State of Pentesting in the Software Industry

Software companies are the strongest remediators with the fastest resolution time of high-risk vulnerabilities of any industry. Software industry teams also express confidence in their performance, a sense of the state of pentesting that the pentest data validates.

Software and technology companies run more penetration testing than almost any other sector, and it shows. This snapshot pairs five years of Cobalt pentest findings with our 2026 security leaders and practitioners survey to profile how the sector finds, fixes, and thinks about security risk. The picture is consistent: software remediates high-risk pentest findings faster than any other industry by the most objective measure (half-life of findings), and its confidence is backed by measurable performance rather than optimism. The open question is whether that discipline extends to AI, the one asset class security teams across industries still struggle to secure.

Sources: Cobalt State of Pentesting Report 2026 (~5,000 penetration tests/yr) · 2026 survey of 455 security leaders and practitioners (Emerald Research).

The high-risk remediation funnel

Every high-risk pentest finding ideally needs to be closed in days not weeks. Software industry closes them faster than any other industry.

9%
of findings
are high-risk
86%
of those
get resolved
38d
mean time
to remediate
38d
high-risk
half-life
83%
run regular AI security assessments and pentests (highest of any sector)
64%
run a programmatic pentesting cadence (vs 53% across all industries)
11%
have had an AI or LLM security incident (among the lowest)

Where software stands: remediation speed by sector

High-risk half-life by sector: the time to remediate half of all high-risk findings. Lower is better.

How long do high-risk pentest findings stay open? By comparing 10 industries, we see software leads outright, with the fastest high-risk half-life of any sector. We use half-life rather than mean time to remediate (MTTR) because it is the fuller measure: half-life captures the time to close 50% of all high-risk findings, including those still open, whereas MTTR counts only the issues that have already been fixed. Why is the software industry better than the rest? As we'll see below, the software industry has a better record of pentesting programmatically.

Software38dProfessional Services45dHospitality50dHealthcare55dFinance55dEducation69dManufacturing73dRetail84dUtilities96dEntertainment98d

And below we show the same half-life ranking on a single scale. Each sector is a colored dot matching the color of that industry's respective bar above, so the full spread is visible at once. Only the software industry is labeled, but it's clear: Software sector is well ahead of other industries in remediation of high-risk vulnerabilities.

40d55d70d85d100dSoftware · 38dfastest sectorslowest sector

What testers actually find

Top finding types by frequency. Bar length = how often it appears; tag = share rated high-risk.

The vulnerability types pentesters surface most often in the software industry. Frequency shows how common each is; the tag flags how many are serious enough to demand urgent attention.

Server Security Misconfiguration 27%2% high-risk
 
Missing Access Control 20%20% high-risk
 
Cross-Site Scripting (XSS) 10%31% high-risk
 
Sensitive Data Exposure 8%6% high-risk
 
Authentication & Sessions 7%7% high-risk
 
Server-Side Injection 5%20% high-risk
 
Authorization & Privilege Escalation 1%37% high-risk
 

Confidence, backed by capability

Unlike some industries, software industry's self-assessment matches its results.

Below are key metrics showing how software teams rate their own security posture in the survey, and the pentest data that agrees with them.

Each survey claim paired with the pentest metric that bears it out.

The claim (survey)
 
The evidence (pentest data)
64%run a programmatic pentesting cadence
86%of high-risk findings actually get resolved
30%feel they are “playing catch-up” (the lowest)
38dfastest high-risk half-life of any sector
72%see AI as a tool, not a threat
11%have had an AI incident — among the lowest

AI in the software industry

What software teams worry about in their AI apps and the testing discipline behind it. Survey of software respondents (n=122).

Software industry security teams focus their AI worry on data exposure and prompt injection, the failure modes closest to how these apps actually break. With the highest AI pentesting rates of any sector, software companies know what findings they should be most concerned about from pentests, not just perception.

Top AI security concerns named by software teams
Data leakage / sensitive exposure
75%
Prompt injection attacks
73%
Unauthorized access to LLM APIs
48%
Adversarial manipulation of output
46%
Model bias (legal / reputational)
23%
83%
run regular AI security assessments and pentests (Highest of any sector)
42%
test AI programmatically (39% average across industries)
11%
have had an AI/LLM security incident (Among the lowest)
Who gets blamed if AI causes an incident

Distinct to software: accountability sits with the builders. Engineering and product are named more often than the CISO, the inverse of most industries, where the security team takes the blame. These teams need to work together, with shared responsibility for security.

Engineering / product
64%
Data / AI team
58%
CISO
46%
Nobody
1%
Zoom out: the AI BIG picture
32%
of AI findings are high-risk vs 12% across all assets
38%
of high-risk AI findings get resolved—lowest of any pentest type

Software tests its AI more than any sector. But across every industry, AI remains the hardest asset class to secure and to fix. Read the AI and Pentesting Pulse Report 2026 for the full cross-industry picture and where autonomous pentesting is headed. →

Recommendations for improving your pentesting program

Protect the speed lead. A 38-day half-life is best-in-class. Defend it as a named SLA, don't assume it holds as AI speeds up development.

Attack the finding mix at the root. Misconfiguration and access control dominate. Invest in secure defaults and authorization review, not one-off fixes.

Track AI as its own asset class. AI findings have the lowest fix rate. Folded into general metrics, the AI resolution gap disappears from view.

Convert confidence into consistency. Software industry's confidence is earned due to programmatic testing.

Watch for complacency at the edges. Make sure assurance scales with that self-assurance.

See where your AI and application security actually stands
Cobalt runs ~5,000 pentests a year across software teams like yours. Get a demo to see how your remediation speed and coverage compare.
Get a demo →
Back to Blog
About Cobalt
Cobalt combines talent and technology to provide end-to-end offensive security solutions that enable organizations to remediate risk across a dynamically changing attack surface. As the innovators of Pentest as a Service (PtaaS), Cobalt empowers businesses to optimize their existing resources, access an on-demand community of trusted security experts, expedite remediation cycles, and share real-time updates and progress with internal teams to mitigate future risk. More By Cobalt
Platform Deep Dive: Lost Device Support for 2FA
Life happens and sometimes users lose their registered devices. We’ve now made it simpler to request a 2FA reset.
Blog
Jul 18, 2022
Meet Judy: The Security AI Watching Out for Small and Midsize Businesses
Compliance mapping, ongoing security training, endpoint detection and response, password management, and 24/7 monitoring — if you pictured a whole team of security consultants while reading this, you’ve clearly not met Judy.
Blog
Jul 29, 2022