VendorsUpGuard
UpGuard
Cybersecurity reports and statistics published by UpGuard
8 categories2 reports
Research Reports
Reports and publications from UpGuard
Recent Statistics & Reports
The median security team spends 20 minutes dismissing a single junk alert.
5/27/2026•
Security OperationsAlert ManagementSecurity Alert
Organizations that use more than five disconnected security tools are twice as likely to miss critical threats compared to organizations with an integrated toolset.
5/27/2026•
Security ToolsThreat DetectionCritical Threats
43% of a security team's investigation time is consumed by manual context gathering.
5/27/2026•
Security OperationsManual Context GatheringThreat Investigation
79% of organizations are notified of a threat by external third parties such as researchers, customers, or attackers before their own internal detection.
5/27/2026•
Threat DetectionThreat NotificationInternal Threat Detection
For 25% of organizations, manual triage requires 214 hours per week, equivalent to 5.3 full-time employees.
5/27/2026•
Security OperationsManual TriageSOC
In MCP registries, for every server provided by a verified technology vendor there are up to 15 lookalike servers from untrusted sources.
2/9/2026•
Supply ChainTyposquattingAI Code Agents
Almost 20% of developers let AI automatically save changes to the project's main code repository without human review.
2/9/2026•
Code IntegritySoftware DevelopmentApplication Security
14.4% of AI agent configuration files grant arbitrary code execution permissions for Node.js.
2/9/2026•
Application SecurityCybersecurityDeveloper Tools
One in five developers grant AI agents permission for unrestricted file deletion, risking recursive wiping of a project or system.
2/9/2026•
Data SecurityAI AgentsSoftware Development
14.5% of AI agent configuration files grant arbitrary code execution permissions for Python.
2/9/2026•
Application SecurityAI AgentsDeveloper Tools
One in five developers grant AI code agents unrestricted access to perform high-risk actions without human oversight.
2/9/2026•
AI AgentsSoftware DevelopmentAccess Control