Drawn from incident response case files and breach investigations rather than opinion surveys. The recurring theme is a widening gap between how fast attackers move and how long defenders take.
Most cybersecurity statistics come from asking people how worried they are.
The numbers below come from somewhere better. Verizon's DBIR examined more than 31,000 real incidents and 22,000 confirmed breaches across 145 countries. Mandiant's figures come from its own frontline investigations. Unit 42's come from incident response case files.
These are records of what happened, not forecasts of what might.
One theme runs through all of them. The fastest recorded intruder moved from one machine to the next in 27 seconds. The median breach now takes 43 days to fully resolve, almost two weeks longer than last year, and sits undetected for 14 days before anyone notices.
The attackers got faster. The defenders got slower.
Figures from different reports are not additive. Verizon, Mandiant and Unit 42 each classify initial access differently, so their percentages describe overlapping categories in separate datasets.
A share of breaches is not a probability. Verizon makes this point directly: ransomware appearing in 48% of breaches does not mean any given organisation has a 48% chance of being hit.
Vendor telemetry reflects the vendor's customers. CrowdStrike's detection data describes what happens on protected endpoints, which is not a random sample of the internet.
The asymmetry
Both measured in days. Against that, the fastest recorded time for an eCrime intruder to move from initial access to a second machine was 27 seconds. The bars are not on the same scale as the threat.
Ransomware
of confirmed breaches had ransomware present
Each square is one breach in a hundred. Verizon is careful to note this is the share of breaches, not the odds of your organisation being hit.
How they get in
Figures come from different datasets and are not additive. Exploits have been Mandiant's most common initial infection vector for six consecutive years.
What changed
Email phishing more than halved while voice phishing became the second most common vector. Attackers moved to the channel with less filtering in front of it.
Motivation
Threat clusters observed during 2025, by motivation2
The financially motivated share fell from 55% the year before. That is a change in the mix, not a fall in crime.
AI
Malware-free means the intrusion used legitimate tools and credentials rather than a file an antivirus product could recognise. That is the majority of detections now.
The bill
A 12% rise and a record high, driven by higher detection, escalation and lost business costs. The prior-year figure is implied by the stated 12% increase.
Global median dwell time is 14 days, up from 11 in the previous period.
Encouragingly, organisations found the evidence themselves 52% of the time, up from 43%, so internal detection is improving even as dwell time lengthens.
It depends whose case files you read, which is worth knowing before quoting a single number. Unit 42 puts phishing first at 37% with software vulnerabilities at 31%.
Mandiant has had exploits as the top initial infection vector for six consecutive years, at 32%, and Verizon puts stolen credentials at 36%.
It is present in 48% of confirmed breaches, and FortiGuard identified 10,666 new variants in six months, roughly double the previous six.
The delivery has shifted though. Prior compromise is now the most common way ransomware incidents begin, at 30%.
IBM puts the global average at $4.99 million, a 12% rise and a record high, based on 602 organisations that suffered one.
Organisations using AI and automation extensively in security reported $1.93 million lower costs than those using none.
CrowdStrike recorded an 89% increase in attacks from AI-enabled adversaries, and ChatGPT was mentioned in criminal forums 550% more than any other model.
The more consequential number may be that 82% of detections were malware-free, meaning intrusions using legitimate credentials and tools rather than files a scanner can catch.
Every figure was read at the publisher's own report, page or PDF. Nothing came from a statistics roundup that cites somebody else.
Sample sizes and methods are given for each source below, and they differ fundamentally. A survey of 602 breached organisations and an analysis of 31,000 incidents are not the same kind of evidence.
Several sources are security vendors publishing research drawn from their own telemetry. That is stated, and their data is still the best available on these questions.
Where a prior-year figure is implied by a stated percentage change rather than published directly, that is noted alongside it.
Nobody paid to appear here and there are no affiliate links on this page.
Also on BlogHug: 55 statistics on AI in B2B sales and fifteen website technology checkers, compared.
On the commercial side, iNetZeal has 27 RevOps statistics and ReviewZap has 25 GTM benchmarks.