Report by CompTIA

State of Cybersecurity 2025

155 FINDINGSPublished Oct 14, 2025
View Original Report →

Key Findings

46% of very large companies (10000+ employees) are concerned with the scale of attacks.

Cyber attacksEnterprise

The feeling that the current approach is 'good enough' is the second-greatest challenge in improving the execution of a strong cybersecurity strategy for business leaders.

Cybersecurity strategy

37% of organizations say their AI priority within cybersecurity is improving internal efforts.

AI

48% of companies are considering certifying current employees for skill improvement.

SkillsCertifications

43% of small companies (<100 employees) are concerned with the emergence of generative AI.

AIGenAI

37% of companies have average capability in securing data in cloud providers.

DataCloud

45% of elements involved in risk analysis are related to use of cloud computing.

Risk analysisRisk managementCloudCloud computing

46% of companies are considering expanding the use of third parties for skill improvement.

SkillsThird-partyMSP

38% of elements involved in risk analysis are related to data ownership.

Risk analysisRisk managementData ownership

50% of respondents surveyed have expert-level skill in network/infrastructure security.

Network securityInfrastructure securitySkillsSkills level

47% of respondents surveyed have expert-level skill in application security.

Application securitySkillsSkills level

38% of large companies (500-9999 employees) are concerned with compliance with regulations.

ComplianceRegulations

46% of respondents surveyed need significant skill improvement in network/infrastructure security.

Network securityInfrastructure securitySkillsSkills level

38% of companies have average capability in creating comprehensive data sets.

Data

57% of companies have high capability in creating comprehensive data sets.

Data

47% of respondents surveyed have expert-level skill in data analysis.

Data analysisSkillsSkills level

36% of firms say they now have a moderate focus on OT.

OT

16% of risks identified through analysis are viewed as organizational concerns.

Risk analysisRisk managementOrganizational concerns

41% of companies are improving board of directors visibility to improve the effectiveness of their cybersecurity program.

Cybersecurity program

6% of companies have below average capability in mining data.

Data

31% of organizations say their AI priority within cybersecurity is prioritizing defending new threats.

AI

36% of organizations surveyed believe that networking protocols used by OT systems must be understood better to properly secure OT.

OTOT security challenges

38% of organizations surveyed believe that total costs of digitizing physical infrastructure must be understood better to properly secure OT.

OTOT security challenges

33% of organizations reported a lack of buy-in from senior leadership in using AI for cybersecurity.

AIAI blocker

44% of elements involved in risk analysis are related to operational technology (OT).

Risk analysisRisk managementOT

Nearly three in four companies report that the impact of cyber incidents in the past year has been severe or moderate.

Cyber incidentCyber attackCyber attack consequences

46% of companies place a higher priority on incident response.

Incident response

58% of firms say they have a high focus on OT.

OT

37% of companies have average capability in securing data on endpoints.

DataEndpoints

70% of firms place themselves in an early education phase or a stage of testing AI implementation on low-priority systems.

AIAI adoption

52% of companies rate themselves as having high capability in AI.

AI

38% of organizations surveyed believe that implementing access control, including remote access, must be understood better to properly secure OT.

OTOT security challenges

58% of companies have high capability in securing data in cloud providers.

DataCloud

59% of companies have high capability in securing data on endpoints.

DataEndpoints

59% of companies have high capability in securing data on networks.

DataNetworks

42% of companies have average capability in mining data.

Data

40% of companies have average capability in capturing data from all sources.

Data

Three of the top seven elements involved in incident response involve some sort of purchase.

Incident response

42% of companies are improving senior executive visibility to improve the effectiveness of their cybersecurity program.

Cybersecurity program

46% of companies face integrating with business initiatives as a challenge in retaining cybersecurity talent.

Talent

43% of organizations are in the early education/experiment phase of AI adoption.

AIAI adoption

70% of companies are in early stages of AI adoption.

AI

52% of companies have high capability in mining data.

Data

There are 514,000 U.S.-based job openings with cybersecurity-related skills.

SkillsStaff

49% of large companies (500-9999 employees) are concerned with privacy.

PrivacyLarge company

46% of small companies (<100 employees) are concerned with privacy.

PrivacySmall company

41% of medium companies (100-499 employees) are concerned with privacy.

PrivacyMedium company

47% of very large companies (10000+ employees) are concerned with privacy.

PrivacyEnterprise

41% of small companies (<100 employees) are concerned with their reliance on data.

DataSmall company

43% of medium companies (100-499 employees) are concerned with their reliance on data.

DataMedium company

45% of large companies (500-9999 employees) are concerned with their reliance on data.

DataLarge company

55% of very large companies (10000+ employees) are concerned with their reliance on data.

DataEnterprise

46% of small companies (<100 employees) are concerned with the scale of attacks.

Cyber attacksSmall company

36% of medium companies (100-499 employees) are concerned with the scale of attacks.

Cyber attacksMedium company

49% of respondents surveyed need significant skill improvement in data security.

Data securitySkillsSkills level

43% of large companies (500-9999 employees) are concerned with the scale of attacks.

Cyber attacksLarge company

36% of large companies (500-9999 employees) are concerned with the breadth of skills needed.

SkillsLarge company

37% of very large companies (10000+ employees) are concerned with the breadth of skills needed.

SkillsEnterprise

35% of medium companies (100-499 employees) are concerned with compliance with regulations.

ComplianceRegulations

38% of organizations reported uncertainty around AI efficiency as a challenge in using AI for cybersecurity.

AIAI blocker

43% of organizations reported skill gaps in basic cybersecurity topics as a challenge in using AI for cybersecurity.

AIAI blocker

45% of organizations reported skill gaps in using AI tools as a challenge in using AI for cybersecurity.

AI AI blocker

45% of firms believe existing IT workers need OT training.

OTOT training

34% of firms believe there is insufficient OT budget.

OTBudgetOT budget

37% of firms believe OT cybersecurity has been overlooked.

OTOT cybersecurity

33% of organizations surveyed believe that incorporating OT into network maps/architecture must be understood better to properly secure OT.

OTOT security challenges

30% of organizations surveyed believe that patching strategy for OT devices must be understood better to properly secure OT.

OTPatching

43% of organizations surveyed believe that risk assessment for OT systems must be understood better to properly secure OT.

OT OT security challenges

5% of companies have below average capability in securing data on networks.

Data Networks

66% of companies have dedicated employees for data security.

Data securityStaff

60% of companies have dedicated employees for database administration.

Database administration

58% of companies have dedicated employees for data analytics.

Data analytics

41% of respondents surveyed have expert-level skill in knowledge of threat landscape.

Threat landscapeSkillsSkills level

40% of respondents surveyed have expert-level skill in regulatory landscape.

Regulatory SkillsSkills level

46% of respondents surveyed have expert-level skill in access control and identity management.

Access controlIdentity managementSkillsSkills level

42% of respondents surveyed have expert-level skill in automation and AI.

AutomationAISkillsSkills level

44% of respondents surveyed need significant skill improvement in access control and identity management.

Access controlIdentity managementSkillsSkills level

43% of respondents surveyed need significant skill improvement in application security.

Application securitySkillsSkills level

43% of respondents surveyed need significant skill improvement in data analysis.

Data analysisSkillsSkills level

96% of respondents indicated that Identity management requires significant or moderate improvement.

Identity management

42% of companies are considering exploring new uses of third parties for skill improvement.

SkillsThird-partyMSP

96% of respondents indicated that Application security requires significant or moderate improvement.

Application security

95% of respondents indicated that Automation/AI requires significant or moderate improvement.

AutomationAI

94% of respondents indicated that Knowledge of the threat landscape requires significant or moderate improvement.

Threat landscape

44% of companies are developing new or better cybersecurity policies to improve the effectiveness of their cybersecurity program.

Cybersecurity programPolicies

45% of companies are implementing a dedicated reporting structure to improve the effectiveness of their cybersecurity program.

Cybersecurity program

35% of companies face burnout/mental health issues as a challenge in retaining cybersecurity talent.

TalentBurnoutMental health

42% of companies face defining career pathways as a challenge in retaining cybersecurity talent.

Talent

44% of companies face salary/paying market wages as a challenge in retaining cybersecurity talent.

Talent

46% of companies face finding ways to enable skill building as a challenge in retaining cybersecurity talent.

Talent

47% of companies face ensuring tools/support availability as a challenge in retaining cybersecurity talent.

Talent

31% of small companies (<100 employees) are concerned with compliance with regulations.

ComplianceRegulations

42% of respondents surveyed have expert-level skill in endpoint security.

Endpoint securitySkillsSkills level

42% of companies have a higher awareness of regulatory issues.

Regulatory

94% of companies have a high or moderate focus on operational technology.

OT

73% of companies rate the impact of cybersecurity incidents as severe or moderate.

Cybersecurity incident

36% of companies have average capability in securing data on networks.

DataNetworks

5% of companies have below average capability in manipulating data.

Data

4% of companies have below average capability in capturing data from all sources.

Data

5% of companies have below average capability in finding patterns within data.

Data

6% of companies have below average capability in creating comprehensive data sets.

Data

4% of companies have below average capability in securing data on endpoints.

DataEndpoints

51% of respondents surveyed have expert-level skill in data security.

Data securitySkillsSkills level

42% of respondents surveyed need significant skill improvement in regulatory landscape.

RegulatorySkillsSkills level

4% of companies have below average capability in securing data in cloud providers.

DataCloud

44% of respondents surveyed need significant skill improvement in knowledge of threat landscape.

Threat landscapeSkillsSkills level

56% of companies surveyed say that they are using a formal risk management framework.

Risk managementRisk management framework

41% of respondents surveyed need significant skill improvement in endpoint security.

Endpoint securitySkillsSkills level

50% of respondents surveyed need significant skill improvement in automation and AI.

AutomationAISkillsSkills level

97% of respondents indicated that Network/infrastructure security requires significant or moderate improvement.

Network securityInfrastructure security

95% of respondents indicated that the Regulatory landscape requires significant or moderate improvement.

Regulatory

95% of respondents indicated that Endpoint security requires significant or moderate improvement.

Endpoint security

95% of respondents indicated that Data analysis requires significant or moderate improvement.

Data analysis

40% of companies are implementing dedicated cybersecurity roles to improve the effectiveness of their cybersecurity program.

StaffCybersecurity program

45% of medium companies (100-499 employees) are concerned with the emergence of generative AI.

AIGenAI

47% of large companies (500-9999 employees) are concerned with the emergence of generative AI.

AIGenAI

52% of very large companies (10000+ employees) are concerned with the emergence of generative AI.

AIGenAI

48% of small companies (<100 employees) are concerned with the variety of attacks.

Cyber attacksSmall company

46% of large companies (500-9999 employees) are concerned with the variety of attacks.

Cyber attacksLarge company

49% of very large companies (10000+ employees) are concerned with the variety of attacks.

Cyber attacksEnterprise

42% of medium companies (100-499 employees) are concerned with the variety of attacks.

Cyber attacksMedium company

34% of small companies (<100 employees) are concerned with nation-state actors.

Cyber attacksSmall company

30% of medium companies (100-499 employees) are concerned with nation-state actors.

Nation-stateMedium company

40% of large companies (500-9999 employees) are concerned with nation-state actors.

Nation-stateLarge company

42% of very large companies (10000+ employees) are concerned with nation-state actors.

Nation-stateEnterprise

34% of companies are exploring cybersecurity insurance.

Insurance

37% of organizations reported a lack of cybersecurity metrics as a challenge in using AI for cybersecurity.

AIAI blocker

35% of small companies (<100 employees) are concerned with the breadth of skills needed.

SkillsSmall company

34% of medium companies (100-499 employees) are concerned with the breadth of skills needed.

SkillsMedium company

38% of very large companies (10000+ employees) are concerned with compliance with regulations.

ComplianceRegulations

35% of companies are building dedicated cyber resources.

Cyber resources

35% of companies are exploring emerging cyber trends more.

Trends

38% of companies are focusing more on employee cyber education.

EducationTraining

42% of companies are making greater investment in technology tools.

Tools

42% of companies are focusing more on risk management.

Risk management

27% of organizations are implementing AI in low-priority systems.

AIAI adoption

9% of organizations have full integration of AI with modified workflow.

AIAI adoption

20% of organizations are implementing AI in high-priority systems.

AIAI adoption

35% of organizations reported a lack of AI policy as a challenge in using AI for cybersecurity.

AIAI blocker

36% of organizations reported a lack of appropriate data sets as a challenge in using AI for cybersecurity.

AIAI blocker

41% of organizations surveyed believe that different security priorities for OT vs. IT must be understood better to properly secure OT.

OTOT security challenges

44% of organizations surveyed believe that types of threats that can impact OT must be understood better to properly secure OT.

OTOT security challenges

56% of companies have high capability in capturing data from all sources.

Data

56% of companies have high capability in finding patterns within data.

Data

39% of companies have average capability in finding patterns within data.

Data

One third of companies surveyed say that risks are assessed informally.

Risk managementRisk management frameworkRisk analysis

49% of risks identified through analysis are viewed as cybersecurity concerns.

Risk analysisRisk managementCybersecurity concerns

34% of risks identified through analysis are viewed as technology concerns.

Risk analysisRisk managementTechnology concerns

45% of elements involved in risk analysis are related to technology procurement.

Risk analysisRisk managementTechnology procurement

39% of elements involved in risk analysis are related to data classification.

Risk analysisRisk managementData classification

97% of respondents indicated that Data security requires significant or moderate improvement.

Data security

56% of companies are considering new hiring for skill improvement.

SkillsHiring

41% of companies are implementing better metrics for cybersecurity to improve the effectiveness of their cybersecurity program.

Cybersecurity program

54% of companies are considering training current employees for skill improvement.

SkillsTraining

41% of companies are establishing better connection with business units to improve the effectiveness of their cybersecurity program.

Cybersecurity program