UpGuard
Reports
All Statistics
97.4% of institutions have at least one Microsoft product.
28% of the top 100 vendors most commonly used by universities have experienced a data breach since 2024.
11% of the top 100 vendors most commonly used by universities currently show evidence of active infostealer malware infections.
79% of organizations are notified of a threat by external third parties such as researchers, customers, or attackers before their own internal detection.
For 25% of organizations, manual triage requires 214 hours per week, equivalent to 5.3 full-time employees.
The median security team spends 20 minutes dismissing a single junk alert.
In MCP registries, for every server provided by a verified technology vendor there are up to 15 lookalike servers from untrusted sources.
One in five developers grant AI code agents unrestricted access to perform high-risk actions without human oversight.
One in five developers grant AI agents permission for unrestricted file deletion, risking recursive wiping of a project or system.
95% of universities have at least one vendor with embedded AI exposure.
Around 50% of universities have detectable third-party AI embedded in their services.
80% of higher education institutions share the same 11 vendors.
67% of suppliers are used by five or fewer higher education institutions.
Organizations that use more than five disconnected security tools are twice as likely to miss critical threats compared to organizations with an integrated toolset.
43% of a security team's investigation time is consumed by manual context gathering.
14.5% of AI agent configuration files grant arbitrary code execution permissions for Python.
14.4% of AI agent configuration files grant arbitrary code execution permissions for Node.js.
Almost 20% of developers let AI automatically save changes to the project's main code repository without human review.