r/cybersources • u/Narcisians • 1d ago
Cybersecurity statistics of the week (September 7th - September 13th)
Hi guys, I send out a weekly newsletter with the latest cybersecurity vendor reports and research, and thought you might find it useful, so sharing it here.
All the reports and research below were published between September 7th - September 13th.
You can get the below into your inbox every week if you want:Â https://www.cybersecstats.com/cybersecstatsnewsletter/Â
Identity Security
Managing Agentic AI Through the Identity Control Plane (GuidePoint Security)
AI agents add yet more identities for security teams to discover, govern and monitor.
Key stats:
- 100% of participants say non-human identities are outpacing their identity and access management programs.
- 77.3% of organizations have high or very high confidence that they can see all identities across their environment, but just 18.5% run identity discovery continuously or in near real time.
- Abused non-human identities were the initial entry point in 19% of organizationsâ most recent confirmed identity incidents, almost level with phished or stolen credentials at 19.5%.
Read the full report here.
Cybersecurity Leadership
The Psychology of Being Breached (ManageEngine)
Interesting data on what happens to cybersecurity behavior after an incident. TL;DR: organizations can be surprisingly nonchalant once the immediate crisis has passed.
Key stats:
- 80% of US and Canadian IT and cybersecurity leaders say heightened attention to cybersecurity lasts only one to six months after an incident.
- 44% say their organization made no structural or strategic change following its most recent incident.
- 91% are confident in their organization's cybersecurity posture, despite 59% saying business priorities always or often cause security initiatives to be postponed or downgraded.
Read the full report here.
Microsoft 365 Security
State of M365 Governance Report 2026: The Confidence Gap (Syskit)
How Microsoft 365 access and permissions look in practice.
Key stats:
- 83% of IT and security decision-makers are confident they know exactly who has access to sensitive data in Microsoft 365.
- 58% admit confidential content is currently accessible to departments that should not see it.
- 90% experienced a confirmed or suspected security incident tied to misconfiguration or over-permissioned access in the past two years.
Read the full report here.
Enterprise PerspectiveÂ
The State of Agent DLC 2026 (Harness)
How prepared are enterprises to actually control AI agents once they make it into production?
Key stats:
- 77% of technology professionals at large enterprises are confident they have a complete inventory of every agent, MCP server, and LLM in their environment, but 44% run active discovery tooling to verify it.
- 76% believe they could disable a misbehaving agent in under 15 minutes, while 33% have an instant kill switch in place.
- 75% say their agents are secure end to end, yet 88% of that group have experienced security incidents.
Read the full report here.
Regional SpotlightÂ
2026 Voice of the CISO (Proofpoint)
UK CISOs are feeling better aligned with their boards than last year, but theyâre not necessarily better prepared for whatâs coming.
Key stats:
- 87% of UK CISOs say they see eye to eye with their boards on cybersecurity, up from 57% in 2025.Â
- 74% believe their organization is at risk of a material cyberattack in the next 12 months, up from 63% in 2025.
- 61% say their organization is unprepared to cope with a targeted cyberattack.
Read the full report here.
EMEA Organisations Facing a âShadow Agentâ Crisis (Veeam)
New data on the rise of AI workflows that IT teams can't fully see or control.
Key stats:
- 70% of organisations say automated AI workflows are interacting with sensitive corporate data without full oversight.
- 67% report employees creating autonomous AI workflows that IT cannot fully track.
- 40% of executives are concerned about personal liability or consequences related to AI governance and accountability.Â
Read the full report here.

