Skip to main content

Cybersecurity statistics / Security Testing

55% of organizations are cutting or not increasing investment in red and purple teaming.

PublisherKroll
ReportBridging the Cyber Resiliency Gap: Why Aligning Cybersecurity Priorities Is Critical for Business Resilience
Published18 March 2026
TopicsSecurity Testing, Proactive Defense, Budget, Investment, Red Teaming

Published by Kroll in Bridging the Cyber Resiliency Gap: Why Aligning Cybersecurity Priorities Is Critical for Business Resilience, 18 March 2026. The figure is taken from the report as published; the full methodology is in the source.

View the original report

Related statistics

95% of enterprise security leaders discovered high or critical vulnerabilities outside scheduled testing windows in the past year.
Synack, 25/07/2026
42% of enterprise security leaders discovered high or critical vulnerabilities outside scheduled testing windows at least monthly in the past year.
Synack, 25/07/2026
15% of enterprise security leaders describe their security testing and validation program as continuous.
Synack, 25/07/2026
38% of enterprise security leaders report that at least one-quarter of their critical attack surface had not been independently tested or validated in the previous 90 days.
Synack, 25/07/2026
44% of organizations test their security biannually or less, or not at all.
SimSpace, 27/05/2026
12% of CISOs report testing their endpoint protection detection capability within the last three months
Horizon3.ai, 27/05/2026

Get the newsletter

Weekly cybersecurity statistics by email.