Report by Bitsight

State of Cyber Risk and Exposure 2025

15 FINDINGSPublished Jul 29, 2025
View Original Report →

Key Findings

Rapidly expanding attack surfaces are cited by 38% of cybersecurity and cyber risk leaders as a reason for increased difficulty in managing cyber risk today vs five years ago.

BitsightState of Cyber Risk and Exposure 2025·Jul 29, 2025
Cyber riskRisk managementAttack surface

Just 28% of organisations say they are "very effective" at communicating cyber risk to leadership.

BitsightState of Cyber Risk and Exposure 2025·Jul 29, 2025
Cyber riskRisk managementCommunication

Cybersecurity and cyber risk leaders at organizations without full threat visibility have a burnout rate of 63%.

BitsightState of Cyber Risk and Exposure 2025·Jul 29, 2025
Cyber riskRisk managementBurnout

Organisations with strong asset visibility are 2.5 times more likely to communicate cyber risk effectively to the board

BitsightState of Cyber Risk and Exposure 2025·Jul 29, 2025
Cyber riskRisk managementAsset visibilityCommunication

Nearly all organisations (99%) assess vendor risk.

BitsightState of Cyber Risk and Exposure 2025·Jul 29, 2025
Cyber riskRisk managementVendor risk

Just 17% of organisations have tools to regularly map threats and contextualise them for full visibility.

BitsightState of Cyber Risk and Exposure 2025·Jul 29, 2025
Cyber riskRisk managementToolsThreat mapping

Cybersecurity and cyber risk leaders at organizations with full threat visibility experience a significantly lower burnout rate of 44%.

BitsightState of Cyber Risk and Exposure 2025·Jul 29, 2025
Cyber riskRisk managementBurnout

Only 17% of organisations have the capability for continuous monitoring, despite it being a top priority.

BitsightState of Cyber Risk and Exposure 2025·Jul 29, 2025
Cyber riskRisk managementContinuous monitoring

Only a third of organisations monitor third-party relationships over time.

BitsightState of Cyber Risk and Exposure 2025·Jul 29, 2025
Cyber riskRisk managementThird-party

The percentage of breaches tied to third parties doubled from the previous year.

BitsightState of Cyber Risk and Exposure 2025·Jul 29, 2025
Cyber riskRisk managementThird-partyData breach

90% of surveyed cybersecurity and cyber risk leaders find managing cyber risks harder today than five years ago.

BitsightState of Cyber Risk and Exposure 2025·Jul 29, 2025
Cyber riskRisk management

The explosion of AI is cited by 39% of cybersecurity and cyber risk leaders as a reason for increased difficulty in managing cyber risks today vs five years ago.

BitsightState of Cyber Risk and Exposure 2025·Jul 29, 2025
Cyber riskRisk managementAI

1 in 5 organisations still admit their cyber practices are "immature".

BitsightState of Cyber Risk and Exposure 2025·Jul 29, 2025
Cyber riskRisk managementMaturity

Just 29% of organisations have a formal cyber program that is truly aligned with business objectives.

BitsightState of Cyber Risk and Exposure 2025·Jul 29, 2025
Cyber riskRisk management

47% of cybersecurity and cyber risk professionals report exhaustion (burnout).

BitsightState of Cyber Risk and Exposure 2025·Jul 29, 2025
Cyber riskRisk managementBurnout