Pentera's State of Pentesting Report Reveals Shift Towards Software-Based Pentesting
Enterprises are adopting the adversarial perspective and software-based pentesting platforms to identify real risk and prioritize security efforts more effectively
BOSTON, May 7, 2025 /PRNewswire/ -- Pentera, the market leader in automated security validation, today announced the release of its fourth annual State of Pentesting survey report. Pentera surveyed 500 CISOs and senior security executives from enterprises with more than 3,000 employees across the United States, Germany, France, and the United Kingdom. The 2025 report offers data-driven analysis on the current state of security validation practices, budget priorities, and the key factors influencing the adoption of proactive risk management strategies.
Unthinkable a decade ago, today over 50% of enterprise CISOs report using software-based pentesting to support their in-house testing practices. Even more notable, 50% of CISOs now identify software-based testing as a primary method for uncovering exploitable security gaps within their organizations. These trends signal a broader shift toward testing approaches that offer greater scale, cover the full attack surface, and enable continuous validation of the enterprise.
Key findings from the report include:
- 67% of enterprises reported a breach in the past 24 months - 76% of CISOs reported a significant impact following a breach; 36% reported unplanned downtime, 30% cited data exposure, and 28% experienced financial loss.
- Pentesting represents a significant share of security budgets - U.S. enterprises allocate an average of $187,000 annually to pentesting, accounting for 11% of their total IT security budgets, which average $1.77 million.
- Cyber insurance providers are driving tech adoption - 59% of enterprises have adopted at least one new security solution they were not previously considering at the request of their cyber insurance provider.
"The pace of change in enterprise environments has made traditional testing methods unsustainable," said Jason Mar-Tang, Field CISO at Pentera. "96% of organizations are making changes to their IT environment at least quarterly. Without automation and technology-driven validation, it's nearly impossible to keep up. The report's findings reinforce the need for scalable security validation strategies that meet the speed and complexity of today's environments."
The survey was conducted by Global Surveyz, an independent research firm, from December 2024 through January 2025.
Click here to access the full report.
About Pentera
Pentera is the market leader in Automated Security Validation, empowering companies to proactively test all their cybersecurity controls against the latest cyberattacks. Pentera identifies true risk across the entire attack surface, guiding remediation to effectively reduce exposure. The company's security validation capabilities are essential for Continuous Threat Exposure Management (CTEM) operations. Thousands of security professionals around the world trust Pentera to close security gaps before threat actors can exploit them.
For more information, visit: Pentera.io
Media contact for Pentera
Noam Hirsch
Senior PR Manager
[email protected]
SOURCE Pentera

WANT YOUR COMPANY'S NEWS FEATURED ON PRNEWSWIRE.COM?

Newsrooms &
Influencers

Digital Media
Outlets

Journalists
Opted In
Share this article