Report by Vectra AI

2026 State of Threat Exposure Management Report

14 FINDINGSPublished Jul 22, 2026
View Original Report →

Key Findings

83% of enterprise environments observe new device types.

Asset ManagementEnterprise Security

On average, more than 30% of enterprise devices are unmanaged because endpoint agents cannot be deployed.

Unmanaged DevicesEndpoint SecurityAsset ManagementEnterprise Security

100% of enterprise environments observe newly discovered devices within 14 days.

Asset ManagementEnterprise Security

90% of enterprise environments observe new device roles.

Asset ManagementEnterprise Security

The typical enterprise environment contains 1.17 AI agents per device.

AI AgentsIdentity and AccessEnterprise Security

35% of enterprise environments contain more AI agents than devices.

AI AgentsAsset ManagementEnterprise Security

Deprecated TLS clients are present in 96% of enterprise environments.

CryptographyLegacy ProtocolsEnterprise Security

98% of enterprise environments contain at least one attacker-relevant exposure condition.

Exposure ManagementEnterprise Security

Plaintext passwords are present in 85% of enterprise environments.

Credential ExposureAuthenticationEnterprise Security

63% of enterprise environments exhibit exposure across multiple risk themes, including weak cryptography, credential exposure, legacy protocols and exposed remote access.

CryptographyCredential ExposureLegacy ProtocolsRemote AccessEnterprise Security

Expired certificates are present in 91% of enterprise environments.

CertificatesEnterprise Security

Deprecated TLS servers are present in 82% of enterprise environments.

CryptographyLegacy ProtocolsEnterprise Security

NetBIOS is present in 86% of enterprise environments.

Network ProtocolsLegacy ProtocolsEnterprise Security

The most extreme enterprise environment contains 96 AI agents assigned to a single device.

AI AgentsAttack SurfaceEnterprise Security