Sources
Every third-party statistic on this site comes from a published source. We show the wording we checked, link the original, and date our last check.
Home page
-
A 2025 peer-reviewed ACM CCS study says reliable broken-access-control detection remains limited; in its benchmark, a commercial scanner with an authorization extension caught 54% of 57 unauthorized-modification flaws.Source: Liu et al., ACM CCS 2025, BACScan: Automatic Black-Box Detection of Broken-Access-Control Vulnerabilities in Web Applications (2025) (PDF)
Checked October 7, 2026
-
OWASP’s Web Security Testing Guide says business-logic flaws “cannot be detected by a vulnerability scanner.”Source: OWASP Foundation, Web Security Testing Guide v4.2: Introduction to Business Logic (2020)
Checked October 7, 2026
-
Verizon 2026 DBIR: “Exploitation of vulnerabilities is now the most common initial access vector for breaches. It has risen to 31%.”Source: Verizon Business, 2026 Data Breach Investigations Report: Executive Summary (2026) (PDF)
Checked October 7, 2026
-
IBM Cost of a Data Breach Report 2026: offensive security testing (red teaming, pen or vulnerability testing) was associated with breach costs USD 211,339 below the USD 4.99M global average.Source: IBM and Ponemon Institute, Cost of a Data Breach Report 2026 (2026) (PDF)
Note: IBM reports an association, not cause and effect.
Checked October 7, 2026
-
NIST SP 800-53 Rev. 5 (CA-8) says penetration testing “goes beyond automated vulnerability scanning.”Source: NIST, SP 800-53 Rev. 5: Security and Privacy Controls for Information Systems and Organizations, control CA-8 (2020) (PDF)
Checked October 7, 2026
Web application penetration testing
-
IBM X-Force 2026: exploitation of public-facing applications was the leading initial access vector in 2025 (40% of cases; such incidents rose 44%).Source: IBM X-Force, X-Force Threat Intelligence Index 2026: Top initial access vectors (2026)
Checked October 7, 2026
-
The OWASP Top 10:2025 keeps Broken Access Control at #1, and OWASP notes its data is ‘largely limited to what the industry can test for in an automated fashion.’Source: OWASP Foundation, OWASP Top 10:2025, Introduction (2025)
Checked October 7, 2026
API penetration testing
-
OWASP Top 10:2025 ranks Broken Access Control #1. It has the most occurrences of any category in OWASP’s contributed data (1,839,701).Source: OWASP Foundation, OWASP Top 10:2025, A01 Broken Access Control (2025)
Note: Occurrences count applications with at least one instance of a related weakness, summed across weaknesses. They aren’t individual bugs.
Checked October 7, 2026
-
A 2025 peer-reviewed ACM CCS study says reliable broken-access-control detection remains limited; in its benchmark, a commercial scanner with an authorization extension caught 54% of 57 unauthorized-modification flaws.Source: Liu et al., ACM CCS 2025, BACScan: Automatic Black-Box Detection of Broken-Access-Control Vulnerabilities in Web Applications (2025) (PDF)
Checked October 7, 2026
Network penetration testing
-
Mandiant M-Trends 2026: exploits led initial infection vectors for a sixth straight year (32% of cases with an identified vector).Source: Mandiant / Google Cloud, M-Trends 2026: Data, Insights, and Strategies From the Frontlines (2026) (PDF)
Note: Based on Mandiant incident-response investigations in 2025.
Checked October 7, 2026
-
NIST SP 800-115 notes most penetration tests seek combinations of vulnerabilities granting more access than any single flaw, and manual analysis can identify new or obscure vulnerabilities scanners may miss.Source: NIST, SP 800-115: Technical Guide to Information Security Testing and Assessment (2008) (PDF)
Checked October 7, 2026
Cloud penetration testing
-
Google Cloud Threat Horizons H1 2026: identity issues gave attackers initial access in 83% of Mandiant-handled cloud/SaaS incidents (H2 2025).Source: Google Cloud, Cloud Threat Horizons Report H1 2026 (2026)
Note: Covers cloud and SaaS incidents Mandiant handled in the second half of 2025, not all cloud incidents.
Checked October 7, 2026
AI and LLM penetration testing
-
IBM (2026): 21% of breached organizations reported an AI model or application incident, up from 13%; 92% of those lacked proper AI access controls.Source: IBM and Ponemon Institute, Cost of a Data Breach Report 2026 (2026) (PDF)
Note: The 21% is a share of the breached organizations IBM studied, not of all organizations.
Checked October 7, 2026
Red team and assumed-breach testing
-
Mandiant M-Trends 2026: global median dwell time rose to 14 days; organizations found 52% of intrusions themselves (up from 43%); attackers revealed 14%. Mandiant recommends regular red-team emulation.Source: Mandiant / Google Cloud, Mandiant M-Trends 2026 Report, Executive Edition (2026) (PDF)
Checked October 7, 2026
-
IBM Cost of a Data Breach Report 2026: offensive security testing (red teaming, pen or vulnerability testing) was associated with breach costs USD 211,339 below the USD 4.99M global average.Source: IBM and Ponemon Institute, Cost of a Data Breach Report 2026 (2026) (PDF)
Note: IBM reports an association, not cause and effect.
Checked October 7, 2026
Phishing and social engineering testing
-
Mandiant M-Trends 2026: exploits led initial infection vectors for a sixth straight year (32% of cases with an identified vector); voice phishing rose to 11%, now second-most common.Source: Mandiant / Google Cloud, M-Trends 2026: Data, Insights, and Strategies From the Frontlines (2026) (PDF)
Note: Based on Mandiant incident-response investigations in 2025.
Checked October 7, 2026
Secure code review and threat modeling
-
A 2023 peer-reviewed ESEC/FSE study of seven free or open-source Java SAST tools found the best single tool detected only 12.7% of 165 real-world vulnerabilities; combined, 70.9% went undetected.Source: Li et al., ESEC/FSE 2023, Comparison and Evaluation on Static Application Security Testing (SAST) Tools for Java (2023)
Note: Free or open-source Java tools only.
Checked October 7, 2026
-
In a 2022 peer-reviewed case study on one web app, static analysis found the most vulnerabilities, exploratory manual pentesting found more severe ones, and each technique found issues others missed.Source: Elder et al., Empirical Software Engineering 27, Do I really need all this work to find vulnerabilities? An empirical case study comparing vulnerability detection techniques on a Java application (2022)
Note: One web application studied.
Checked October 7, 2026
Vulnerability assessments and scanning
-
Verizon 2026 DBIR: “Only 26% of critical vulnerabilities” (CISA KEV-listed) “were fully remediated by organizations in 2025,” and “the median time for full resolution went up to 43 days.”Source: Verizon Business, 2026 Data Breach Investigations Report: Executive Summary (2026) (PDF)
Note: Here ‘critical’ means listed in CISA’s KEV catalog.
Checked October 7, 2026
-
NIST SP 800-115 says application vulnerability scanners ‘typically have high false positive rates’ and high false negative rates; interpreting results requires ‘a high degree of human involvement.’Source: NIST, SP 800-115: Technical Guide to Information Security Testing and Assessment (2008) (PDF)
Checked October 7, 2026
Penetration testing for compliance
-
Verizon 2026 DBIR: “breaches with third-party involvement have increased by 60% from last year’s dataset, reaching 48% of total breaches.”Source: Verizon Business, 2026 Data Breach Investigations Report: Executive Summary (2026) (PDF)
Checked October 7, 2026
SOC 2 penetration testing
-
Verizon 2026 DBIR: “breaches with third-party involvement have increased by 60% from last year’s dataset, reaching 48% of total breaches.”Source: Verizon Business, 2026 Data Breach Investigations Report: Executive Summary (2026) (PDF)
Checked October 7, 2026
HIPAA penetration testing
-
NIST SP 800-115 notes most penetration tests seek combinations of vulnerabilities granting more access than any single flaw, and manual analysis can identify new or obscure vulnerabilities scanners may miss.Source: NIST, SP 800-115: Technical Guide to Information Security Testing and Assessment (2008) (PDF)
Checked October 7, 2026
ISO 27001 penetration testing
-
NIST SP 800-115 notes most penetration tests seek combinations of vulnerabilities granting more access than any single flaw, and manual analysis can identify new or obscure vulnerabilities scanners may miss.Source: NIST, SP 800-115: Technical Guide to Information Security Testing and Assessment (2008) (PDF)
Checked October 7, 2026
Penetration testing for customer security reviews
-
Verizon 2026 DBIR: “breaches with third-party involvement have increased by 60% from last year’s dataset, reaching 48% of total breaches.”Source: Verizon Business, 2026 Data Breach Investigations Report: Executive Summary (2026) (PDF)
Checked October 7, 2026
Penetration testing for cyber insurance
-
Verizon 2026 DBIR: “Exploitation of vulnerabilities is now the most common initial access vector for breaches. It has risen to 31%.”Source: Verizon Business, 2026 Data Breach Investigations Report: Executive Summary (2026) (PDF)
Checked October 7, 2026
-
2026 Breach Impact Study (US cyber-insurance): “half of all the reviewed paid-out claims had a financial impact greater than $83,000, with the top 10% having a more than $920,000 impact.”Source: Verizon Business, 2026 Breach Impact Study (2026)
Checked October 7, 2026
Approach
-
Edgescan’s 2026 Vulnerability Statistics Report found high and critical application/API vulnerabilities took an average of 54.81 days to remediate in 2025, based on its own assessments and pentests.Source: Edgescan, 2026 Vulnerability Statistics Report (2026)
Checked October 7, 2026
-
A 2025 peer-reviewed ACM CCS study says reliable broken-access-control detection remains limited; in its benchmark, a commercial scanner with an authorization extension caught 54% of 57 unauthorized-modification flaws.Source: Liu et al., ACM CCS 2025, BACScan: Automatic Black-Box Detection of Broken-Access-Control Vulnerabilities in Web Applications (2025) (PDF)
Checked October 7, 2026
-
A peer-reviewed 2025 NDSS paper says web scanners ‘still perform poorly or even fail’ at discovering deeper app states behind multi-step workflows like checkout, ‘leaving potential vulnerabilities undetected.’Source: Stafeev et al., NDSS 2025, YuraScanner: Leveraging LLMs for Task-driven Web App Scanning (2025) (PDF)
Checked October 7, 2026
-
In a 2022 peer-reviewed case study on one web app, static analysis found the most vulnerabilities, exploratory manual pentesting found more severe ones, and each technique found issues others missed.Source: Elder et al., Empirical Software Engineering 27, Do I really need all this work to find vulnerabilities? An empirical case study comparing vulnerability detection techniques on a Java application (2022)
Checked October 7, 2026
-
In a peer-reviewed 2010 study, all 11 web scanners missed 8 of 16 planted flaws, including a coupon logic flaw; students with average security skills found 15 of 16.Source: Doupé, Cova, and Vigna, DIMVA 2010, Why Johnny Can’t Pentest: An Analysis of Black-box Web Vulnerability Scanners (2010) (PDF)
Checked October 7, 2026
-
MITRE’s CWE-862 (Missing Authorization) rates automated static analysis ‘Limited,’ noting difficulty with ‘custom authorization schemes,’ and says ‘manual analysis is required’ to determine whether missing authorization violates business logic.Source: The MITRE Corporation, CWE-862: Missing Authorization (2026)
Checked October 7, 2026
-
NIST SP 800-115 notes most penetration tests seek combinations of vulnerabilities granting more access than any single flaw, and manual analysis can identify new or obscure vulnerabilities scanners may miss.Source: NIST, SP 800-115: Technical Guide to Information Security Testing and Assessment (2008) (PDF)
Checked October 7, 2026
-
NIST SP 800-53 Rev. 5 (CA-8) says penetration testing ‘goes beyond automated vulnerability scanning,’ is conducted by teams ‘with demonstrable skills and experience,’ and provides ‘a more in-depth analysis.’Source: NIST, SP 800-53 Rev. 5: Security and Privacy Controls for Information Systems and Organizations, control CA-8 (2020) (PDF)
Checked October 7, 2026
-
OWASP’s Web Security Testing Guide says business-logic flaws ‘cannot be detected by a vulnerability scanner’ and that automating business-logic abuse cases ‘is not possible and remains a manual art.’Source: OWASP Foundation, Web Security Testing Guide v4.2: Introduction to Business Logic (2020)
Checked October 7, 2026
-
The OWASP Top 10:2025 keeps Broken Access Control at #1, and OWASP notes its data is ‘largely limited to what the industry can test for in an automated fashion.’Source: OWASP Foundation, OWASP Top 10:2025, Introduction (2025)
Checked October 7, 2026
-
Verizon 2026 DBIR: “Only 26% of critical vulnerabilities” (CISA KEV-listed) “were fully remediated by organizations in 2025,” and “the median time for full resolution went up to 43 days.”Source: Verizon Business, 2026 Data Breach Investigations Report: Executive Summary (2026) (PDF)
Checked October 7, 2026
Your first penetration test, explained
-
NIST SP 800-53 Rev. 5 (CA-8) says penetration testing “goes beyond automated vulnerability scanning.”Source: NIST, SP 800-53 Rev. 5: Security and Privacy Controls for Information Systems and Organizations, control CA-8 (2020) (PDF)
Checked October 7, 2026
-
OWASP’s Web Security Testing Guide says business-logic flaws “cannot be detected by a vulnerability scanner.”Source: OWASP Foundation, Web Security Testing Guide v4.2: Introduction to Business Logic (2020)
Checked October 7, 2026
-
Verizon 2026 DBIR: “breaches with third-party involvement have increased by 60% from last year’s dataset, reaching 48% of total breaches.”Source: Verizon Business, 2026 Data Breach Investigations Report: Executive Summary (2026) (PDF)
Checked October 7, 2026
Penetration test vs. vulnerability scan
-
CISA’s Known Exploited Vulnerabilities catalog lists more than 1,700 vulnerabilities with reliable evidence of in-the-wild exploitation. CISA strongly recommends all organizations prioritize remediating them.Source: Cybersecurity and Infrastructure Security Agency (CISA), Known Exploited Vulnerabilities Catalog (2026)
Checked October 7, 2026
-
A 2025 peer-reviewed ACM CCS study says reliable broken-access-control detection remains limited; in its benchmark, a commercial scanner with an authorization extension caught 54% of 57 unauthorized-modification flaws.Source: Liu et al., ACM CCS 2025, BACScan: Automatic Black-Box Detection of Broken-Access-Control Vulnerabilities in Web Applications (2025) (PDF)
Checked October 7, 2026
-
MITRE’s CWE-862 (Missing Authorization) rates automated static analysis ‘Limited,’ noting difficulty with ‘custom authorization schemes,’ and says ‘manual analysis is required’ to determine whether missing authorization violates business logic.Source: The MITRE Corporation, CWE-862: Missing Authorization (2026)
Checked October 7, 2026
-
The OWASP Top 10:2025 keeps Broken Access Control at #1, and OWASP notes its data is ‘largely limited to what the industry can test for in an automated fashion.’Source: OWASP Foundation, OWASP Top 10:2025, Introduction (2025)
Checked October 7, 2026
-
OWASP’s Web Security Testing Guide says business-logic flaws ‘cannot be detected by a vulnerability scanner’ and that automating business-logic abuse cases ‘is not possible and remains a manual art.’Source: OWASP Foundation, Web Security Testing Guide v4.2: Introduction to Business Logic (2020)
Checked October 7, 2026
-
A 2014 peer-reviewed NDSS paper noted that application-specific logic flaws ‘remain outside the scope of most of the existing tools and still need to be discovered by manual inspection.’Source: Pellegrino and Balzarotti, NDSS 2014, Toward Black-Box Detection of Logic Flaws in Web Applications (2014) (PDF)
Checked October 7, 2026
-
A peer-reviewed 2025 NDSS paper says web scanners ‘still perform poorly or even fail’ at discovering deeper app states behind multi-step workflows like checkout, ‘leaving potential vulnerabilities undetected.’Source: Stafeev et al., NDSS 2025, YuraScanner: Leveraging LLMs for Task-driven Web App Scanning (2025) (PDF)
Checked October 7, 2026
-
In a peer-reviewed 2010 study, all 11 web scanners missed 8 of 16 planted flaws, including a coupon logic flaw; students with average security skills found 15 of 16.Source: Doupé, Cova, and Vigna, DIMVA 2010, Why Johnny Can’t Pentest: An Analysis of Black-box Web Vulnerability Scanners (2010) (PDF)
Note: These studies tested older tools, a single test application, or a single bug class, so read them as a pattern rather than a measurement of today’s scanners.
Checked October 7, 2026
-
In a 2010 IEEE S&P study, eight commercial scanners caught none of the planted second-order SQL injections and averaged 15% on stored XSS; only textbook reflected XSS topped 32.5%.Source: Bau, Bursztein, Gupta, and Mitchell, IEEE S&P 2010, State of the Art: Automated Black-Box Web Application Vulnerability Testing (2010) (PDF)
Note: These studies tested older tools, a single test application, or a single bug class, so read them as a pattern rather than a measurement of today’s scanners.
Checked October 7, 2026
-
In a peer-reviewed 2021 study (IEEE S&P), six open-source and academic scanners found no confirmed XSS on six modern apps, including WordPress and PrestaShop; only the authors’ scanner did.Source: Eriksson, Pellegrino, and Sabelfeld, IEEE S&P 2021, Black Widow: Blackbox Data-driven Web Scanning (2021) (PDF)
Note: These studies tested older tools, a single test application, or a single bug class, so read them as a pattern rather than a measurement of today’s scanners.
Checked October 7, 2026
-
NIST SP 800-115 notes most penetration tests seek combinations of vulnerabilities granting more access than any single flaw, and manual analysis can identify new or obscure vulnerabilities scanners may miss.Source: NIST, SP 800-115: Technical Guide to Information Security Testing and Assessment (2008) (PDF)
Checked October 7, 2026
-
NIST SP 800-53 Rev. 5 (CA-8) says penetration testing ‘goes beyond automated vulnerability scanning,’ is conducted by teams ‘with demonstrable skills and experience,’ and provides ‘a more in-depth analysis.’Source: NIST, SP 800-53 Rev. 5: Security and Privacy Controls for Information Systems and Organizations, control CA-8 (2020) (PDF)
Checked October 7, 2026
-
In a 2022 peer-reviewed case study on one web app, static analysis found the most vulnerabilities, exploratory manual pentesting found more severe ones, and each technique found issues others missed.Source: Elder et al., Empirical Software Engineering 27, Do I really need all this work to find vulnerabilities? An empirical case study comparing vulnerability detection techniques on a Java application (2022)
Checked October 7, 2026
How to choose a penetration testing company
-
OWASP’s Web Security Testing Guide says business-logic flaws “cannot be detected by a vulnerability scanner.”Source: OWASP Foundation, Web Security Testing Guide v4.2: Introduction to Business Logic (2020)
Checked October 7, 2026
About our own figures
- Founded 2023: HackNow, LLC was formed in Texas in 2023.
- 30,000+: Member count of HackNow’s hacking community, from the owner’s written statement of October 7, 2026.
- 100+: Penetration tests delivered by our testers over their careers, including engagements for partner security firms, from the owner’s written statement of October 7, 2026.
Tell us what you need tested.
We reply to every request within one business day. Every engagement is a fixed fee after a free scoping call.