Skip to main content

Cybersecurity statistics / Incident Response

75% of critical vulnerability responses initiate administrative workflows (such as ticket creation or routing) rather than immediately fixing the underlying flaw.

PublisherVicarius
ReportThe 2026 State of Vulnerability Remediation report
Published15 July 2026
TopicsIncident Response, Vulnerability Management, Operational Risk

Published by Vicarius in The 2026 State of Vulnerability Remediation report, 15 July 2026. The figure is taken from the report as published; the full methodology is in the source.

View the original report

Related statistics

Most government agencies take an average of about four months to notify victims of data breaches following ransomware attacks.
Comparitech, 19/07/2026
German municipal transport company Verkehrsgesellschaft Main-Tauber took 11 weeks to recover from its January 2026 ransomware attack.
Comparitech, 19/07/2026
67% of root causes across 661 incident response and managed detection and response (MDR) cases are identity-related.
Sophos, 18/07/2026
Utilities resolve 30% of critical exposures within one hour.
Check Point, 04/07/2026
The meantime to resolve (MTTR) for AI/LLM security issues is 36 days, up from 19 days in 2025.
Cobalt, 28/06/2026
34% of organizations that experienced a production incident in the past year cannot determine whether AI-generated code contributed to it.
GitLab, 28/06/2026

Get the newsletter

Weekly cybersecurity statistics by email.