Netwrix

43 stats2 reports

All Statistics

79% of healthcare organizations say their non-human identities are not fully governed.

Identity SecurityAI AgentsGovernanceHealthcare

86% of healthcare organizations lack full confidence that their Active Directory environments are free of privilege escalation risks.

Active DirectoryPrivilege EscalationIdentity SecurityHealthcare

Only 14% of healthcare organizations are fully confident in their Active Directory security, compared with 26% across all industries.

Active DirectoryHealthcareIdentity Security

29% of organizations reported that auditors now require proof of data security and privacy in AI-based systems.

Data SecurityAI Systems

20% of organizations reported that they have offloaded some IT/security workloads to AI.

AI WorkloadsIT Management

28% of organizations reported that cybersecurity AI tools improved their detection and response capabilities.

AI ToolsDetection and Response

77% of healthcare organizations cannot immediately determine who has access to a specific piece of sensitive data.

Data AccessVisibilityHealthcareIdentity SecurityAccess Management

48% of healthcare organizations say a compromised identity is the most common starting point for unauthorized access to sensitive data.

Compromised IdentityUnauthorized AccessHealthcareIdentity Security

61% of healthcare organizations say determining who has access to a specific piece of sensitive data takes hours and multiple tools.

Data AccessSecurity ToolsHealthcareAccess Management

75% of healthcare organizations say AI and automation have increased identity-related risk to sensitive data over the past two years.

AI RiskIdentity SecurityHealthcare

70% of healthcare organizations say their data access governance is behind the speed of AI adoption.

Data GovernanceAI AdoptionHealthcareIdentity Security

31% of healthcare organizations experienced unauthorized identities accessing sensitive data in the past year, compared with 24% in other industries.

HealthcareUnauthorized AccessIdentity Security

Among healthcare organizations that experience an identity-related incident, 33% incur costs above $250,000, compared with 21% in other industries.

HealthcareIncident CostData BreachIdentity Security

70% of organizations have no unified strategy connecting identity and data visibility.

Identity StrategyData Visibility

17% of organizations remain entirely unprepared for AI security.

AI SecurityAI ReadinessAI Governance

75% of sensitive data exposures begin with compromised identities or misconfigured permissions.

Data SecurityIdentity CompromiseMisconfigurationMisconfigured Permissions

45% of organizations are still developing AI governance programs.

AI GovernanceAI ReadinessAI Security

74% of organizations lack a unified view of sensitive data and the identities that can access it.

Data VisibilityIdentity Management

Only 11% of organizations report full AI security readiness.

AI SecurityAI ReadinessAI Governance

Among organizations where AI significantly expanded identities requiring access, breach rates reached 43% over the past twelve months. In contrast, where AI had not materially changed access patterns, breach rates were 11% over the past twelve months.

Data BreachIdentity ManagementAI

Only 11% of organizations have operationalized AI governance through continuous enforcement and monitoring.

AI GovernanceContinuous Monitoring

76% of organizations cannot immediately revoke standing access when it is no longer needed.

Access ManagementData Security

Only 19% of organizations fully govern non-human identities.

Identity GovernanceNon-Human Identities

Only 20% of organizations fully monitor employee use of shadow AI.

Shadow AIEmployee Monitoring

Only 23.5% of organizations can respond at the speed attackers move.

Incident Response

Organizations with 500 to 999 employees reported a 40.3% breach rate, the highest of any size segment.

Data Breach

In North America, 24% of breached organizations reported losses of at least $100,000 in the past year.

Financial LossData BreachNorth America

Nearly 63% of organizations require between one and three days to remediate identified risks.

RemediationIncident Response

76% of organizations do not fully govern or monitor non-human identities.

Identity ManagementNon-Human Identities

In North America, 12% of breached organizations reported losses above $250,000 in the past year.

Financial LossData BreachNorth America

37% of organizations reported that AI-driven attacks forced them to adjust their security approach over the past year.

AI AttacksSecurity Adjustments

The implementation of AI-based tools as a top-five IT priority surged by 189% from 9% in 2023 to 26% in 2025.

AI AdoptionIT Priorities

30% of businesses reported that they use AI and must now protect it like any other critical system.

AI SecurityData Protection

29% of IT and security professionals identified adopting AI-based solutions as one of their top three actions to strengthen cybersecurity.

AI SolutionsProfessional PrioritiesIT Priorities

51% of respondents confirmed experiencing a security incident that demanded a dedicated response from security teams in the past 12 months.

Security incidentSecurity teamIncident response

The number of organizations reporting no impact from security incidents is shrinking rapidly, from 45% in 2023 to just 36% in 2025.

Security incidentAttack consequences

29% of organizations struggle with compliance since auditors require proof of data security and privacy in AI-based systems.

AIComplianceData securityPrivacy

37% of respondents say that new AI-driven threats forced them to adjust their security approach.

AIAI-driven threats

60% of organizations are already using artificial intelligence (AI) in their IT infrastructure.

AIAI useIT infrastructure

30% of respondents report the emergence of a new attack surface due to the use of AI by their business users.

AIAI risks

75% of respondents reported financial damage due to attacks, which is a significant increase from 60% in 2024.

Attack consequencesFinancial damage

The number of organizations estimating their financial damage at $200,000 due to attacks or more nearly doubled, from 7% to 13%

Attack consequencesFinancial damage

30% of organizations are considering implementing AI.

AIAI adoption