.
The average breakout time for attackers (how quickly they move laterally after initial access) is under 60 minutes, and in some cases, less than 15 minutes.
Fake CAPTCHA social engineering attacks, particularly ClickFix campaigns, jumped 1,450% from the second half of 2024 to the first half of 2025.
80% of organizations with low visibility of their software supply chain view critical factors like custom code, commercial off-the-shelf software, and API integrations as "very risky" or "somewhat risky".
About half (49%) of companies say they lack the visibility to fully understand – or even identify – software supply chain risks.
Despite high investment in enhanced software supply chain security, Europe ranks lowest at 23% in prioritizing engaging with software suppliers about security credentials
61% of healthcare organizations are now aligning their cybersecurity teams with lines of business.
Nearly half (43%) of healthcare executives say they allocate cybersecurity budgets at the outset of new initiatives.
24% of healthcare executives say they are likely to invest in machine learning for pattern matching.
Nearly half (43%) of executives within cyber resilient organizations report they are increasing boardroom engagement in resilience-related discussions.
53% of cyber resilient organizations are committing significant investment to advanced threat detection.
Nearly half (42%) of executives believe AI-powered threats will happen.
67% of retail executives who reported high-profile breaches indicated that cybersecurity has become a higher priority on the C-suite agenda in 2025.
44% of retailers reported experiencing a significantly higher volume of attacks in 2025.
66% of retailers plan to invest significantly in application security to prepare for evolving threats.
65% of retailers intend to invest significantly in cyber-resilience processes across their business.
63% of retailers aim to invest significantly in machine learning for pattern matching to enhance cybersecurity.
63% of retailers plan to invest significantly in generative AI for social engineering attacks.
34% of retailers stated that their organization has suffered a breach in the past 12 months.
38% of organizations admit to being underprepared for AI-driven social engineering threats such as automated attacks, deepfake-based videos, and voice scams.
44% of organizations believe an AI-powered attack is likely to occur within the next 12 months.
Only 29% of organizations are prepared for an AI-powered attack.
Just 20% of organizations describe themselves as highly effective in defending against cyber adversaries using AI techniques.
44% of organizations are prepared for insider threats or account takeover.
57% of organizations are prepared for personal information exfiltration.
43% of organizations are prepared for smishing.
41% of organizations are prepared for quishing.
51% of organizations are prepared for phishing.
32% of organizations reported being prepared for deepfake and synthetic identity attacks.
Only 20% of organizations feel confident they are implementing a strategy to educate their workforce.
Only 13% of organizations are investing significantly in Zero Trust Architecture (ZTA).
Organizations are likely to make significant investments in generative AI to defend against social engineering attacks (31%).
41% of organizations report a significantly higher volume of cyberattacks compared to 12 months ago.
Organizations are most likely to make significant investments in cyber resilience processes across the business (33%).
59% of organizations report an increasing difficulty for employees to discern real from not real.
Approximately one-quarter (24%) of organizations say they are highly effective at implementing and using AI to enhance cybersecurity.
Social engineering attacks accounted for 39% of initial access incidents observed during the first half of 2025.
Non-Business Email Compromise (BEC) incidents rose by 214%.
In Latin America, 50% say they are prepared for software supply chain attacks.
39% of CEOs say AI adoption presents a greater risk to the software supply chain.
40% of CEOs believe that the biggest security risk the organization faces today is from the software supply chain, compared with 29% of CIOs and 27% of CTOs.
57% of North American organizations say they are prepared for software supply chain attacks.
In North America, the top three risks for organizations are third-party software distribution channels (49%), third-party risk management (48%), and unsupported software (48%).
67% of European organizations are investing in enhanced software supply chain security, which is the highest of all regions.