UpGuard
Reports
All Statistics
97.4% of institutions have at least one Microsoft product.
28% of the top 100 vendors most commonly used by universities have experienced a data breach since 2024.
11% of the top 100 vendors most commonly used by universities currently show evidence of active infostealer malware infections.
95% of universities have at least one vendor with embedded AI exposure.
Around 50% of universities have detectable third-party AI embedded in their services.
80% of higher education institutions share the same 11 vendors.
67% of suppliers are used by five or fewer higher education institutions.
79% of organizations are notified of a threat by external third parties such as researchers, customers, or attackers before their own internal detection.
For 25% of organizations, manual triage requires 214 hours per week, equivalent to 5.3 full-time employees.
The median security team spends 20 minutes dismissing a single junk alert.
Organizations that use more than five disconnected security tools are twice as likely to miss critical threats compared to organizations with an integrated toolset.
43% of a security team's investigation time is consumed by manual context gathering.
In MCP registries, for every server provided by a verified technology vendor there are up to 15 lookalike servers from untrusted sources.
One in five developers grant AI code agents unrestricted access to perform high-risk actions without human oversight.
One in five developers grant AI agents permission for unrestricted file deletion, risking recursive wiping of a project or system.
14.5% of AI agent configuration files grant arbitrary code execution permissions for Python.
14.4% of AI agent configuration files grant arbitrary code execution permissions for Node.js.
Almost 20% of developers let AI automatically save changes to the project's main code repository without human review.