Report by Vectra AI
2026 State of Threat Exposure Management Report
Key Findings
83% of enterprise environments observe new device types.
On average, more than 30% of enterprise devices are unmanaged because endpoint agents cannot be deployed.
100% of enterprise environments observe newly discovered devices within 14 days.
90% of enterprise environments observe new device roles.
The typical enterprise environment contains 1.17 AI agents per device.
35% of enterprise environments contain more AI agents than devices.
Deprecated TLS clients are present in 96% of enterprise environments.
98% of enterprise environments contain at least one attacker-relevant exposure condition.
Plaintext passwords are present in 85% of enterprise environments.
63% of enterprise environments exhibit exposure across multiple risk themes, including weak cryptography, credential exposure, legacy protocols and exposed remote access.
Expired certificates are present in 91% of enterprise environments.
Deprecated TLS servers are present in 82% of enterprise environments.
NetBIOS is present in 86% of enterprise environments.
The most extreme enterprise environment contains 96 AI agents assigned to a single device.