Netwrix
All Statistics
79% of healthcare organizations say their non-human identities are not fully governed.
86% of healthcare organizations lack full confidence that their Active Directory environments are free of privilege escalation risks.
Only 14% of healthcare organizations are fully confident in their Active Directory security, compared with 26% across all industries.
29% of organizations reported that auditors now require proof of data security and privacy in AI-based systems.
20% of organizations reported that they have offloaded some IT/security workloads to AI.
28% of organizations reported that cybersecurity AI tools improved their detection and response capabilities.
77% of healthcare organizations cannot immediately determine who has access to a specific piece of sensitive data.
48% of healthcare organizations say a compromised identity is the most common starting point for unauthorized access to sensitive data.
61% of healthcare organizations say determining who has access to a specific piece of sensitive data takes hours and multiple tools.
75% of healthcare organizations say AI and automation have increased identity-related risk to sensitive data over the past two years.
70% of healthcare organizations say their data access governance is behind the speed of AI adoption.
31% of healthcare organizations experienced unauthorized identities accessing sensitive data in the past year, compared with 24% in other industries.
Among healthcare organizations that experience an identity-related incident, 33% incur costs above $250,000, compared with 21% in other industries.
70% of organizations have no unified strategy connecting identity and data visibility.
17% of organizations remain entirely unprepared for AI security.
75% of sensitive data exposures begin with compromised identities or misconfigured permissions.
45% of organizations are still developing AI governance programs.
74% of organizations lack a unified view of sensitive data and the identities that can access it.
Only 11% of organizations report full AI security readiness.
Among organizations where AI significantly expanded identities requiring access, breach rates reached 43% over the past twelve months. In contrast, where AI had not materially changed access patterns, breach rates were 11% over the past twelve months.
Only 11% of organizations have operationalized AI governance through continuous enforcement and monitoring.
76% of organizations cannot immediately revoke standing access when it is no longer needed.
Only 19% of organizations fully govern non-human identities.
Only 20% of organizations fully monitor employee use of shadow AI.
Only 23.5% of organizations can respond at the speed attackers move.
Organizations with 500 to 999 employees reported a 40.3% breach rate, the highest of any size segment.
In North America, 24% of breached organizations reported losses of at least $100,000 in the past year.
Nearly 63% of organizations require between one and three days to remediate identified risks.
76% of organizations do not fully govern or monitor non-human identities.
In North America, 12% of breached organizations reported losses above $250,000 in the past year.
37% of organizations reported that AI-driven attacks forced them to adjust their security approach over the past year.
The implementation of AI-based tools as a top-five IT priority surged by 189% from 9% in 2023 to 26% in 2025.
30% of businesses reported that they use AI and must now protect it like any other critical system.
29% of IT and security professionals identified adopting AI-based solutions as one of their top three actions to strengthen cybersecurity.
51% of respondents confirmed experiencing a security incident that demanded a dedicated response from security teams in the past 12 months.
The number of organizations reporting no impact from security incidents is shrinking rapidly, from 45% in 2023 to just 36% in 2025.
29% of organizations struggle with compliance since auditors require proof of data security and privacy in AI-based systems.
37% of respondents say that new AI-driven threats forced them to adjust their security approach.
60% of organizations are already using artificial intelligence (AI) in their IT infrastructure.
30% of respondents report the emergence of a new attack surface due to the use of AI by their business users.
75% of respondents reported financial damage due to attacks, which is a significant increase from 60% in 2024.
The number of organizations estimating their financial damage at $200,000 due to attacks or more nearly doubled, from 7% to 13%
30% of organizations are considering implementing AI.