Palo Alto Networks
Reports
All Statistics
Across more than 750 major cyber incidents investigated in 2025, Unit 42® found that 87% required evidence from two or more distinct sources to establish what happened.
85% of organizations agree that fragmented identity systems and tools impact or delay their ability to detect and respond to identity-related threats.
86% agree that they will need external help to become quantum ready.
82.8% of adversary activity occurs during an extended precursor phase, long before operational impact is realized, with an average dwell time of 185 days .
There's been a 332% increase in unique internet-exposed OT devices and services, with nearly 20 million OT-related devices now observable on the public internet .
The highest concentrations of exposed OT devices was in the United States, China, and Germany.
53% of organizations identified lenient identity and access management practices as a top challenge.
97% of organizations prioritize consolidating their cloud security footprint due to tool sprawl.
30% of teams take more than a full day to resolve an incident due to disjointed workflows between cloud and SOC teams.
42% of the human workforce has direct access to organizational data.
97% of respondents reporting that tool fragmentation adds additional time to identity-related incidents, amounting to an average of 12 hours per incident.
99% of respondents say their organization already uses AI agents.
On average, 40% of AI agents and 40% of machine identities already have access to organizational data.
On average, only 39% of privileged access is managed through a just-in-time (JIT) or zero standing privilege (ZSP) model.
84% of respondents believe their organization could at least moderately improve awareness of the permissions and access granted to connectors and service accounts.
56% of organizations report that they can’t effectively enforce continuous least privilege for service accounts across cloud, SaaS, and on-premises environments.
64% of organizations still report they are not yet prepared to defend against quantum-enabled threats.
90% of respondents agree that AI agents should operate under least privilege principles, with bounded access and tighter controls.
Among C-suite respondents, 54% believe their organization is completely effective at continuously enforcing least privilege, while 61% of the practitioners doing the work disagree.
Across multiple identity-related breach categories, 90% of organizations report a successful identity-related breach in the last 12 months, with 83% seeing it happen at least twice, and 76% experiencing it three or more times.
91% believe they can rapidly contain compromised AI agents.
96% of respondents report that human identities operate with access far beyond what is required for their roles.
71% of organizations don’t fully automate certificate renewal and monitoring across all environments.
Over the next 12 months, organizations expect AI agents to increase by 85% and machine identities to increase by 77%, compared to the 56% growth in human identities.
The most populous OT application fingerprint we observed on the internet were Tridium Niagara, Linear eMerge, and Saia PCD Web Server.
89% of organizations believe that cloud and application security must be fully integrated with the SOC.
API attacks increased by 41% due to the rise of agentic AI relying heavily on APIs.
28% of organizations reported unrestricted network access between cloud workloads as a growing threat.
99% of organizations experienced at least one attack on their AI systems in the past year.