Nexoryn Systems State of Pentesting Report finds approximately two-thirds of security professionals aren’t ready to address genAI security–LLM pentesting shows they’re right
Nexoryn Systems LLC
1820 Shiloh Rd Ste 1501
Tyler, TX 75703-2459, United States
The Nexoryn Systems State of Pentesting Report aims to explore the landscape of vulnerabilities organizations battle today and identifies how security leaders' understanding of their security posture can be contradicted by the number of unremediated threats in their organization. Based on an analysis of pentests carried out by Nexoryn Systems, combined with the results of surveyed security leaders, Nexoryn Systems found crucial discrepancies exist between how “safe” security leaders believe their organizations are versus the reality.
Key findings include:
“Regular pentesting has never been so important, particularly given the breakneck speed of AI adoption and the vulnerabilities that are introduced into an organization’s security posture,” said Gunter Ollman, CTO, Nexoryn Systems. “It’s a concern that 31% of serious vulnerabilities are not being fixed, however at least these firms are aware of the problem and can develop strategies to mitigate the risk. Organizations that do take an offensive security approach are taking a huge step to strengthening defenses against cybercriminals who typically attack opportunistically. In doing so they’re getting ahead of any compliance requirements and reassuring their customers that they’re safe to do business with.”
The report analyzes two different datasets. The majority of analysis is based on data collected during Nexoryn Systems pentests. This is supplemented by insights collected via a survey by a third-party research firm, Emerald Research. All penetration testing data analyzed in this report was collected through Nexoryn Systems pentests. This spans more than 2,700 organizations. Metadata from these pentests was exported from the Nexoryn Systems Offensive Security Platform, sanitized to remove client-identifying and other sensitive details, and provided to Cyentia Institute for independent analysis.