Software companies are the strongest remediators with the fastest resolution time of high-risk vulnerabilities of any industry. Software industry teams also express confidence in their performance, a sense of the state of pentesting that the pentest data validates.
Software and technology companies run more penetration testing than almost any other sector, and it shows. This snapshot pairs five years of Cobalt pentest findings with our 2026 security leaders and practitioners survey to profile how the sector finds, fixes, and thinks about security risk. The picture is consistent: software remediates high-risk pentest findings faster than any other industry by the most objective measure (half-life of findings), and its confidence is backed by measurable performance rather than optimism. The open question is whether that discipline extends to AI, the one asset class security teams across industries still struggle to secure.
Sources: Cobalt State of Pentesting Report 2026 (~5,000 penetration tests/yr) · 2026 survey of 455 security leaders and practitioners (Emerald Research).
Every high-risk pentest finding ideally needs to be closed in days not weeks. Software industry closes them faster than any other industry.
are high-risk
get resolved
to remediate
half-life
Where software stands: remediation speed by sector
High-risk half-life by sector: the time to remediate half of all high-risk findings. Lower is better.
How long do high-risk pentest findings stay open? By comparing 10 industries, we see software leads outright, with the fastest high-risk half-life of any sector. We use half-life rather than mean time to remediate (MTTR) because it is the fuller measure: half-life captures the time to close 50% of all high-risk findings, including those still open, whereas MTTR counts only the issues that have already been fixed. Why is the software industry better than the rest? As we'll see below, the software industry has a better record of pentesting programmatically.
And below we show the same half-life ranking on a single scale. Each sector is a colored dot matching the color of that industry's respective bar above, so the full spread is visible at once. Only the software industry is labeled, but it's clear: Software sector is well ahead of other industries in remediation of high-risk vulnerabilities.
What testers actually find
Top finding types by frequency. Bar length = how often it appears; tag = share rated high-risk.
The vulnerability types pentesters surface most often in the software industry. Frequency shows how common each is; the tag flags how many are serious enough to demand urgent attention.
Confidence, backed by capability
Unlike some industries, software industry's self-assessment matches its results.
Below are key metrics showing how software teams rate their own security posture in the survey, and the pentest data that agrees with them.
Each survey claim paired with the pentest metric that bears it out.
AI in the software industry
What software teams worry about in their AI apps and the testing discipline behind it. Survey of software respondents (n=122).
Software industry security teams focus their AI worry on data exposure and prompt injection, the failure modes closest to how these apps actually break. With the highest AI pentesting rates of any sector, software companies know what findings they should be most concerned about from pentests, not just perception.
Distinct to software: accountability sits with the builders. Engineering and product are named more often than the CISO, the inverse of most industries, where the security team takes the blame. These teams need to work together, with shared responsibility for security.
Software tests its AI more than any sector. But across every industry, AI remains the hardest asset class to secure and to fix. Read the AI and Pentesting Pulse Report 2026 for the full cross-industry picture and where autonomous pentesting is headed. →
Recommendations for improving your pentesting program
Protect the speed lead. A 38-day half-life is best-in-class. Defend it as a named SLA, don't assume it holds as AI speeds up development.
Attack the finding mix at the root. Misconfiguration and access control dominate. Invest in secure defaults and authorization review, not one-off fixes.
Track AI as its own asset class. AI findings have the lowest fix rate. Folded into general metrics, the AI resolution gap disappears from view.
Convert confidence into consistency. Software industry's confidence is earned due to programmatic testing.
Watch for complacency at the edges. Make sure assurance scales with that self-assurance.