Cybersecurity Statistics
Every figure is quoted as its publisher wrote it and linked back to the report it came from, so you can check it before you cite it.
Most recent
Redspin, Committed to the Mission: The State of the DIB with CMMC in Flux
Latest statistics
The newest addition from each of the last six reports.
Between 89% and 95% of email phishing attachments lead to credential theft efforts.
Half of security leaders identify attacks targeting AI systems as one of their biggest preparedness gaps.
88% of security operations professionals and leaders report that AI makes their work more satisfying.
Average monthly vulnerabilities exploited increased from 10.5 per month in 2025 to 18 per month from January 2026 to August 2026.
79% of healthcare organizations say their non-human identities are not fully governed.
90% of open critical and high-severity vulnerabilities remain exposed for more than 90 days across the organizations analyzed.
Browse by Industry
Healthcare
414 stats · 61 sourcesFinancial Services
603 stats · 117 sourcesEducation
194 stats · 27 sourcesGovernment
136 stats · 39 sourcesBrowse by Topic
View All →Ransomware
1216The most heavily reported topic here, and the one where publishers disagree most about how often organisations pay.
Phishing
444Click rates and BEC losses. Watch for figures that count attempts rather than successful attacks.
Data Breach
545Breach costs and detection times.
Fraud
1105Now dominated by deepfake and AI-assisted scams.
DDoS
137Insider Threat
166Negligent insiders outnumber malicious ones in almost every source.
Compare
Top Publishers
View All 626→Every statistic links to the report it came from, with the publisher and publication date attached. Read about our methodology →
Curated by Laura Martisiute. Last updated Oct 1, 2026.