Secure every application with flexible pentesting that combines expert-led testing, autonomous validation, and actionable results
Learn moreIdentify exploitable risk across external networks, internal infrastructure, and cloud environments
Learn moreExtend your offensive security program with specialized assessments, adversarial testing, code review, and program-level support
Learn moreFinancial services and insurance run security like the regulated sectors they are: programmatic, measured, and confident. This report combines five years of Cobalt pentest findings with a 2026 survey of 65 financial services and insurance security leaders and practitioners to profile how these sectors find, fix, and think about security risk.
48%
Test AI applications programmatically (highest of any sector)
9%
Have had an AI or LLM security incident (lowest of any sector)
55 days
High-risk vulnerability half-life, only mid-pack across 10 sectors
What’s Inside: