Report by Pentera

State of Pentesting survey report

11 FINDINGSPublished May 7, 2025
View Original Report →

Key Findings

Pentesting accounts for 11% of the total IT security budgets of U.S. enterprises.

PenteraState of Pentesting survey report·May 7, 2025
Pen testingOffensive securityBudgetEnterpriseUS

67% of enterprises reported a breach in the past 24 months.

PenteraState of Pentesting survey report·May 7, 2025
Data breach

U.S. enterprises allocate an average of $187,000 annually to pentesting.

PenteraState of Pentesting survey report·May 7, 2025
Pen testingOffensive securityBudget

50% of CISOs identify software-based testing as a primary method for uncovering exploitable security gaps within their organizations.

PenteraState of Pentesting survey report·May 7, 2025
Pen testingOffensive securityCISO

28% of CISOs experienced financial loss following a breach.

PenteraState of Pentesting survey report·May 7, 2025
Data breachCyber attack consequences

36% of CISOs reported unplanned downtime following a breach.

PenteraState of Pentesting survey report·May 7, 2025
Data breachCyber attack consequences

30% of CISOs cited data exposure following a breach.

PenteraState of Pentesting survey report·May 7, 2025
Data breachCyber attack consequences

59% of enterprises have adopted at least one new security solution at the request of their cyber insurance provider.

PenteraState of Pentesting survey report·May 7, 2025
Security toolEnterpriseCyber insurance

96% of organizations are making changes to their IT environment at least quarterly

PenteraState of Pentesting survey report·May 7, 2025
IT infrastructure

The average total IT security budget for U.S. enterprises is $1.77 million.

PenteraState of Pentesting survey report·May 7, 2025
Pen testingOffensive securityBudgetEnterpriseUS

76% of CISOs reported a significant impact following a breach.

PenteraState of Pentesting survey report·May 7, 2025
Data breachCyber attack consequences