UpGuard

18 stats3 reports

All Statistics

97.4% of institutions have at least one Microsoft product.

Vendor ConcentrationMicrosoftHigher Education

28% of the top 100 vendors most commonly used by universities have experienced a data breach since 2024.

Data BreachThird-Party RiskHigher EducationThird-Party Supply Risk

11% of the top 100 vendors most commonly used by universities currently show evidence of active infostealer malware infections.

MalwareCredential TheftHigher EducationInfostealerThird-Party Supply Risk

79% of organizations are notified of a threat by external third parties such as researchers, customers, or attackers before their own internal detection.

UpGuardThe Context Gap·5mo ago
Threat DetectionThreat NotificationInternal Threat DetectionExternal Threat Detection

For 25% of organizations, manual triage requires 214 hours per week, equivalent to 5.3 full-time employees.

UpGuardThe Context Gap·5mo ago
Security OperationsManual TriageSOC

The median security team spends 20 minutes dismissing a single junk alert.

UpGuardThe Context Gap·5mo ago
Security OperationsAlert ManagementSecurity AlertSOC

In MCP registries, for every server provided by a verified technology vendor there are up to 15 lookalike servers from untrusted sources.

Supply ChainTyposquattingAI Code Agents

One in five developers grant AI code agents unrestricted access to perform high-risk actions without human oversight.

AI AgentsSoftware DevelopmentAccess ControlAI Code Agents

One in five developers grant AI agents permission for unrestricted file deletion, risking recursive wiping of a project or system.

Data SecurityAI AgentsSoftware DevelopmentAI Code Agents

95% of universities have at least one vendor with embedded AI exposure.

AI ExposureHigher EducationThird-Party RiskAI Exposure

Around 50% of universities have detectable third-party AI embedded in their services.

AI IntegrationHigher EducationThird-Party Risk

80% of higher education institutions share the same 11 vendors.

Vendor ConcentrationHigher EducationSupply Chain RiskThird-Party Risk

67% of suppliers are used by five or fewer higher education institutions.

Vendor DiversityHigher EducationThird-Party RiskThird-Party Supply Risk

Organizations that use more than five disconnected security tools are twice as likely to miss critical threats compared to organizations with an integrated toolset.

UpGuardThe Context Gap·5mo ago
Security ToolsThreat DetectionCritical ThreatsSOC

43% of a security team's investigation time is consumed by manual context gathering.

UpGuardThe Context Gap·5mo ago
Security OperationsManual Context GatheringThreat InvestigationSOC

14.5% of AI agent configuration files grant arbitrary code execution permissions for Python.

Application SecurityAI AgentsDeveloper ToolsAI Code Agents

14.4% of AI agent configuration files grant arbitrary code execution permissions for Node.js.

Application SecurityCybersecurityDeveloper ToolsNode.jsAI Agents

Almost 20% of developers let AI automatically save changes to the project's main code repository without human review.

Code IntegritySoftware DevelopmentApplication SecurityAI Code Agents