Secure every application with flexible pentesting that combines expert-led testing, autonomous validation, and actionable results.
Learn moreIdentify exploitable risk across external networks, internal infrastructure, and cloud environments.
Learn moreExtend your offensive security program with specialized assessments, adversarial testing, code review, and program-level support.
Learn moreHow much more likely programmatic teams are to resolve critical findings in three days or less compared to ad-hoc or compliance-driven teams.
The rate at which high-risk findings appear in AI/LLM tests compared to the overall dataset.
The additional window of risk exposure under-performers face compared to leaders.
This report provides the actionable intelligence necessary to bridge the disconnect between executive perception and practitioner reality, offering a roadmap for teams to transform their offensive security from a reactive burden into a strategic advantage.
Watch our experts dissect the remediation divide and learn how elite security teams neutralize high-risk findings, outpace machine-speed threats, and reduce total exposure windows.
A massive gap exists between leading organizations that integrate security and the laggard organizations that treat it as a periodic hurdle.
10 days: The half-life—how long vulnerabilities remain exploitable—of high-risk findings for top-performing teams.
249 days: The half-life—how long vulnerabilities remain exploitable—of high-risk findings for the bottom tier.
Innovation is outstripping defense as organizations rush to deploy LLM-backed features without a matching security strategy.
32%: Percentage of all AI/LLM findings rated as High Risk.
38%: The resolution rate for AI vulnerabilities—the lowest of any category in our report.
Strategic process maturity is the single greatest predictor of remediation success.
45% vs. 10%: Organizations that take a programmatic approach to security testing resolve 4.5x more critical findings in under three days than compliance-driven teams.
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Phasellus imperdiet accumsan vehicula. Suspendisse dictum lorem ex, at laoreet ex fermentum eu. Nunc commodo ut magna a pellentesque.
The 2026 State of Pentesting Report is an annual research publication by Cobalt that provides deep insights into the offensive security landscape. Now in its eighth year, the report combines data from thousands of real-world penetration tests with a qualitative survey of 450 security leaders and practitioners, to identify why vulnerabilities persist and how leading teams resolve them.
The report draws from two primary datasets:
While multiple factors can be considered, this analysis is based on remediation of high-risk pentest findings—specifically the half-life of vulnerabilities (the number of days to remediate 50% of findings, including those that are still unfixed).
Yes, the State of Pentesting Report includes security recommendations based on best practices of top-performing organizations in the research. Key recommendations include: