11 September 2026 / 40 minutes of reading
Our latest Ethical Hacking Report presented three striking figures:
On their own, however, these figures do not tell a CISO the most important thing: where to allocate the security budget. Although the data comes from 2025, the patterns it reveals remain just as relevant in 2026, which is precisely why organisations need to be prepared for them.
We therefore took a closer look: we divided all 3,293 findings by the type of environment tested, examined which vulnerabilities appeared most frequently in each system, and compared them with global developments during 2025, from updated OWASP lists to CVEs that attackers were actively exploiting.
Where our penetration testing findings overlap with real-world attacks, a fairly clear picture emerges of what organisations should prioritise.
One pattern was repeated across almost every type of environment: the severity of vulnerabilities is not related to their number. The most critical risks appear precisely where organisations believe they are already sufficiently protected.
A higher number of findings does not automatically mean poorer security, so the figures need to be interpreted carefully. Citadelo completed 628 projects in 2025, 34% more than in the previous year. The total number of vulnerabilities therefore increased naturally—in simple terms, we tested more systems.
The real story, however, is not about volume, but concentration. The most serious findings began to cluster in specific areas, particularly inside organisations. The number of critical vulnerabilities increased by 42% year on year, faster than the number of tests itself, and by as much as 185% in infrastructure projects. The sharpest increase occurred in internal networks and systems that companies consider less exposed simply because they are not directly accessible from the internet.
The same pattern is visible in real-world incident data. According to the Verizon 2025 Data Breach Investigations Report, vulnerability exploitation accounted for approximately one fifth of all incidents, a 34% year-on-year increase, while the share of attacks targeting network devices and VPNs rose sharply from 3% to 22%. The latest Verizon DBIR 2026, published in May 2026, fully confirmed this shift: for the first time in the report’s history, vulnerability exploitation became the most common initial access vector, overtaking compromised credentials.
What we describe as a false sense of security during internal testing therefore becomes a clearly measurable factor in incident data. For CISOs, this leads to an uncomfortable but unambiguous conclusion: the security level of internet-facing systems reveals very little about the organisation’s actual level of risk. The following sections examine individual environment types and identify where this gap is greatest.
Not every finding is simply the rediscovery of a known issue. During 2025, our penetration tests led us to four new CVE vulnerabilities in widely used products.
These cases clearly illustrate the difference between automated scanning for known weaknesses and penetration testing, where a specialist thinks like an attacker. Scanners find yesterday’s problems; penetration tests uncover tomorrow’s.
Before moving on to specific recommendations, let us summarise the overall picture.
Across the entire map, both in our data and in real-world attacks from 2025, the same conclusion recurs: where organisations underestimate testing, the most serious vulnerabilities accumulate. This leads to four priorities.
We found the highest proportion of critical vulnerabilities in internal infrastructure and the cloud. Network devices were among the most frequently exploited targets. Identity management largely determines whether initial access develops into full control of a company. Direct a greater share of testing towards the areas where the greatest risks arise, not towards those that are easiest to test.
A 40% social engineering success rate, fraud involving deepfake technology and the first zero-click attacks on AI are no longer edge cases. Both areas reward systematic investment and punish neglect just as quickly.
A penetration test conducted over one or two weeks identifies technical vulnerabilities. Red Teaming, which takes four to eight weeks, evaluates how people and detection mechanisms respond to a coordinated attack. Threat-led Penetration Testing (TLPT) in regulated sectors is also gradually becoming mandatory through frameworks such as TIBER-EU and CBEST, testing preparedness against threats specific to the relevant industry.
An attacker only needs to find one vulnerability. You only need to find it before they do.
Our results and real-world incidents send an unequivocal message: systematic testing is no longer optional. Only one question remains: will you discover your vulnerabilities, or will an attacker?
In most organisations, the security budget is not exactly the top priority, so the question is not the amount invested but the order in which investments are made. Three simple rules can help even when the budget remains unchanged.
A critical vulnerability on an internet-facing device that already appears in the CISA KEV catalogue takes priority over a vulnerability with a higher CVSS score that nobody is actively exploiting. What matters more than the score is whether the vulnerability can actually be exploited and how significant its impact could be.
The measures that delivered the greatest benefit in 2025 were also among the least expensive: network segmentation, Active Directory tiering, SMB and LDAP signing, regular cloud key rotation, and independent identity verification when communicating with the helpdesk. These are not new products, but sound configuration and discipline—and these practices are often what break the chain of more complex attacks.
If you currently test mainly publicly accessible web applications, the likelihood of finding another critical vulnerability decreases. The priority should therefore be to redirect testing towards other segments, including internal infrastructure and identity management, rather than carrying out another test of an environment that is already thoroughly monitored.
In a regulated sector, this is not only about technical risk, but also about demonstrating that your organisation meets regulatory requirements. Your compliance team should always assess the exact provisions of the relevant legislation, but the fundamental connections are clear.
Boards do not buy CVE identifiers. They buy business continuity, lower legal exposure and reputational protection. Speak to them in the language of business, not in technical terminology.
The key message for leadership is simple: the measures that address these risks are precisely those that regulators now expect organisations to perform continuously, rather than once a year.
Five actions you can start today:
The complete data behind this analysis is available in Citadelo’s Ethical Hacking Report 2025. If you want to identify the weak points in your own organisation, contact us and we will agree on the next steps.
All news