Report by Bitsight

State of Cyber Risk and Exposure 2025

15 FINDINGSPublished Jul 29, 2025
View Original Report →

Key Findings

Rapidly expanding attack surfaces are cited by 38% of cybersecurity and cyber risk leaders as a reason for increased difficulty in managing cyber risk today vs five years ago.

Cyber riskRisk managementAttack surface

Just 28% of organisations say they are "very effective" at communicating cyber risk to leadership.

Cyber riskRisk managementCommunication

Cybersecurity and cyber risk leaders at organizations without full threat visibility have a burnout rate of 63%.

Cyber riskRisk managementBurnout

Organisations with strong asset visibility are 2.5 times more likely to communicate cyber risk effectively to the board

Cyber riskRisk managementAsset visibilityCommunication

Nearly all organisations (99%) assess vendor risk.

Cyber riskRisk managementVendor risk

Just 17% of organisations have tools to regularly map threats and contextualise them for full visibility.

Cyber riskRisk managementToolsThreat mapping

Cybersecurity and cyber risk leaders at organizations with full threat visibility experience a significantly lower burnout rate of 44%.

Cyber riskRisk managementBurnout

Only 17% of organisations have the capability for continuous monitoring, despite it being a top priority.

Cyber riskRisk managementContinuous monitoring

Only a third of organisations monitor third-party relationships over time.

Cyber riskRisk managementThird-party

The percentage of breaches tied to third parties doubled from the previous year.

Cyber riskRisk managementThird-partyData breach

90% of surveyed cybersecurity and cyber risk leaders find managing cyber risks harder today than five years ago.

Cyber riskRisk management

The explosion of AI is cited by 39% of cybersecurity and cyber risk leaders as a reason for increased difficulty in managing cyber risks today vs five years ago.

Cyber riskRisk managementAI

1 in 5 organisations still admit their cyber practices are "immature".

Cyber riskRisk managementMaturity

Just 29% of organisations have a formal cyber program that is truly aligned with business objectives.

Cyber riskRisk management

47% of cybersecurity and cyber risk professionals report exhaustion (burnout).

Cyber riskRisk managementBurnout