[Blog](/blog)

Show links

Resources

[Blog](/blog)

[Breaches](/breaches)

[eBooks, reports, & more](/resources)

[Events](/events)

[News](/news)

[Cybersecurity](/category/cybersecurity)

Show links

Categories

[Attack Surface Management](/category/attack-surface-management)

[Company News](/category/company-news)

[Compliance and Regulations](/category/compliance-and-regulations)

[Cybersecurity](/category/cybersecurity)

[Data Breaches](/category/data-breaches)

[DevOps](/category/devops)

[Human Cyber Risk](/category/human-cyber-risk)

[Risks and Vulnerabilities](/category/risks-and-vulnerabilities)

[Third-Party Risk Management](/category/third-party-risk-management)

[Vendor Risk Management](/category/vendor-risk-management)

[54 Cybersecurity Statistics Technology Companies Need To Know](/blog/cybersecurity-statistics-technology)

Publish date

November 30, 2025

{x} minute read

# 54 Cybersecurity Statistics Technology Companies Need To Know

[Get a demo](/contact-sales)

[Free trial](/demo)

[Download the PDF guide](/resources/critical-cybersecurity-threats-and-kpis-for-every-business)

[Free trial](/demo)

Written by

[Nicholas Sollitto](/team/nicholas-sollitto)

Senior Cybersecurity Writer

Nicholas's cybersecurity writing has been featured in G2.

Reviewed by

[Kaushik Sen](/team/kaushik-sen)

Chief Marketing Officer

Kaushik has a background in software engineering, enterprise solution architecture, and data analytics. He brings a unique, data-driven perspective to cybersecurity education.

Table of contents

eBook

Critical cybersecurity threats and KPIs for every business

Free resource

### Critical cybersecurity threats and KPIs for every business

[Download now](/resources/critical-cybersecurity-threats-and-kpis-for-every-business)

Severe [cyber threats ](https://www.upguard.com/blog/cyber-threat)often threaten the technology sector because of the level of [sensitive data](https://www.upguard.com/blog/sensitive-data) companies and their [third-party vendors](https://www.upguard.com/blog/third-party-vendor) process and store. Developing a comprehensive awareness of [cybersecurity trends](https://www.upguard.com/blog/tprm-trends) is one of the easiest ways for tech companies to protect themselves from cybercriminals, scams, and other [cybersecurity threats](https://www.upguard.com/blog/cyber-attack).

Keep reading to discover 54 cybersecurity statistics your technology organization should know along with the most prevalent cybersecurity risks threatening the tech sector.

[Learn how UpGuard helps tech organizations scale securely >](https://www.upguard.com/industries/technology)

## Top Cybersecurity Breach Statistics To Know

Alongside the [healthcare industry](https://www.upguard.com/industries/healthcare), the tech sector (including FinTech providers specializing in [financial services](https://www.upguard.com/industries/financial-services)) ranks as one of the most susceptible industries to [data breaches](https://www.upguard.com/blog/biggest-data-breaches). In the past, data breaches have inflicted devastating consequences on large enterprises and small businesses in the tech sector. Organizations that have fallen victim to a breach have incurred damages to their reputation, stability, and financial health.

In 2023, the average cost of a data breach was $4.45 million, according to a [report](https://www.ibm.com/reports/data-breach) developed by IBM and the Ponemon Institute.

Other intriguing statistics from the 2023 IBM report include the following:

* The average cost of a data breach increased by 22% year-over-year
* The average cost of a data breach in the tech sector was $4.66 million
* The average cost of a data breach for companies with fewer than 500 employees was $3.31 million
* 52% of data breaches compromised [customer PII](https://www.upguard.com/blog/personally-identifiable-information-pii), including customer names, credit card numbers, and other information
* 40% of data breaches compromised employee PII
* Only 33% of data breaches were identified by an organization’s internal security team
* The average time to identify and contain a data breach was 277 days
* 20% of organizations that experienced a data breach paid 250,000 or more in fines

## Notable Data Breaches in the Tech Sector

The tech sector has witnessed several significant data breaches in recent years. The following breaches are some of the most damaging that have occurred since 2020:

* **Microsoft (January 2021):** Hackers exploited four different zero-day vulnerabilities to compromise 60,000 accounts worldwide, including multiple government agencies.
* **Facebook (April 2021):&#x20;**&#x43;ybercriminals exposed the personal data of 530 million users by exploiting a vulnerability in the social media platform’s “sync mobile device contacts” tool.
* **LinkedIn (April 2021):** Hackers scraped the LinkedIn platform and stole over 700 million user records, including phone numbers and geolocation data.
* **Yahoo (2013 - 2016):&#x20;**&#x43;ybercriminals in Russia used backdoors and stolen backups to access and steal user records containing [personally identifiable information (PII)](https://www.upguard.com/blog/personally-identifiable-information-pii).

**Recommended Reading:** [Biggest Data Breaches in US History](https://www.upguard.com/blog/biggest-data-breaches-us)

## Cybercrime Stats

The technology industry is susceptible to various forms of cybercrime due to its reliance on digital infrastructure, extensive third-party [supply chains](https://www.upguard.com/blog/supply-chain-attack), and valuable personal data. The tech sector must maintain robust information security programs to prevent cybercrime, deter hackers and other cybercriminals, and protect [sensitive information](https://www.upguard.com/blog/protecting-sensitive-data).

In 2022, cybercrime caused more than $10.3 Billion in damages, according to a [report](https://www.statista.com/forecasts/1280009/cost-cybercrime-worldwide) charting the monetary impact of cybercrime from 2002 to 2022 by Statista.

The most common forms of cybercrime affecting the tech industry include:

* [**Malware**](https://www.upguard.com/blog/malware)**:** Software that executes unauthorized actions on a system user’s account
* [**Phishing Attacks**](https://www.upguard.com/blog/phishing)**:&#x20;**&#x53;ocial engineering attack that targets a user’s credentials through an email, text message, or phone call
* [**Ransomware Attacks:**](https://www.upguard.com/blog/ransomware)**&#x20;**&#x41; type of malware attack that locks and encrypts a user’s data
* [**DDoS (Denial of Service) Attacks:**](https://www.upguard.com/blog/what-is-a-ddos-attack)**&#x20;**&#x41; type of attack that overwhelms a system and prevents access by flooding infrastructure with localized traffic[**‍**](https://www.upguard.com/blog/business-email-compromise)
* [**BEC (Business Email Compromise) Attacks:**](https://www.upguard.com/blog/business-email-compromise)**&#x20;**&#x41; specific type of spear phishing attack that attempts to trick employees into harmful actions against the organization

## Cybersecurity Statistics By Type of Cyber Attack

By understanding cyber attack trends, your organization will be better prepared to prevent subsequent attacks. Learning more about the consequences and frequency of various cyber attack methods will allow your organization to improve its decision-making and allocate resources appropriately.

### Malware Attack Statistics

Here are the most intriguing [malware](https://www.upguard.com/blog/types-of-malware) statistics every tech organization should be aware of in 2025:

* 560,000 new pieces of malware are sent by threat actors every 24 hours ([Statista](https://www.statista.com/topics/8338/malware/#topicOverview), 2023)
* Over the past decade, the total number of malware attacks has increased by 87% (Statista, 2023)
* In 2022,[ 5.5 Billion malware attacks](https://www.statista.com/statistics/873097/malware-attacks-per-year-worldwide/) were deployed (Statista, 2023)
* Every minute, four companies fall victim to a malware attack ([DataProt](https://dataprot.net/statistics/malware-statistics/), 2023)
* Trojan horses account for 58% of all malware attacks (DataProt, 2023)

### Phishing Attack Statistics

Here are several critical [phishing](https://www.upguard.com/blog/types-of-phishing-attacks) statistics you should know:

* 84% of companies experienced at least one phishing attempt in 2021 ([State of the Phish](https://www.proofpoint.com/us/resources/threat-reports/state-of-phish), 2022)
* In 2023, phishing was the initial [attack vector](https://www.upguard.com/blog/attack-vector) in 16% of data breaches (IBM)
* Phishing attacks increased by 45% year-over-year (State of the Phish, 2022)
* 3 Billion phishing emails are sent every day ([ZDNET](https://www.zdnet.com/article/three-billion-phishing-emails-are-sent-every-day-but-one-change-could-make-life-much-harder-for-scammers/), 2021)
* 1.2 % of all emails sent are malicious (ZDNET, 2021)
* 22% of data breaches are caused by phishing scams ([FBI](https://www.ic3.gov/Media/PDF/AnnualReport/2021_IC3Report.pdf), 2021)

### Ransomware Attack Statistics

Here are six [ransomware](https://www.upguard.com/blog/ransomware-examples) statistics affecting cybersecurity industry:

* Ransomware attacks accounted for more than $49.2 million in losses (FBI, 2021)
* 24% of all cyber attacks involve ransomware ([Verizon](https://www.verizon.com/business/resources/infographics/2023-dbir-infographic.pdf), 2023)
* In 2022, the average ransom amount was $1.54 million ([Sophos](https://www.sophos.com/en-us/whitepaper/state-of-ransomware), 2023)
* On average, an affected company experiences 22 days of downtime after a ransomware attack ([Statista,](https://www.statista.com/statistics/1275029/length-of-downtime-after-ransomware-attack-global/#:~:text=Length%20of%20impact%20after%20a%20ransomware%20attack%20Q1%202020%2D%20Q3%202021\&text=As%20of%20the%20third%20quarter,United%20States%20was%2022%20days.) 2021)
* REvil, a malicious ransomware group, accounted for 37% of all ransomware attacks in 2021 ([AAG](https://aag-it.com/the-latest-ransomware-statistics/), 2023)
* 93% of all ransomware is Microsoft Windows-based (AAG, 2023)

### DDoS Attack (Denial of Service) Statistics

The cybersecurity market has perceived [denial of service](https://www.upguard.com/blog/what-is-a-ddos-attack) attacks as a significant threat for many years. Here are several statistics that showcase the effect DDoS attacks can have:

* 15 million infected IP addresses are hijacked by bots worldwide ([G2](https://learn.g2.com/ddos-attack-statistics#:~:text=In%202022%2C%20the%20rate%20of,increased%20by%20332%25%20in%202022.), 2023)
* From 2021 to 2022, DDoS attacks rose by 67% (G2, 2023)
* 18.3% of all DDoS attacks targeted United States-based infrastructure ([Station X](https://www.stationx.net/ddos-statistics/), 2023)
* 4 million DDoS attacks over the last 40 years have lasted more than one hour ([NetScout](https://www.netscout.com/threatreport/ddos-threat-intelligence-report/), 2023)
* 1 million DDoS attacks in the previous 40 years have lasted more than 12 hours (NetScout, 2023)

### BEC (Business Email Compromise) Attack Statistics

[Business Email Compromise (BEC) scams](https://www.upguard.com/blog/business-email-compromise) are on the rise. Here are five BEC attack statistics your organization needs to know to develop protective cybersecurity measures:

* 28% of all BEC scams are opened by employees ([Abnormal](https://abnormalsecurity.com/blog/28-of-bec-attacks-opened-by-employees), 2023)
* 2.1% of all BEC scams are reported by employees (Abnormal, 2023)
* From 2013 to 2022, BEC scams exploited over 137,000 U.S. victims ([FBI](https://www.ic3.gov/Media/Y2023/PSA230609), 2023)
* From 2013 to 2022, BEC scams stole over 17 Billion from American companies and citizens (FBI, 2023)
* From 2017 to 2020, 52,842 BEC attempts were recorded worldwide (Statista, 2022)

## Internet of Things (IoT) Cybersecurity Stats

Over the last decade, [IoT devices](https://www.upguard.com/blog/internet-of-things-iot) have surged in use. These devices provide organizations with many benefits, including streamlining processes, improving convenience, and reducing costs. However, IoT devices are also susceptible to various cyber threats. Organizations utilizing IoT devices must be aware of the risks.

* Over 15 Billion IoT devices were in use globally in 2023 ([Statista](https://www.statista.com/statistics/1183457/iot-connected-devices-worldwide/), 2023)
* By 2030, the number of IoT devices used worldwide is expected to surpass 29 Billion (Statista, 2023)
* 25% of all cyber attacks will involve IoT devices ([Gartner](https://www.gartner.com/imagesrv/books/iot/iotEbook_digital.pdf), 2018)
* In 2022, more than 112 million cyber attacks targeted IoT devices ([Statista](https://www.statista.com/statistics/1377569/worldwide-annual-internet-of-things-attacks/), 2023)

## Remote Work Attack Statistics

Spurred by the COVID-19 pandemic and technological advancements such as IoT devices, remote authentication apps, and automation services, remote work has become a legitimate alternative to standard on-premise reporting for many organizations. These organizations need to know the following statistics to develop security procedures to protect their remote workers and business operations.

* 20% of organizations experience a data breach caused by a remote worker ([LinkedIn](https://www.linkedin.com/pulse/what-security-risks-remote-working-thesecurityco-1imge/), 2023)
* Remote work has increased the average cost of a data breach by $137,000 ([LinkedIn](https://www.linkedin.com/pulse/remote-work-cyber-security-challenges-2022-prabhu-kiran-veesam/), 2022)
* In April 2020, more than 500,000 Zoom passwords were sold on the dark web ([Forbes](https://www.forbes.com/sites/daveywinder/2020/04/28/zoom-gets-stuffed-heres-how-hackers-got-hold-of-500000-passwords/), 2020)
* Between January and April 2020, cyberattacks on cloud services increased by 630% ([HIPAA Journal](https://www.hipaajournal.com/attacks-on-cloud-services-increased-by-630-jan-apr-2020/), 2020)

## Cryptocurrency Scam Statistics

Between 2020 and 2021, the [cryptocurrency market](https://www.upguard.com/blog/the-role-of-cybersecurity-in-blockchain-technology) surged unprecedentedly. However, since 2021, notable events like the collapse of FTX (Nassau-based cryptocurrency exchange) have altered the perception of crypto from intrigue to apprehension. Throughout the fourth quarter of 2023, the crypto market has shown a slight resurgence, yet persistent risks—such as volatility, regulatory uncertainty, scams, and [security vulnerabilities](https://www.upguard.com/blog/vulnerability-management)—remain.

* From 2021 to the first half of 2022, 46,000 people reported losing money to a crypto scam ([FTC](https://www.ftc.gov/news-events/data-visualizations/data-spotlight/2022/06/reports-show-scammers-cashing-crypto-craze#crypto1), 2022)
* $3.8 Billion in cryptocurrency was stolen by cybercriminals in 2022 ([Chainalysis](https://www.chainalysis.com/blog/2022-biggest-year-ever-for-crypto-hacking/), 2023)
* DeFi protocols accounted for 82.1% of all crypto-based attacks in 2022 ([Persona](https://withpersona.com/blog/cryptocurrency-theft-statistics), 2023)
* The Ronin spyware attack stole 173,000 Ethereum (worth $595 million at the time) in March 2022 (Persona, 2023)
* 140 million crypto-hacking attempts were deployed in 2022 ([Statista](https://www.statista.com/statistics/1377860/worldwide-annual-number-cryptojacking/), 2023)

## Zero-Trust Statistics

As IoT devices, remote work, and cyber attacks rise, security teams deploy [zero-trust security models ](https://www.upguard.com/blog/zero-trust)to challenge traditional “trust but verify” principles and develop robust cyber protections. Overall, here is how [zero-trust](https://www.upguard.com/blog/prevent-supply-chain-attacks-with-zero-trust-architecture) stacks up against common cybercriminals:

* On average, zero trust reduces the cost of a data breach by $1 million ([IBM](https://www.ibm.com/reports/data-breach), 2023)
* 47% of SMEs are using multi-factor authentication ([Jumpcloud](https://jumpcloud.com/blog/top-zero-trust-security-stats), 2023)
* 21% of security professionals use more than 100 systems to manage digital identities ([Solutions Review](https://solutionsreview.com/identity-management/one-identity-organizations-want-a-unified-identity-management-solution/), 2021)
* 72% of security leaders in Europe have implemented cloud access security brokers ([Fortinet](https://www.fortinet.com/blog/industry-trends/zero-trust-report-key-takeaways), 2023)

## How Does UpGuard Help the Tech Sector

UpGuard helps technology security teams with [external attack surface](https://www.upguard.com/blog/what-is-external-attack-surface-management) monitoring, [third-party risk management](https://www.upguard.com/blog/third-party-risk-management), incident response, data security, and other cybersecurity ventures.

UpGuard’s cybersecurity toolkit includes two comprehensive products: UpGuard Vendor Risk ([Third-Party Risk Management software](https://www.upguard.com/product/vendor-risk/third-party-risk-assessments)) and UpGuard Breach Risk (first-party attack surface monitoring).

Cybersecurity professionals using UpGuard can access these powerful tools:

* [**Data Leak Detection**](https://www.upguard.com/product/breach-risk/threat-monitoring)**:** Prevent data leakage due to breaches, phishing attempts, identity theft, ransomware, endpoint vulnerabilities, human error, and other cyber threats
* [**Security Ratings**](https://www.upguard.com/product/security-ratings)**:** Understand your organization’s and your vendor’s security posture
* [**Vendor Risk Assessments**](https://www.upguard.com/product/risk-assessments)**:** Reduce the time it takes to assess new and existing vendors[**‍**](https://www.upguard.com/product/vendorrisk/features#vendor-tiering)
* [**Vendor Tiering**](https://www.upguard.com/product/vendorrisk/features#vendor-tiering)**:** Classify vendors based on their level of inherent cyber risk and your organization’s unique risk tolerance[**‍**](https://www.upguard.com/product/reporting)
* [**Compliance Reporting**](https://www.upguard.com/product/reporting)**:** Map vendor details against common compliance frameworks (NIST, ISO 27001, PCI, etc.) and initiatives[ **‍**](https://www.upguard.com/product/data-leak-detection)[**‍**](https://www.upguard.com/product/vendorrisk/features#security-ratings-section)
* [**24/7 Continuous Monitoring:**](https://www.upguard.com/product/vendorrisk/features#security-ratings-section) Receive real-time updates when security incidents affect your security rating or the security rating of one of your third-party vendors
* ‍[**Third-party integrations:**](https://www.upguard.com/integrations) Configure UpGuard within your existing security tools and web applications

eBook

Critical cybersecurity threats and KPIs for every business

Free resource

### Critical cybersecurity threats and KPIs for every business

[Download now](/resources/critical-cybersecurity-threats-and-kpis-for-every-business)

## Related posts

Learn more about the latest issues in cybersecurity.

Cybersecurity

#### [Left Unsupervised: 10 Times Access Outlived Its Authorization](/blog/10-times-access-outlived-authorization)

Access granted once shouldn’t mean access forever. Read more on how unmonitored access caused 10 of these real-life breaches and what they taught us.

[](/team/revashni-moodley)

[Revashni Moodley](#)

August 25, 2026

Cybersecurity

#### [Surviving a LockBit Ransomware Attack: The ROI of Visibility](/blog/surviving-a-lockbit-ransomware-attack)

Read how veteran CISO Nick Gicinto saved his alma mater from a LockBit ransomware attack by discarding the standard playbook.

[](/team/nicholas-sollitto)

[Nicholas Sollitto](#)

June 1, 2026

Cybersecurity

#### [Top 10 Security Events of 2025](/blog/top-security-events-of-2025)

Recap the ten most impactful events that reshaped the cybersecurity industry this year and the critical lessons each had to teach us. Read more here.

[](/team/revashni-moodley)

[Revashni Moodley](#)

January 7, 2026

Cybersecurity

#### [Risk Automations: The Shift From Catch-Up to Command](/blog/risk-automations-shift-catch-up-to-command)

Connect intelligence to system execution with Risk Automations, your new resolution layer for risk. Reduce remediation from hours to seconds - read more.

[](/team/revashni-moodley)

[Revashni Moodley](#)

December 1, 2025

Cybersecurity

#### [Shai-Hulud's True Lesson for CISOs: A Crisis of Communication](/blog/shai-hulud-lesson-for-cisos)

Shai-Hulud was driven by a communication crisis between security and engineering. Get a CISO's perspective on how to finally bridge this gap.

[](/team/phil-ross)

[Phil Ross](#)

September 3, 2026

Cybersecurity

#### [UpGuard’s Updated Cyber Risk Ratings](/blog/cyber-risk-ratings-2024)

Discover UpGuard's updates to its cyber risk ratings, including enhanced risk categorization and an improved scoring algorithm.

[](/team/nicholas-sollitto)

[Nicholas Sollitto](#)

July 4, 2025

[All posts](/blog)

Experience superior visibility and a simpler approach to cyber risk management

[Get a demo](/contact-sales)

[Free trial](/demo)
