Cyber Attack Statistics

244 STATS54 SOURCES

Latest Statistics

National security organizations faced an average of 137 attempted or successful cyberattacks per week in 2025, up from 127 cyberattacks per week in 2024.

National SecurityCyber Attack

Cyberattacks against agencies in the U.S. have surged 25% in the last year and occur more frequently on a weekly basis than in the UK.

National SecurityCyber AttackUSUK

Web applications are the most attacked service type at 61%, up from 41% in 2024; remote management protocols account for 15%.

Forescout Technologies Inc2025 Threat Roundup·3mo ago
Application SecurityRemote ManagementCyber Attacks

72% of CISOs agreed that their role has evolved to include leading their organization’s ability to recover continuity following a cyberattack or security incident.

Incident RecoveryCyber IncidentCISOUKUS

In 2025, 57% of CISOs reported that their organizations took more than 4.5 days on average for full remediation and recovery after a cyber incident.

Incident RecoveryIncident RemediationCyber IncidentUSUK

In 2025, not a single Chief Information Security Officer (CISO) reported being able to recover from a cyber incident within a day.

Incident RecoveryCyber IncidentUSUK

In 2025, 19% of CISOs indicated that recovery efforts from cyber incidents extended as long as two weeks.

Incident RecoveryCyber IncidentUSUK

48% of New Yorkers stated they have been the victim of a cyberattack at least once.

Cyber AttackConsumerUSNew York

43% of SMBs report they experienced a cyberattack in the past 5 years.

SMBsUSCyber Attack

89% of schools experienced at least one cyber incident in the past year, primarily phishing, unauthorized access, and malware.

Cyber IncidentEducationPhishingUnauthorized AccessMalware

27% of SMBs said they were targeted in the past 12 months.

SMBsUSCyber Attack

64% of SMB owners reportedly recovered quickly from a cyber attack.

SMBsUSCyber AttackCyber Attack Recovery

3% of SMB owners faced severe, lasting damage following a cyber attack.

SMBsUSCyber AttackCyber Attack Consequences

99% of organizations experienced at least one attack on their AI systems in the past year.

Palo Alto NetworksThe State of Cloud Security Report 2025·5mo ago
AI systemsCyber attack

83% of US organizations reported a rise in cyberattacks.

Cyber attacksUS

47% of CISOs report being completely confident that AI-powered security tools can effectively defend against autonomous, AI-driven cyberattacks.

TrellixThe Mind of the CISO ·5mo ago
CISOAI DefenseAI-driven Cyberattacks

70% of organizations experienced at least one material third-party cyber incident in the past year.

Third-Party RiskThird-Party Cyber Incident

Resilience Scores among organizations have remained statistically flat since 2023, with an average decline of 3%.

Cybersecurity trainingCyber incident simulationResilience

Senior participation in AI-scenario labs dropped by 14% year over year.

Cybersecurity trainingCyber incident simulationAI-scenario labsSenior leadership

Only 41% of organizations include non-technical roles in cyber incident simulations.

Cybersecurity trainingCyber incident simulation

60% of all cyber training focuses on vulnerabilities that are more than two years old.

Cybersecurity trainingCyber incident simulationVulnerabilities

The average containment time for simulated cyber attacks is 29 hours.

Cybersecurity trainingCyber incident simulationContainment

94% of organizations globally believe they are prepared for a major cyber incident.

Cybersecurity trainingCyber incident simulationPreparadness

Decision accuracy among teams responding to cyber incidents is only 22%.

Cybersecurity trainingCyber incident simulation

58% of IT and security leaders believe it would take at least two days to recover and achieve full-service operations post-compromise

Cyber attack consequences

In 2025, only 28% of IT and security leaders believed they could fully recover from a cyber incident in 12 hours or less, down from 43% in 2024

Cyber attack consequencesRecovery

44% of retailers reported experiencing a significantly higher volume of attacks in 2025.

RetailCyber attacks

92% of organizations reported experiencing legal, regulatory, or compliance consequences, including fines, lawsuits, or other enforcement actions.

Cyber attack consequences

76% of organizations have experienced at least one material cyberattack.

Cyber attack consequences

70% of publicly traded companies reported adjusting earnings or financial guidance after a cyberattack.

Cyber attack consequences

68% of publicly traded companies said they observed an impact on their stock price after a cyberattack.

Cyber attack consequences

73% of privately held firms redirected budgets from innovation and growth initiatives after a cyberattack.

Cyber attack consequences

38% of all reported cyber incidents in the EU in 2024 targeted the public administration sector.

Cyber incidentPublic AdministrationEurope

Cybercrime operators accounted for approximately 16% of cyber incidents in the EU in 2024.

Cyber incidentCybercrime operatorEurope

Cyberespionage campaigns constituted 2.5% of all reported cyber incidents in the EU in 2024.

Cyber incidentCyberespionageEurope

Data breaches accounted for 17.4% of cyber incidents affecting public administration in the EU in 2024.

Data breachCyber incidentPublic AdministrationEurope

69% of cyber incidents in 2024 targeted central governments in the EU.

Cyber incidentCentral governmentEurope

60% of all reported cyber incidents in 2024 were Distributed Denial-of-Service (DDoS) attacks.

Cyber incidentDDoSEurope

Hacktivists were responsible for nearly 63% of cyber incidents in the EU in 2024.

Cyber incidentHacktivismEurope

13% of CISOs oversee 50 or more security tools.

Nagomi Security2025 CISO Pressure Index,·6mo ago
Cyber incidentCISOUSSecurity tools