Seemplicity
Reports
All Statistics
50% of security professionals spend more time on coordination than technical analysis at enterprises
31% of enterprises fully trust AI-sourced recommendations to influence prioritization decisions
59% of security and engineering teams still negotiate who is responsible for each fix at enterprises.
45% of U.S.-based cybersecurity leaders work 11 or more extra hours per week.
89% of U.S.-based cybersecurity leaders say their position now requires significant cross-functional collaboration and business alignment.
20% of U.S.-based cybersecurity leaders work an additional 16 or more hours weekly.
Fewer than 1 in 5 organizations use structured prioritization models.
30% cite budget limitations as their biggest barrier to adopting additional solutions.
Nearly 40% of organizations still rely on manual workflows for most of their vulnerability remediation processes.
Costs were an obstacle for 46% of respondents in effective use of AI.
Endpoint security was a current application of AI in 52% of security tech stacks
About 16% of security teams say their use of AI has been very beneficial and have made it a core part of their program
94% of cybersecurity and IT leaders at enterprises can translate security risks for non-technical stakeholders
88% of enterprises have integrated AI into their security stacks
43% of cybersecurity and IT leaders at enterprises admit their remediation processes are still ad hoc
64% of U.S.-based cybersecurity leaders report sufficient budget for AI.
94% of U.S.-based cybersecurity leaders would still choose cybersecurity as a career.
52% of U.S.-based cybersecurity leaders say training for human-AI collaboration is limited or insufficient.
44% of U.S.-based cybersecurity leaders say their role feels emotionally exhausting more often than rewarding.
73% of U.S.-based cybersecurity leaders say AI oversight and governance is the most important future capability.
68% of U.S.-based cybersecurity leaders rate technical expertise as the most important future capability.
85% of U.S.-based cybersecurity leaders feel pressure to strengthen communication and business skills because of AI.
82% of U.S.-based cybersecurity leaders say people skills are more central to cybersecurity leadership than five years ago.
85% of organizations believe their cross-team collaboration is strong.
1 in 5 organizations take four or more days to fix critical vulnerabilities.
91% of organizations experience delays in vulnerability remediation.
61% of organizations still measure success of vulnerability remediation by the number of vulnerabilities resolved.
86% of organizations are increasing their security spending in 2025.
49% measure success of vulnerability remediation by mean time to remediation.
54% measure success of vulnerability remediation by fewer breaches.
91% of organizations experience delays in vulnerability remediation.
Speed of threat detection was used to evaluate AI efficacy by 57% of respondents
Endpoint security (34%), antivirus/anti-malware (31%), and malware analysis (31%) were the security tech categories where AI is thought to be the most overhyped
The majority of organizations (55%) say that they’ve enabled AI in under half the tools in their environments that have it available
39% of firms are using AI to solve data overload problems that stymie vulnerability and exposure management work
Antivirus/anti-malware was a current application of AI in 40% of security tech stacks
Approximately 56% of respondents reported that at least half of their security vendors tout their AI capabilities
Security and privacy risks were a reason for turning off AI functionality, cited by 55%
Basic vulnerability scanning was a current application of AI in 47% of security tech stacks
46% of security teams primarily depend on AI that is embedded in their security tools and delivered by their vendors versus building their own
The top five vulnerability management problems they’re actively trying to solve with AI today were: false positives (49%), overload of data (39%), reliance on manual processes (33%), disparate results from scanning tools (31%), and false negatives (31%)
A lack of transparency and explainability was the top reason for turning off AI functionality, cited by 58%
Around 45% say that AI is moderately beneficial and they’re starting to note the benefits
21% say they apply AI to security through a mix of vendor-led and internal AI.
Sophisticated threat landscape was the most commonly cited security pain point, named by 60% of respondents
A scant 6% reported that AI is detrimental to their security program
Difficulty in tuning, training, and supervising AI was an obstacle to the effective use of AI for 39% of respondents
Incident response was the second security function where AI will provide the most value in the next 3 years, cited by 59% of respondents
The No. 1 security issue respondents are most hopeful that AI will help fix is the prioritization of disparate results from scanning tools, for which 82% are hopeful for gains
Just 6% of respondents say that they fully outsource their AI training