Report by Filigran
State of Threat Management 2026
Key Findings
61% of organizations say they cannot determine which vulnerabilities are most likely to be exploited in real-world attacks.
German security teams report spending just 27% of their time on low-priority or non-exploitable risks.
94% say a proactive cybersecurity posture in 2026 will depend on integrating threat intelligence with exposure management.
Only 41% of organizations have a fully consolidated view of cyber risk exposure.
Organizations deploy an average of 14 different threat intelligence feeds.
52% of North American organizations report having a fully consolidated view of cyber risk exposure.
Concern about disrupting systems (49%), excessive manual effort (46%), and poor integration with existing security processes (42%) are the top barriers to validating whether threats are exploitable.
Currently, 37% of exposure management processes are AI-driven and organizations expect this to reach 59% within two years.
56% say AI and automation would most help in understanding which threats are relevant to their specific environment.
93% agree that delaying improvements to how they manage cyber risk increases the likelihood of serious incidents.
EMEA organizations report 37% having a fully consolidated view of exposure and 35% using continuous, automated validation.
APAC organizations report 31% having a fully consolidated view of exposure and 27% using continuous, automated validation.
84% of security decision-makers and practitioners agree that cyberattacks exploit known risks that are not prioritized.
Security teams spend 42% of their time investigating risks that later prove low priority or non-exploitable.
Germany leads surveyed countries with 58% adoption of automated validation.
88% of security teams acknowledge that periodic assessments cannot keep pace with the speed of change in their environments.
95% of organizations agree greater automation would improve their confidence that teams are focused on the most important risks.
Three-quarters of organizations plan to invest in both cyber risk quantification tools and exposure assessment capabilities over the next 12–24 months.
58% of U.S. organizations report a fully established CTEM program.
51% of North American organizations use threat intelligence within a continuous, automated validation process.
Only 38% of organizations use threat intelligence within a continuous, fully automated validation process.
Organizations outside North America are roughly 20 percentage points behind North America on both consolidated cyber risk visibility and continuous automated validation.
88% of security teams agree that without greater automation, they cannot keep up with the volume of risks they must assess.
59% say AI and automation would most help detect vulnerabilities, misconfigurations, and exposures.
89% say reducing alert noise would help identify which alerts represent real business risk.
Nearly 9 in 10 security decision-makers and practitioners agree that threat intelligence alone does not reduce risk unless it is continuously validated against actual exposure.
54% say AI and automation would most help in validating whether exposures are realistically exploitable.