Skip to main content
HomeTopicsPen Testing

Pen Testing

Cybersecurity statistics about pen testing

Showing 1-20 of 28 results

77% of internal Security Operations Center (SOC) teams reported a skills shortage in penetration testing as of 2025, indicating a significant gap in essential cybersecurity capabilities.

Red Canary10/23/2025
Security OperationsSkills

21% of organizations rely on regular penetration testing to assess the effectiveness of their API security measures.

Salt Security10/8/2025
APIPen testing

Cloud misconfigurations and excessive permissions vulnerabilities were found in 42% of cloud environments that were pen tested.

BreachLock8/11/2025
CloudMisconfiguration

Nearly nine in 10 security leaders (88%) view penetration testing as an essential component of their overall security programme.

Cobalt7/31/2025
TestingPen testing

More than half (58%) of respondents require third-party penetration test reports to validate software security.

Cobalt7/31/2025
TestingPen testing

33% of respondents are still not conducting regular security assessments, including penetration testing, for their Large Language Model (LLM) deployments.

Cobalt6/24/2025
AIGen AI

32% of LLM pentest findings are serious

Cobalt6/24/2025
AIGen AI

Overall, 69% of serious findings across all pentest categories are resolved.

Cobalt6/24/2025
AIGen AI

The resolution rate for high-severity vulnerabilities found in LLM pentests falls to just 21%.

Cobalt6/24/2025
AIGen AI

Pentesting accounts for 11% of the total IT security budgets of U.S. enterprises.

Pentera5/7/2025
Pen testingOffensive security

U.S. enterprises allocate an average of $187,000 annually to pentesting.

Pentera5/7/2025
Pen testingOffensive security

50% of CISOs identify software-based testing as a primary method for uncovering exploitable security gaps within their organizations.

Pentera5/7/2025
Pen testingOffensive security

The average total IT security budget for U.S. enterprises is $1.77 million.

Pentera5/7/2025
Pen testingOffensive security

67% say infrequent pen testing has left concerning gaps in security assessments.

Cymulate4/23/2025

Almost two-thirds (approximately 66%) of security leaders say that missing exposures due to manual pen testing is an issue.

Cymulate4/23/2025
Exposure managementPen testing

94% of security leaders agree that pentesting is foundational to security.

Cobalt4/14/2025
TestingPen testing

Financial companies have a lower rate of serious findings (11%) in pentests.

Cobalt4/14/2025
TestingPen testing

Large organisations resolve only 60% of serious pentest findings.

Cobalt4/14/2025
TestingPen testing

Larger organisations take over a month longer (61 days) than smaller ones (27 days) to resolve serious findings in pentests.

Cobalt4/14/2025
TestingPen testing

LLM pentests yield the highest proportion of serious vulnerabilities (32%) than any other asset type tested.

Cobalt4/14/2025
LLMPen testing