Skip to main content

Cybersecurity statistics / Vulnerability Management

Across all financial services vendors, 50.2% carry high-severity CVEs.

PublisherBlack Kite
Report2026 State of Financial Services: The Dual Storm of Ransomware and Vendor Ecosystem Risk
Published3 June 2026
TopicsVulnerability Management, Financial Services, CVEs

Published by Black Kite in 2026 State of Financial Services: The Dual Storm of Ransomware and Vendor Ecosystem Risk, 3 June 2026. The figure is taken from the report as published; the full methodology is in the source.

View the original report

Related statistics

42% of enterprise security leaders discovered high or critical vulnerabilities outside scheduled testing windows at least monthly in the past year.
Synack, 25/07/2026
95% of enterprise security leaders discovered high or critical vulnerabilities outside scheduled testing windows in the past year.
Synack, 25/07/2026
79% of enterprise security leaders will not act on AI-generated findings without human validation.
Synack, 25/07/2026
79% of organizations take more than a day to deploy critical security patches.
Fleet Device Management, 25/07/2026
38% of organizations say vulnerability remediation ownership depends on the situation.
Vicarius, 18/07/2026
The average organization touches three or more systems per vulnerability remediation.
Vicarius, 18/07/2026

Get the newsletter

Weekly cybersecurity statistics by email.