Skip to main content

Cybersecurity statistics / Attack Surface

38% of enterprise security leaders report that at least one-quarter of their critical attack surface had not been independently tested or validated in the previous 90 days.

PublisherSynack
ReportThe State of Continuous Security Validation
Published21 July 2026
TopicsAttack Surface, Security Testing, Threat Exposure, Enterprise Security

Published by Synack in The State of Continuous Security Validation , 21 July 2026. The figure is taken from the report as published; the full methodology is in the source.

View the original report

Related statistics

The most extreme enterprise environment contains 96 AI agents assigned to a single device.
Vectra AI, 25/07/2026
The top barriers to reducing the attack surface reported by IT and security professionals are high overhead in maintaining hardening rules and exceptions (38%), fear of operational disruption (35.4%), and resource constraints (34.6%).
Bitdefender, 04/07/2026
64% of IT and security professionals in Singapore and 61.6% in the U.S. view agentic AI expanding the attack surface as a regional flashpoint.
Bitdefender, 04/07/2026
More than 1 in 7 organizations expose API documentation to the internet.
Intruder, 27/05/2026
40% of organizations rank integrating generative and agentic AI into the business among their top three cybersecurity priorities.
SpecterOps, 27/05/2026
68% of the enterprise environment remains untested, creating significant blind spots.
Synack & Omdia, 27/05/2026

Get the newsletter

Weekly cybersecurity statistics by email.