Report by Vectra AI

2026 State of Threat Exposure Management Report

14 FINDINGSPublished Jul 22, 2026
View Original Report →

Key Findings

83% of enterprise environments observe new device types.

Asset ManagementEnterprise Security

On average, more than 30% of enterprise devices are unmanaged because endpoint agents cannot be deployed.

Unmanaged DevicesEndpoint SecurityAsset ManagementEnterprise Security

100% of enterprise environments observe newly discovered devices within 14 days.

Asset ManagementEnterprise Security

90% of enterprise environments observe new device roles.

Asset ManagementEnterprise Security

35% of enterprise environments contain more AI agents than devices.

AI AgentsAsset ManagementEnterprise Security

Deprecated TLS clients are present in 96% of enterprise environments.

CryptographyLegacy ProtocolsEnterprise Security

98% of enterprise environments contain at least one attacker-relevant exposure condition.

Exposure ManagementEnterprise Security

Plaintext passwords are present in 85% of enterprise environments.

Credential ExposureAuthenticationEnterprise Security

63% of enterprise environments exhibit exposure across multiple risk themes, including weak cryptography, credential exposure, legacy protocols and exposed remote access.

CryptographyCredential ExposureLegacy ProtocolsRemote AccessEnterprise Security

Expired certificates are present in 91% of enterprise environments.

CertificatesEnterprise Security

Deprecated TLS servers are present in 82% of enterprise environments.

CryptographyLegacy ProtocolsEnterprise Security

NetBIOS is present in 86% of enterprise environments.

Network ProtocolsLegacy ProtocolsEnterprise Security

The typical enterprise environment contains 1.17 AI agents per device.

AI AgentsIdentity and AccessEnterprise Security

The most extreme enterprise environment contains 96 AI agents assigned to a single device.

AI AgentsAttack SurfaceEnterprise Security