Key Takeaways
- 57% of breaches involved the use of stolen credentials (per Verizon DBIR 2024 using 2023 data)
- 70% of organizations reported they use conditional access policies for risk-based access decisions (2024)
- 1.2 billion records were exposed due to data breaches in 2023 (global total reported by HIPAA Journal)
- 63% of organizations reported using third-party software as part of their application stack (2024)
- 49% of organizations reported they have experienced a security incident caused by a third party or vendor (2024)
- 22,000+ vulnerabilities were added to the NVD in 2023 (NVD annual totals)
- 1,600 vulnerabilities are disclosed per day on average globally (per VulnDB/industry analyses based on NVD and other sources, 2023)
- $5.02 million average cost of a data breach in 2018, as reported by IBM Cost of a Data Breach Report (2018)
- The average time to identify a breach was 207 days and average time to contain was 75 days (2023)
- $247.0 billion global cybersecurity spending forecast for 2029 (Gartner forecast)
- A $2.11 billion US market for security information and event management (SIEM) in 2023 (Frost & Sullivan)
- $5.0 billion global market for identity and access management (IAM) in 2024 (MarketsandMarkets)
- 3.4 million ransomware attacks were blocked in 2023 by Microsoft Defender and Microsoft 365 security products, reported in Microsoft’s Security Blog metrics
- The US Federal Government reported 61,000 cybersecurity incidents in FY 2023 (per CISA incident reporting dashboard)
- In 2023, CISA analyzed 2,000+ vulnerabilities and published guidance for critical infrastructure agencies (CISA vulnerability guidance output)
Stolen credentials and third party risk drive major breaches, as malware, phishing, and vulnerabilities keep escalating.
Related reading
01 · Category
Market Size11 stats
Market Size Interpretation
02 · Category
Industry Trends8 stats
Industry Trends Interpretation
03 · Category
Security Operations5 stats
Security Operations Interpretation
More related reading
04 · Category
Cloud & Identity2 stats
Cloud & Identity Interpretation
05 · Category
Third Party Risk2 stats
Third Party Risk Interpretation
06 · Category
Industry Overview6 stats
Industry Overview Interpretation
Security market size and incident pressure
A snapshot of the security landscape spans large spend forecasts alongside major incident volumes and remediation activity.
Cite This Report
This report is designed to be cited. We maintain stable URLs and versioned verification dates. Copy the format appropriate for your publication below.
Kevin O'Brien. (2026, February 13). Security Statistics. Gitnux. https://gitnux.org/security-statistics
Kevin O'Brien. "Security Statistics." Gitnux, 13 Feb 2026, https://gitnux.org/security-statistics.
Kevin O'Brien. 2026. "Security Statistics." Gitnux. https://gitnux.org/security-statistics.
Sources & references
34 datasets cited across this report · attribution is report-level
+15 additional datasets cited (not shown individually)

