Skip to main content

Cybersecurity statistics / Incident Response

Over two-thirds of GRC and security leaders are only "somewhat confident" or "not very confident" that their organization can respond decisively to a fast-moving AI security incident.

PublisherOptro
ReportHuman behavior: The AI risk surface GRC can't ignore
Published12 May 2026
TopicsIncident Response, AI Security Incident, AI Risk

Published by Optro in Human behavior: The AI risk surface GRC can't ignore, 12 May 2026. The figure is taken from the report as published; the full methodology is in the source.

View the original report

Compare this across sources

12 sources answer what share of organisations have an ai governance policy in place. They report between 18% and 44%, with a median of 36.5%.

See all 12 sources

Related statistics

Most government agencies take an average of about four months to notify victims of data breaches following ransomware attacks.
Comparitech, 19/07/2026
German municipal transport company Verkehrsgesellschaft Main-Tauber took 11 weeks to recover from its January 2026 ransomware attack.
Comparitech, 19/07/2026
67% of root causes across 661 incident response and managed detection and response (MDR) cases are identity-related.
Sophos, 18/07/2026
75% of critical vulnerability responses initiate administrative workflows (such as ticket creation or routing) rather than immediately fixing the underlying flaw.
Vicarius, 18/07/2026
Utilities resolve 30% of critical exposures within one hour.
Check Point, 04/07/2026
The meantime to resolve (MTTR) for AI/LLM security issues is 36 days, up from 19 days in 2025.
Cobalt, 28/06/2026

Get the newsletter

Weekly cybersecurity statistics by email.