Report by Filigran

State of Threat Management 2026

27 FINDINGSPublished Jun 30, 2026
View Original Report →

Key Findings

61% of organizations say they cannot determine which vulnerabilities are most likely to be exploited in real-world attacks.

Vulnerability ManagementThreat Prioritization

German security teams report spending just 27% of their time on low-priority or non-exploitable risks.

Operational EfficiencyGermanyExploitation

94% say a proactive cybersecurity posture in 2026 will depend on integrating threat intelligence with exposure management.

Proactive SecurityThreat IntelligenceExposure Management

Only 41% of organizations have a fully consolidated view of cyber risk exposure.

Cyber RiskSecurity Visibility

Organizations deploy an average of 14 different threat intelligence feeds.

Threat IntelligenceSecurity Tooling

52% of North American organizations report having a fully consolidated view of cyber risk exposure.

Cyber Risk ExposureSecurity VisibilityNorth America

Concern about disrupting systems (49%), excessive manual effort (46%), and poor integration with existing security processes (42%) are the top barriers to validating whether threats are exploitable.

ExploitabilityValidation

Currently, 37% of exposure management processes are AI-driven and organizations expect this to reach 59% within two years.

AIExposure Management

56% say AI and automation would most help in understanding which threats are relevant to their specific environment.

Threat RelevanceAIAutomation

93% agree that delaying improvements to how they manage cyber risk increases the likelihood of serious incidents.

Risk ManagementIncident Likelihood

EMEA organizations report 37% having a fully consolidated view of exposure and 35% using continuous, automated validation.

Exposure ManagementAutomationEMEA

APAC organizations report 31% having a fully consolidated view of exposure and 27% using continuous, automated validation.

Exposure ManagementAutomationAPAC

84% of security decision-makers and practitioners agree that cyberattacks exploit known risks that are not prioritized.

CyberattacksRisk PrioritizationKnown RisksExploitation

Security teams spend 42% of their time investigating risks that later prove low priority or non-exploitable.

Operational EfficiencySecurity OperationsInvestigation

Germany leads surveyed countries with 58% adoption of automated validation.

AutomationGermany

88% of security teams acknowledge that periodic assessments cannot keep pace with the speed of change in their environments.

AssessmentOperational Pace

95% of organizations agree greater automation would improve their confidence that teams are focused on the most important risks.

AutomationRisk Focus

Three-quarters of organizations plan to invest in both cyber risk quantification tools and exposure assessment capabilities over the next 12–24 months.

InvestmentRisk QuantificationExposure Management

58% of U.S. organizations report a fully established CTEM program.

CTEMUS

51% of North American organizations use threat intelligence within a continuous, automated validation process.

Threat IntelligenceAutomationNorth America

Only 38% of organizations use threat intelligence within a continuous, fully automated validation process.

AutomationThreat Intelligence

Organizations outside North America are roughly 20 percentage points behind North America on both consolidated cyber risk visibility and continuous automated validation.

Consolidated Cyber Risk VisibilityContinuous Automated ValidationNorth AmericaRegional Differences

88% of security teams agree that without greater automation, they cannot keep up with the volume of risks they must assess.

AutomationRisk VolumeRisk Assessment

59% say AI and automation would most help detect vulnerabilities, misconfigurations, and exposures.

Vulnerability DetectionAIAutomation

89% say reducing alert noise would help identify which alerts represent real business risk.

Alert ManagementRisk Detection

Nearly 9 in 10 security decision-makers and practitioners agree that threat intelligence alone does not reduce risk unless it is continuously validated against actual exposure.

Threat IntelligenceRisk ReductionExposure Validation

54% say AI and automation would most help in validating whether exposures are realistically exploitable.

Exploitation ValidationAIAutomation