Palo Alto Networks
Reports
All Statistics
Across more than 750 major cyber incidents investigated in 2025, Unit 42® found that 87% required evidence from two or more distinct sources to establish what happened.
85% of organizations agree that fragmented identity systems and tools impact or delay their ability to detect and respond to identity-related threats.
86% agree that they will need external help to become quantum ready.
42% of the human workforce has direct access to organizational data.
97% of respondents reporting that tool fragmentation adds additional time to identity-related incidents, amounting to an average of 12 hours per incident.
99% of respondents say their organization already uses AI agents.
On average, 40% of AI agents and 40% of machine identities already have access to organizational data.
On average, only 39% of privileged access is managed through a just-in-time (JIT) or zero standing privilege (ZSP) model.
84% of respondents believe their organization could at least moderately improve awareness of the permissions and access granted to connectors and service accounts.
56% of organizations report that they can’t effectively enforce continuous least privilege for service accounts across cloud, SaaS, and on-premises environments.
64% of organizations still report they are not yet prepared to defend against quantum-enabled threats.
90% of respondents agree that AI agents should operate under least privilege principles, with bounded access and tighter controls.
Among C-suite respondents, 54% believe their organization is completely effective at continuously enforcing least privilege, while 61% of the practitioners doing the work disagree.
Across multiple identity-related breach categories, 90% of organizations report a successful identity-related breach in the last 12 months, with 83% seeing it happen at least twice, and 76% experiencing it three or more times.
91% believe they can rapidly contain compromised AI agents.
96% of respondents report that human identities operate with access far beyond what is required for their roles.
71% of organizations don’t fully automate certificate renewal and monitoring across all environments.
Over the next 12 months, organizations expect AI agents to increase by 85% and machine identities to increase by 77%, compared to the 56% growth in human identities.
82.8% of adversary activity occurs during an extended precursor phase, long before operational impact is realized, with an average dwell time of 185 days .
There's been a 332% increase in unique internet-exposed OT devices and services, with nearly 20 million OT-related devices now observable on the public internet .
The highest concentrations of exposed OT devices was in the United States, China, and Germany.
The most populous OT application fingerprint we observed on the internet were Tridium Niagara, Linear eMerge, and Saia PCD Web Server.
53% of organizations identified lenient identity and access management practices as a top challenge.
97% of organizations prioritize consolidating their cloud security footprint due to tool sprawl.
30% of teams take more than a full day to resolve an incident due to disjointed workflows between cloud and SOC teams.
89% of organizations believe that cloud and application security must be fully integrated with the SOC.
API attacks increased by 41% due to the rise of agentic AI relying heavily on APIs.
28% of organizations reported unrestricted network access between cloud workloads as a growing threat.
99% of organizations experienced at least one attack on their AI systems in the past year.