Report by Swimlane

Cracks in the Foundation: Why Basic Security Still Fails

11 FINDINGSPublished Nov 12, 2025
View Original Report →

Key Findings

66% of organizations faced a security incident in the past year.

Security incident

64% of organizations fail to continuously assess vendor and supplier security after onboarding.

Vendor security assessmentSupplier security assessmentOnboarding

64% of organizations report that AI and automation have increased their focus on the basics of cyber hygiene.

AIAutomationCyber hygiene

73% of organizations take longer than 24 hours to apply critical patches.

PatchingCritical patches

41% of organizations rank expanding AI usage and expertise as the top improvement area.

AI

67% of organizations audit user access privileges quarterly or less often.

User access privilege

84% of organizations say AI and automation enhance cyber hygiene.

AIAutomationCyber hygiene

25% of organizations take between 8 and 30 days to apply critical patches.

PatchingCritical patches

92% of organizations that experienced a security incident in the past year believe stronger cyber hygiene could have prevented it.

Security incidentCyber hygiene

15% of organizations self-identify as 'leading' in cyber hygiene maturity.

Cyber hygieneMaturity

52% of organizations identify the human element, including employee training and awareness, as their greatest weakness.

Human elementEmployee trainingEmployee awareness