Unusual Statistics

4.2% of organizations took over 30 days to fix high-severity vulnerabilities—discover why that delay matters in today’s cyber risk landscape.
Magnus ÖbergAdrien Chevalier

Written by Magnus Öberg

Fact-checked by Adrien Chevalier

Statistics
25
Sources
25
Sections
6
Reading time
6 minutes
Security isn’t just about what threats exist—it’s about how quickly organizations can respond. Across 2023–2024 reports, patterns emerge from 11 hours median malware detection in endpoints to long remediation timelines for critical flaws, alongside risks like human error, ransomware, and supply-chain attacks. We also explore how defenses evolve, from automated patching and threat intelligence feeds to SOAR, managed security services, and deception tech.

Key Takeaways

  1. 12.1% of measured passwords were known to be reused across multiple breach incidents in 2024
  2. 24.2% of organizations took more than 30 days to remediate high-severity vulnerabilities (2024)
  3. 392% of organizations said they use automated patching for at least some systems (2024)
  4. 438% of organizations reported their cloud security posture is 'not mature' (2024)
  5. 547% of organizations reported using threat intelligence feeds (2024)
  6. 68.0% of all global greenhouse gas (GHG) emissions came from buildings in 2022
  7. 7$32.4 billion was the global spending on cybersecurity services in 2024
  8. 8$8.5 billion was the worldwide market for deception technology in 2023
  9. 9$18.8 billion global market value for incident response services in 2023
  10. 1018% of employees used generative AI tools at work weekly in 2024
  11. 1139% of enterprises reported using security orchestration automation and response (SOAR) (2024)
  12. 1243% of organizations reported that attackers target internet-facing applications first (2023)
  13. 1326% of organizations reported they had experienced at least one supply-chain attack in the past year (2024)
  14. 14$9.9 billion global spend on IT services was attributed to generative AI in 2023
  15. 152.3% of global GDP was lost to electricity theft and system losses in 2020

Breaches keep scaling while defenses lag: 2.1% reused passwords, 72% involve web apps, and 61% of small businesses get attacked.

01Performance Metrics

5
  1. 12.1% of measured passwords were known to be reused across multiple breach incidents in 2024
  2. 24.2% of organizations took more than 30 days to remediate high-severity vulnerabilities (2024)
  3. 392% of organizations said they use automated patching for at least some systems (2024)
  4. 4Median time to detect malware outbreaks in endpoints was 11 hours in 2023
  5. 55.1 years was the median time to resolve a data breach in 2023 (from detection to containment)

03Market Size

4
  1. 1$32.4 billion was the global spending on cybersecurity services in 2024
  2. 2$8.5 billion was the worldwide market for deception technology in 2023
  3. 3$18.8 billion global market value for incident response services in 2023
  4. 4$5.7 billion global spend on managed security services in 2023

04User Adoption

3
  1. 118% of employees used generative AI tools at work weekly in 2024
  2. 239% of enterprises reported using security orchestration automation and response (SOAR) (2024)
  3. 343% of organizations reported that attackers target internet-facing applications first (2023)

05Industry Overview

3
  1. 126% of organizations reported they had experienced at least one supply-chain attack in the past year (2024)
  2. 2$9.9 billion global spend on IT services was attributed to generative AI in 2023
  3. 32.3% of global GDP was lost to electricity theft and system losses in 2020

06Cybersecurity Impact

6
  1. 161% of small businesses reported experiencing a cyberattack in 2023
  2. 259% of IT leaders reported data breaches were caused by human error in 2023
  3. 31.8 million ransomware attacks were detected in 2023 worldwide
  4. 472% of data breaches involved web applications in 2023
  5. 531% of organizations reported they experienced ransomware recovery failures in 2023
  6. 641% of cybersecurity incidents involved credential theft

Cite this report

This report is designed to be cited. We maintain stable URLs and versioned verification dates. Copy the format appropriate for your publication below.

APA
Magnus Öberg. (2026, September 21). Unusual Statistics. Statpit. https://statpit.com/unusual-statistics
MLA
Magnus Öberg. "Unusual Statistics." Statpit, 21 Sep 2026, https://statpit.com/unusual-statistics.
Chicago
Magnus Öberg. 2026. "Unusual Statistics." Statpit. https://statpit.com/unusual-statistics.

Sources and references

25 datasets cited across this report. Attribution is report-level.

2 additional datasets are cited and not shown individually.