Skip to main content

Cybersecurity statistics / Endpoint Security

Across those attacks, 30% of initial compromises occur on user devices.

PublisherSophos
ReportThe State of Ransomware 2026
Published15 July 2026
TopicsEndpoint Security, Ransomware

Published by Sophos in The State of Ransomware 2026, 15 July 2026. The figure is taken from the report as published; the full methodology is in the source.

View the original report

Related statistics

59% of organizations agree they must take physical possession of an endpoint to remediate and restore the device after an incident.
Absolute Security, 27/05/2026
58% of enterprise CISOs agree that a ransomware incident left endpoints inoperable.
Absolute Security, 27/05/2026
92% of organizations have AI installed on at least some local machines with access to SSH and encryption keys.
Semperis, 27/05/2026
Over the past 12–18 months, 57% of enterprise CISOs report their enterprises experienced an attack that originated on a remote, mobile, or hybrid device.
Absolute Security, 27/05/2026
Remote monitoring and management (RMM) tool abuse accounted for 26% of all detections in monitored SMB environments.
Guardz, 27/05/2026
Critical OS patching across PCs running Windows 10 and 11 is behind an average of 127 days, up from 56 days in 2025.
Absolute Security, 27/05/2026

Get the newsletter

Weekly cybersecurity statistics by email.