Report by Netwrix
2026 Data and Identity Security Report
Key Findings
17% of organizations remain entirely unprepared for AI security.
75% of sensitive data exposures begin with compromised identities or misconfigured permissions.
70% of organizations have no unified strategy connecting identity and data visibility.
45% of organizations are still developing AI governance programs.
74% of organizations lack a unified view of sensitive data and the identities that can access it.
Only 11% of organizations report full AI security readiness.
Among organizations where AI significantly expanded identities requiring access, breach rates reached 43% over the past twelve months. In contrast, where AI had not materially changed access patterns, breach rates were 11% over the past twelve months.
Only 11% of organizations have operationalized AI governance through continuous enforcement and monitoring.
76% of organizations cannot immediately revoke standing access when it is no longer needed.
Only 19% of organizations fully govern non-human identities.
Only 20% of organizations fully monitor employee use of shadow AI.
Only 23.5% of organizations can respond at the speed attackers move.
Organizations with 500 to 999 employees reported a 40.3% breach rate, the highest of any size segment.
In North America, 24% of breached organizations reported losses of at least $100,000 in the past year.
Nearly 63% of organizations require between one and three days to remediate identified risks.
76% of organizations do not fully govern or monitor non-human identities.
In North America, 12% of breached organizations reported losses above $250,000 in the past year.