
Cyber resilience now measures more than whether an organization can block an attack. It measures how well a business can continue operating, protect critical data, recover systems, and adapt after an incident. In real-world settings, retailers need resilience to keep payments and fulfillment running during ransomware attacks, while manufacturers need it to protect production systems and restore operations without extended shutdowns. The latest data shows that AI, identity compromise, supply chain exposure, and faster attacks are changing how organizations prepare for disruption. Explore the statistics below to see how cyber resilience is changing.
Editor’s Choice: Key Findings
- AI security governance improved sharply: 64% of organizations now have processes for assessing the security of AI tools, up from 37% in the previous year’s findings.
- The cyber resilience ceiling remains low. While 64% meet minimum requirements, just 19% exceed their resilience requirements, up from 9% in 2025.
- Cyberattack speed has compressed the response window. The average eCrime breakout time fell to 29 minutes during 2025, while the fastest observed breakout took just 27 seconds.
- Vulnerability exploitation became the leading breach entry point in the latest breach dataset, accounting for 31% of breaches.
- Third-party involvement reached 48% of breaches in the latest dataset, a 60% increase, highlighting the growing resilience risk created by interconnected suppliers and service providers.
- Ransomware remains costly even when ransom payments fall. The latest survey places the average recovery cost at $1.7 million, excluding ransom payments.
- Identity has emerged as a central ransomware weakness: 79% of ransomware attacks in the latest survey started through an identity-based approach.
Recent Developments
- The share of organizations assessing AI tool security rose from 37% in 2025 to 64% in 2026, one of the clearest year-over-year improvements in cyber governance.
- Among organizations evaluating AI security, 40% conduct periodic reviews, while 24% rely on a one-time assessment. Roughly one-third still have no validation process before AI deployment.
- AI-enabled adversary activity increased 89% year over year, with attackers using AI for reconnaissance, credential theft, evasion, and other stages of intrusion.
- Zero-day vulnerabilities exploited before public disclosure increased 42% in the latest threat intelligence findings.
- State-linked cloud-conscious intrusions increased 266%, showing that cloud infrastructure has become an increasingly important resilience battleground.
- Cyber-enabled fraud now reaches far beyond corporate networks: 73% of respondents said they or someone in their network experienced cyber-enabled fraud during 2025.
- Employee use of unapproved or “shadow” AI reached 45% in the latest breach findings, approximately triple the previous level.
- Meanwhile, AI bot traffic is growing at about 21% month over month, increasing the volume of automated activity that security teams must distinguish from legitimate traffic.
- The percentage of organizations using AI for cybersecurity has reached 77%, with phishing detection used by 52%, intrusion and anomaly response by 46%, and user behavior analytics by 40%.
Global Cyber Resilience Statistics
- Globally, 64% of organizations say they meet minimum cyber resilience requirements, while another 19% report exceeding those requirements.
- Cyber resilience confidence varies sharply by sector. 37% of NGOs report insufficient resilience, compared with 23% of public-sector organizations and 11% of private-sector organizations.
- Small organizations remain more exposed: they are twice as likely as large organizations to report insufficient cyber resilience.
- National preparedness also varies significantly. 84% of respondents in the Middle East and North Africa expressed confidence in their country’s ability to protect critical infrastructure, compared with 13% in Latin America and the Caribbean.
- In 2026, 64% of organizations are accounting for geopolitically motivated cyberattacks when setting cyber risk mitigation strategies.
- Among the largest organizations, 91% have changed their cybersecurity strategies in response to geopolitical volatility.
- The leading barriers to greater resilience include the rapidly evolving threat and technology landscape at 61%, third-party and supply chain vulnerabilities at 46%, and shortages of cybersecurity skills and expertise at 45%.
- Global breach research covering more than 22,000 security incidents and 12,195 confirmed breaches in the 2025 dataset found substantial growth in ransomware, third-party involvement, and vulnerability exploitation.
- In 2025, 72% of organizations reported rising cyber risks, while nearly 60% said geopolitical tensions had influenced cybersecurity strategy.
Cyber Resilience Maturity and Readiness Statistics
- Highly resilient organizations show a major workforce advantage: only 22% lack the workforce needed to achieve cybersecurity objectives, compared with 85% of organizations classified as insufficiently resilient.
- 76% of highly resilient organizations involve security teams in procurement decisions, compared with 53% of organizations with insufficient resilience. This indicates that mature programs integrate security before new technology or suppliers enter the environment.
- Mature organizations also monitor operational technology more consistently. 44% of highly resilient organizations monitor OT security, compared with just 9% of insufficiently resilient organizations.
- 71% of highly resilient organizations regularly review the security of their AI tools, versus only 20% among organizations with insufficient resilience.
- Resilient organizations test beyond their own walls: 44% simulate cyber incidents with ecosystem partners, compared with only 16% of insufficiently resilient organizations.
- Only 15% of highly resilient organizations report insufficient incident response and recovery planning, compared with 37% among less resilient organizations.
- Supplier assessment also separates mature programs from weaker ones. 74% of highly resilient organizations assess supplier security, compared with 48% of insufficiently resilient organizations.
- 53% of highly resilient organizations share cybersecurity information with partners, versus 31% among insufficiently resilient organizations.
- Workforce readiness remains a wider challenge. In 2025, 59% of cybersecurity professionals reported critical or significant skills needs, up from 44% in 2024.
- Only 55% of cybersecurity professionals believe their organizations have sufficient resources to handle security incidents over the next two to three years.

Cyberattack Frequency and Threat Trends
- Vulnerability exploitation now starts 31% of breaches in the latest breach dataset, overtaking stolen credentials as the leading initial entry point for the first time in the report’s 19-year history.
- In the 2025 dataset, vulnerability exploitation accounted for 20% of breaches and had already increased 34% year over year, showing the momentum behind the shift.
- The latest findings put third-party involvement at 48% of breaches, after a 60% increase, demonstrating how attackers increasingly reach organizations through external dependencies.
- In comparison, third parties appeared in 30% of breaches in the 2025 report, twice the previous share.
- Mobile-focused social engineering attacks now record a 40% higher success rate than traditional email phishing, reflecting attackers’ growing use of text messages and voice-based techniques.
- The average eCrime breakout time dropped to 29 minutes in 2025, representing a 65% increase in attack speed from 2024.
- The fastest observed eCrime breakout took only 27 seconds, while one documented intrusion began exfiltrating data within four minutes of initial access.
- In the 2025 breach dataset, ransomware appeared in 44% of breaches, up from 32% the previous year and representing a 37% increase.
- In Asia-Pacific specifically, ransomware accounted for 51% of breaches, while malware appeared in 83%, up from 58% in the previous year’s dataset.
- Manufacturing experienced a sharp change in attacker motivation in the 2025 findings: espionage-motivated breaches rose to 20% from 3% the previous year.
Ransomware Attack, Impact, and Recovery Statistics
- 79% of ransomware attacks in the 2026 survey started through an identity-based approach, making identity compromise one of the clearest ransomware resilience priorities.
- Malicious email accounted for 26% of ransomware incidents and phishing another 24% in the latest findings. Together, email-related causes represented half of incidents.
- Exploited vulnerabilities fell to 18% of ransomware root causes, down 14 percentage points year over year, ending their three-year run as the leading technical root cause.
- 56% of ransomware attacks encrypted data in the 2026 findings, compared with 50% in 2025. Of the latest attacks, 16% both encrypted and stole data.
- 48% of organizations with encrypted data paid a ransom in 2026. The four-year average remains close to 50%.
- The median ransomware payment fell to $769,000 in 2026, compared with $1 million in the previous year’s survey.
- Median ransom demands fell to $698,000, representing a 65% decline over two years, although individual attacks can still generate multimillion-dollar demands.
- Recovery remains expensive despite lower ransom demands. The average cost of recovering from ransomware reached $1.7 million per incident, an 11% year-over-year increase, excluding the ransom itself.
- Backup-based recovery improved to 66% of encrypted-data cases, up 12 percentage points from 2025. In addition, 55% of affected organizations fully recovered within one week and 16% recovered in less than a day.
- Organization size has a measurable effect on ransomware outcomes. Only 34% of organizations with 100-250 employees stopped attacks before encryption or extortion, compared with 46% of organizations employing 3,001-5,000 people.
Cyber Risk Trends Over the Past Year
- AI vulnerabilities showed the strongest increase, with 87% of respondents reporting that the risk had grown over the past year.
- Cyber-enabled fraud and phishing ranked second, with 77% saying these threats increased, while 21% saw little or no change.
- Supply chain disruption was also a growing concern, as 65% reported an increase compared with 32% who considered the risk stable.
- Software vulnerability exploitation increased according to 58% of respondents, while 39% reported that the threat remained at roughly the same level.
- Ransomware attacks continued to intensify, with 54% reporting increased risk and another 39% seeing no meaningful change.
- Insider threats were comparatively stable, with 61% reporting no change and only 32% saying the risk had increased.
- Denial-of-service attacks had the lowest reported increase at 28%, while 54% considered the risk unchanged and 18% said it had decreased.
- Overall, the data suggests that AI-related vulnerabilities, fraud, phishing, and supply chain risks are emerging as the fastest-growing cyber concerns, while traditional threats such as denial-of-service attacks appear more stable.

Data Breach Cost and Business Impact Statistics
- The global average cost of a data breach reached $4.99 million in 2026, up 12% from the previous year and setting a new record. Rising detection, escalation, and lost-business costs contributed to the increase.
- In 2025, the global average breach cost stood at $4.44 million. That means the worldwide average increased by about $550,000 between the 2025 and 2026 reports.
- U.S. organizations faced an average breach cost of $10.22 million in 2025, more than twice the global average that year.
- AI-enabled malicious breaches cost organizations an average of $6 million in 2026, roughly $1 million above the overall global breach average.
- AI model inversion attacks also produced an average breach cost of $6 million, highlighting the financial risk tied to exposed training data and sensitive model information.
- Organizations using security AI and automation extensively saved about $1.93 million per breach in 2026 compared with organizations that did not use these technologies.
- Breaches with lifecycles longer than 200 days averaged about $5.65 million in 2026, compared with $4.32 million for incidents contained within 200 days. Longer-running breaches therefore carried a cost premium of more than $1.3 million.
- Average costs for breaches lasting longer than 200 days increased 12% year over year, from about $5.01 million to $5.65 million.
- One in four malicious breaches in the 2026 study involved AI-enabled attacks, showing that AI has moved from an emerging security issue to a material factor in breach economics.
Cyber Incident Detection and Response Time Statistics
- Organizations required an average of 241 days to identify and contain a breach in the 2025 study, showing that many incidents remain active for months before full containment.
- Extensive security AI and automation shortened breach lifecycles by about 80 days in 2025 compared with organizations that did not use those capabilities.
- Global median attacker dwell time increased to 14 days in 2025, up from 11 days in the previous year’s dataset. Longer dwell time gives attackers more opportunity to escalate privileges, move laterally, and locate valuable data.
- Cyberespionage and North Korean IT worker incidents recorded a median dwell time of 122 days in the 2026 threat analysis, substantially above the overall median.
- In the prior annual dataset, incidents discovered internally had a median dwell time of 10 days, while incidents first reported by an external organization remained undetected for a median of 26 days.
- The fastest 25% of investigated intrusions reached data exfiltration in approximately 1.2 hours in the 2026 incident-response dataset, down from 4.8 hours the previous year.
- The fastest investigated attacks moved from initial access to exfiltration in about 72 minutes, making attack progression roughly four times faster than in the prior year.
- In an extreme documented case, data exfiltration began only 39 seconds after initial access, illustrating why automated containment now matters alongside conventional human-led response.
- Attackers can begin scanning for newly disclosed vulnerabilities within 15 minutes of a vulnerability announcement, leaving security teams little time to review advisories before automated exploitation starts.
Backup, Data Recovery, and Business Continuity Statistics
- Backup-based recovery accounted for 66% of encrypted-data recoveries in 2026, up 12 percentage points from the 2025 findings.
- The implied 2025 backup-recovery rate was 54%, showing that organizations made a sizable improvement in restoring encrypted data without relying solely on ransom payments.
- In the 2026 study, 55% of affected organizations fully recovered from ransomware within one week, while 16% completed recovery in less than one day.
- In 2025, 53% of ransomware victims recovered within one week, up sharply from 35% in 2024.
- Only 18% of organizations needed more than one month to recover from ransomware in 2025, compared with 34% in 2024.
- 94% of ransomware-affected organizations surveyed in 2025 planned to increase recovery spending, while 95% planned to increase prevention spending.
- Before experiencing an attack, 69% of organizations believed they were well prepared for ransomware. Confidence dropped by more than 20% after organizations experienced an actual incident.
- More than half, 52%, said their organizations needed significant improvement in aligning IT operations and cybersecurity teams, an important consideration when restoring systems during a crisis.
- Organizations whose backups were compromised experienced median ransomware recovery costs of $3 million versus $375,000 when backups remained intact, an eightfold difference in recovery costs.
- When organizations tested large-scale recovery capabilities, only 58% of their servers returned online within expected recovery targets, highlighting the difference between owning backups and proving recoverability.

Identity, Access Management, and Zero Trust Statistics
- Identity-based methods accounted for 65% of initial access in 2026 incident-response investigations, including social engineering, credential misuse, and authentication manipulation.
- Identity weaknesses played a role in nearly 90% of investigated incidents in the latest 2026 analysis, making identity resilience a core requirement rather than a narrow access-management issue.
- Vulnerability exploitation accounted for 22% of initial access in the same 2026 incident-response dataset, substantially below identity-driven entry methods.
- 97% of identity attacks observed in the 2025 defense dataset involved password-spray attacks, showing that basic password weaknesses still enable attack activity at scale.
- Identity-based attacks rose 32% during the first half of 2025, as attackers increasingly targeted credentials, authentication tokens, and account access.
- Phishing-resistant multifactor authentication can block up to 99% of identity attacks covered by the 2025 defense findings, making stronger authentication one of the highest-impact identity controls available.
- Nearly half, 48%, of 2026 incident investigations involved the browser, reflecting how attackers increasingly use everyday web sessions to steal credentials or bypass local security controls.
- In cloud environments, 59% of surveyed organizations ranked insecure identities and risky permissions as their leading infrastructure security risk, reinforcing the connection between cloud resilience and access governance.
- The growth of autonomous agents creates a new identity-management problem because organizations must govern both human and machine identities. Current 2026 guidance emphasizes continuous verification, limited privileges, and auditable access as central zero-trust controls.
Supply Chain and Third-Party Cyber Risk Statistics
- 65% of large organizations by revenue named third-party and supply chain vulnerabilities as their greatest barrier to cyber resilience in 2026, up from 54% in 2025.
- That 11-percentage-point increase represents roughly a 20% relative rise in the share of large organizations placing supply chain exposure at the top of their resilience challenges.
- 66% of organizations evaluate the cybersecurity maturity of their suppliers, meaning roughly one-third still lack this basic supplier-assurance practice.
- About 65% involve their cybersecurity function in procurement decisions, which leaves more than one-third buying products or services without consistent security involvement.
- Only 33% comprehensively map their supply chain ecosystems, despite growing dependence on software providers, cloud services, logistics partners and other external organizations.
- Just 27% simulate cyber incidents or conduct recovery exercises with supply chain considerations, leaving nearly three-quarters without this advanced resilience measure.
- Third-party involvement stood at 30% of breaches in the 2025 breach dataset, double the previous year’s share, showing how quickly external dependency risk was already growing before the 2026 increase.
- In the 2024 breach dataset, third-party involvement stood at 15% and had already increased 68% from the prior reporting period, indicating several consecutive years of rising partner and supplier exposure.
- Large-company concern about third-party vulnerabilities has therefore increased from 54% in 2025 to 65% in 2026, while only about one organization in three comprehensively maps dependencies. Together, those figures highlight a gap between recognizing supply chain risk and gaining operational visibility into it.
Cloud Security and Cyber Resilience Statistics
- 82% of organizations in a 2025 global survey operated some form of hybrid infrastructure, making security controls that work across cloud and on-premises environments increasingly important.
- About 63% used more than one cloud provider, illustrating how multi-cloud architectures now shape enterprise security and resilience planning.
- Insecure identities and risky permissions ranked as the leading cloud infrastructure security concern, cited by 59% of surveyed professionals.
- More than one-third, 34%, of organizations running AI workloads reported already experiencing an AI-related breach, connecting AI security directly with cloud risk management.
- Only 20% of organizations prioritized unified risk assessment across their cloud and AI environments, pointing to fragmented visibility across many security programs.
- Just 13% prioritized security-tool consolidation, despite the complexity created by hybrid infrastructure, multi-cloud environments and expanding AI workloads.
- Cloud attacks increased 87% during 2025, reinforcing the need to monitor cloud assets, identities and cross-platform attack paths continuously.
- In 2026 incident investigations, 87% of attacks crossed two or more attack surfaces, including combinations of cloud infrastructure, SaaS platforms, endpoints and identities.
- Investigators observed attackers operating across as many as 10 attack surfaces simultaneously, showing why isolated cloud-security tools can miss relationships between otherwise separate signals.

AI, Automation, and Cyber Resilience Statistics
- AI-driven cyberattacks increased 56% in 2026, with deepfake impersonation and AI-enabled malware among the leading forms of AI-supported malicious activity.
- One in four malicious breaches in the 2026 breach-cost study involved AI-enabled attacks, showing that artificial intelligence now affects a measurable share of real-world breach activity.
- Organizations using extensive security AI and automation saved $1.93 million per breach in 2026 compared with organizations that used none, demonstrating a measurable financial benefit from automation on the defensive side.
- In 2025, organizations with extensive security AI and automation resolved breaches about 80 days faster than organizations without those capabilities.
- AI-related breaches had already affected 34% of organizations operating AI workloads in a 2025 cloud and AI security survey.
- Generative AI now strengthens about 15% of documented attack techniques in the 2026 breach dataset, helping attackers accelerate tasks ranging from vulnerability research to malware development.
- The leading obstacle to applying AI in cybersecurity is insufficient knowledge or skills, cited by 54% of organizations. Another 41% cite the need for human oversight, while 39% point to uncertainty about AI risk.
- In sector-specific adoption, 69% of energy organizations using AI for cybersecurity apply it to intrusion and anomaly detection, while 80% of materials and infrastructure organizations emphasize phishing protection.
- Among manufacturing, supply chain and transportation organizations that use AI in cybersecurity, 59% apply it to automated security operations, showing how automation is moving into sectors with significant operational and physical dependencies.
- AI-assisted phishing can generate click-through rates as high as 54%, compared with about 12% for conventional phishing in the cited 2025 findings. That represents a potential 4.5-times increase in engagement with malicious messages.
Cybersecurity Skills and Workforce Statistics
- 95% of cybersecurity professionals reported at least one cybersecurity skills need in 2025, up 5 percentage points from the previous year. This indicates that the workforce challenge increasingly centers on specific capabilities rather than headcount alone.
- Nearly 59% reported critical or significant skills needs in 2025, compared with 44% in 2024. Another 23% described at least one skills shortage as critical.
- AI became the most frequently cited cybersecurity skills need at 41%, followed by cloud security at 36%, risk assessment at 29%, application security at 28%, and security engineering and GRC at 27% each.
- Skills shortages already produce measurable security consequences. 88% of respondents experienced at least one significant cybersecurity consequence because of missing skills, while 69% experienced more than one.
- Budget constraints remain closely connected to staffing. 33% of organizations said they lacked the budget to staff cybersecurity teams adequately, while 29% could not afford professionals with the required skills.
- Only 34% of respondents said their organizations had the right number of cybersecurity professionals in 2025. However, that was a 4-percentage-point improvement from the 30% reported since 2023.
- Workforce pressure has direct resilience implications: 72% believe reducing cybersecurity personnel significantly increases breach risk, while 76% believe organizations should face accountability when breaches follow cybersecurity staff reductions.
- AI is also changing career expectations. 73% expect AI to create demand for more specialized cybersecurity skills, 72% expect greater demand for strategic thinking, and 66% anticipate a need for broader skill sets.
- Training investment is responding to the skills gap. In 2026, 73% of large organizations reported increasing their cybersecurity training budgets during the previous 12 months, while 47% of security leaders named AI as their most pressing training priority.
- Despite these pressures, cybersecurity professionals remain relatively committed to the field: 87% believe cybersecurity professionals will always be needed, 81% remain confident in the profession, and 80% say they are passionate about their work.
Cyber Resilience by Industry and Business Size
- Organization size remains a strong predictor of cyber resilience. In the 2026 global survey, small organizations were twice as likely as large organizations to report insufficient resilience.
- Cybersecurity expertise also varies by company size. 46% of small organizations identified insufficient cybersecurity skills and expertise as a challenge, compared with 29% of large organizations.
- Sector differences remain pronounced. 37% of NGOs reported insufficient cyber resilience in 2026, compared with 23% of public-sector organizations and only 11% of private-sector organizations.
- Ransomware places a disproportionate burden on smaller businesses. In the 2025 breach dataset, ransomware appeared in 88% of SMB breaches, compared with 39% of breaches involving large organizations.
- Nearly half, 47% of SMBs, reported updating their cybersecurity solutions in a 2025 survey, suggesting that smaller businesses increasingly recognize the need to strengthen their defenses.
- Manufacturing recorded 2,713 confirmed breaches in the 2026 breach dataset. Ransomware appeared in 61% of manufacturing breaches, while malware appeared in 75%.
- External attackers caused 95% of manufacturing breaches in that dataset. Financial motives appeared in 87% of breaches, while espionage motives appeared in 15%.
- Healthcare recorded 1,438 confirmed breaches in the 2026 dataset. Third-party involvement reached 32%, reinforcing the sector’s exposure to business associates, software providers and other external dependencies.
- Healthcare breaches remained the most expensive industry category in the 2025 breach-cost study, averaging $7.42 million per incident, despite falling $2.35 million from 2024.
- Across all industries, the 2026 breach dataset contained 22,625 confirmed breaches. Manufacturing accounted for 2,713, public administration for 2,410, professional services for 2,558, healthcare for 1,438, and finance for 1,300.

Cybersecurity Budget and Investment Statistics
- Worldwide end-user information security spending was forecast to reach $213 billion in 2025, compared with $193 billion in 2024. That represents an increase of roughly $20 billion in one year.
- Global information security spending is expected to climb another 12.5% to $240 billion in 2026, adding approximately $27 billion to annual security expenditures.
- Cybersecurity training has become a specific investment priority. 73% of enterprises with 5,000 or more employees reported increasing security-team training budgets during the previous 12 months in the 2026 study.
- More than half, 54%, of those large organizations determine training requirements partly from new technology and system adoption, illustrating how AI and cloud deployments increasingly influence security investment.
- In 2025, 36% of cybersecurity professionals reported organizational cybersecurity budget cuts. The figure declined only 1 percentage point year over year, indicating that spending growth at the market level does not eliminate internal budget pressure.
- 24% of cybersecurity professionals also reported layoffs in 2025, down only 1 percentage point from 2024. Another 26% expected additional layoffs, compared with 22% who had predicted them a year earlier.
- India provides one regional example of continuing investment growth. Information security spending there is forecast to reach $3.44 billion in 2026, up 11.7% from approximately $3.08 billion in 2025.
- Security software represents the largest and fastest-growing security category in that market, with spending forecast to rise 12.4% to $1.56 billion in 2026, compared with about $1.39 billion in 2025.
- Security services spending in the same market is projected to increase from approximately $1.30 billion in 2025 to $1.44 billion in 2026, while network security spending is forecast to rise from $393 million to $437 million.
- Broader technology investment is also expanding the infrastructure that security teams must protect. Worldwide IT spending is forecast to reach $6.31 trillion in 2026, up 13.5% from 2025, with AI infrastructure contributing heavily to growth.
Cyber Resilience by Region and Country
- Confidence in national critical infrastructure cyber readiness varies sharply. 84% of respondents in the Middle East and North Africa expressed confidence in their country’s ability to protect critical infrastructure in 2026.
- In contrast, only 13% of respondents in Latin America and the Caribbean expressed comparable confidence, creating a 71-percentage-point gap with the Middle East and North Africa.
- Globally, 31% of respondents reported low confidence in their country’s ability to respond to a major cyber incident in 2026, up from 26% the previous year.
- Regional exposure to cyber-enabled fraud is also uneven. 82% of respondents in sub-Saharan Africa reported exposure to digital scams, followed by 79% in North America.
- Regional skills gaps remain especially pronounced outside Europe and North America. Among CEOs surveyed, 70% in sub-Saharan Africa and 69% in Latin America and the Caribbean said their organizations lacked the skills required to meet current cybersecurity objectives.
- Asia-Pacific experienced a substantial rise in system-intrusion breaches in the 2025 dataset. Such attacks accounted for 80% of regional breaches, up from 38% in the previous year’s findings.
- Malware appeared in 83% of Asia-Pacific breaches in the same dataset, compared with 58% the previous year, while ransomware appeared in 51%.
- Europe, the Middle East and Africa also recorded a shift in attack patterns. System-intrusion breaches nearly doubled to 53% of regional breaches, while internal actors contributed to 29% of breaches.
- Internal threats accounted for only 5% of North American breaches and 1% of Asia-Pacific breaches in the same dataset, compared with 29% in EMEA, illustrating meaningful regional differences in attack sources.
- Geopolitical pressure increasingly affects large multinational organizations regardless of headquarters. 91% of organizations with more than 100,000 employees changed their cybersecurity strategies in response to geopolitical volatility.

Critical Infrastructure Cyber Resilience Statistics
- Industrial ransomware activity reached a new scale in 2025. More than 3,300 industrial organizations were affected, nearly twice the previous year’s number, while 119 ransomware groups targeted industrial organizations.
- Manufacturing accounted for more than two-thirds of industrial ransomware victims during 2025, demonstrating the operational appeal of targets where downtime can immediately affect production and revenue.
- Industrial ransomware pressure remained high into 2026, with 1,020 incidents identified in Q1 2026 alone across industrial organizations worldwide.
- OT visibility remains limited. Only 30% of OT networks in the 2026 industrial security findings had sufficient visibility, while 56% could not see activity below the IT/OT boundary.
- Detection and response represent an even broader weakness: 88% of assessed OT environments struggled with detection and response, creating opportunities for attackers to operate before physical or operational abnormalities expose them.
- The previous annual study documented 1,693 ransomware attacks against industrial organizations in 2024, an 87% increase over 2023. The following year therefore extended an already steep upward trend.
- Operational consequences can extend well beyond encrypted office computers. Among ransomware incidents investigated in 2024, 75% caused a partial OT shutdown, while 25% caused a complete OT shutdown.
- Remote access remains an important weakness in industrial environments. 65% of assessed sites had insecure remote-access conditions, including exposed remote desktop connections, unpatched VPN infrastructure or weak credentials.
- Vulnerability prioritization also matters because not every OT flaw creates equal operational risk. Only 6% of assessed OT vulnerabilities fell into the highest-priority “Now” category, while 63% fell into the planned-remediation category and 31% into the lowest-priority category.
- In the U.S., 16 critical infrastructure sectors receive special designation because their disruption could harm national security, economic security, public health or safety. Ransomware and data-breach complaints continued to affect these sectors throughout 2025.
Frequently Asked Questions (FAQs)
64% of organizations report meeting their minimum cyber resilience requirements, while another 19% say they exceed them.
Only 19% of organizations report cyber resilience above their required level, highlighting a sizable gap between baseline readiness and stronger resilience.
About 56% of ransomware attacks successfully encrypted organizational data in the latest 2026 ransomware study.
Software vulnerability exploitation accounts for 31% of breaches, making it the leading initial access route in the latest breach dataset.
As one current regional benchmark, information security spending in India is projected to reach $3.4 billion in 2026, an 11.7% increase from 2025.
Conclusion
Cyber resilience remains uneven even as organizations spend more on security and adopt AI-driven defenses. Small organizations face larger resilience gaps, workforce shortages remain widespread, and global information security spending is projected to reach $240 billion. At the same time, ransomware, identity attacks, third-party exposure and industrial threats continue to pressure organizations across sectors and regions. The strongest resilience programs increasingly combine skilled teams, tested recovery plans, secure identities, supplier oversight and visibility across cloud, IT and operational environments.