Report by Cobalt
State of Pentesting Report 2025
Key Findings
Larger organisations take over a month longer (61 days) than smaller ones (27 days) to resolve serious findings in pentests.
94% of security leaders agree that pentesting is foundational to security.
69% of the highest-risk (serious) vulnerabilities are resolved.
Median time to resolve issues of all criticalities stretches to 67 days.
81% of organisations believe their security posture is strong.
Financial companies have a lower rate of serious findings (11%) in pentests.
Less than half (48%) of vulnerabilities are remediated.
46% of companies commit to fix critical vulnerabilities within just three days.
98% of organisations are incorporating generative AI technologies into their products.
Large organisations resolve only 60% of serious pentest findings.
LLM pentests yield the highest proportion of serious vulnerabilities (32%) than any other asset type tested.
Since 2017, the median time to resolve serious vulnerabilities has decreased dramatically—from 112 days down to 37 days last year.
Most companies set ambitious service-level agreements (SLA) requiring vulnerabilities to be fixed within 14 days.
The rate for serious findings in pentests being resolved in each calendar year remains stuck at just 55%.
15% of organisations resolve 10% or less of their serious findings in pentests.
Only 66% of organisations are conducting regular security assessments like pentesting on their AI products.
Only 21% of serious vulnerabilities discovered in LLM tests are being resolved.
This represents a cut of 75 days, or two-thirds.
The proportion of serious findings in pentests has also declined by about half (from 20% to 11%) over 10 years.
Small companies lead with 81% of serious findings in pentests resolved.
57% of organisations resolve at least 90% of their serious findings in pentests.
AI and LLM security has emerged as the top concern among security professionals (72%).