Report by Pentera

State of Pentesting survey report

11 FINDINGSPublished May 7, 2025
View Original Report →

Key Findings

Pentesting accounts for 11% of the total IT security budgets of U.S. enterprises.

Pen testingOffensive securityBudgetEnterpriseUS

67% of enterprises reported a breach in the past 24 months.

Data breach

U.S. enterprises allocate an average of $187,000 annually to pentesting.

Pen testingOffensive securityBudget

50% of CISOs identify software-based testing as a primary method for uncovering exploitable security gaps within their organizations.

Pen testingOffensive securityCISO

28% of CISOs experienced financial loss following a breach.

Data breachCyber attack consequences

36% of CISOs reported unplanned downtime following a breach.

Data breachCyber attack consequences

30% of CISOs cited data exposure following a breach.

Data breachCyber attack consequences

59% of enterprises have adopted at least one new security solution at the request of their cyber insurance provider.

Security toolEnterpriseCyber insurance

96% of organizations are making changes to their IT environment at least quarterly

IT infrastructure

The average total IT security budget for U.S. enterprises is $1.77 million.

Pen testingOffensive securityBudgetEnterpriseUS

76% of CISOs reported a significant impact following a breach.

Data breachCyber attack consequences