-

Cobalt Research Reveals Critical Readiness Gap as Security Teams Fall Behind GenAI Risks

Nearly half of security professionals call for a “strategic pause”, but threat actors aren’t waiting

SAN FRANCISCO--(BUSINESS WIRE)--Cobalt, the pioneer of penetration testing as a service (PTaaS) and leader in offensive security services, today announced the release of its State of LLM Security Report 2025. This new research reveals a widening readiness gap in enterprise security as the rapid adoption of generative AI (genAI) outpaces defenders’ ability to secure it. A staggering 36% of security leaders and practitioners admit that genAI is moving faster than their teams can manage, a sobering reality as organizations continue to embed AI deep into core business operations.

Despite growing concern, many are calling for a timeout: 48% of respondents believe a “strategic pause” is needed to recalibrate defenses against genAI-driven threats. But that pause isn’t coming.

“Threat actors aren’t waiting around, and neither can security teams,” said Gunter Ollmann, CTO, Cobalt. “Our research shows that while genAI is reshaping how we work, it’s also rewriting the rules of risk. The foundations of security must evolve in parallel, or we risk building tomorrow’s innovation on today’s outdated safeguards.”

Key findings from the report include:

  • 72% of respondents cite genAI-related attacks as their top IT risk, but 33% are still not conducting regular security assessments, including penetration testing, for their LLM deployments.
  • 50% of respondents want more transparency from software suppliers about how they detect and prevent vulnerabilities, signaling a growing trust gap in the AI supply chain.
  • Security leaders (C-suite and VP level) are more concerned about long-term genAI threats like adversarial attacks (76%) versus the 68% of practitioners which expressed the same concern. However when it came to near-term operational risks such as inaccurate outputs, 45% of practitioners expressed concern versus 36% of security leaders.
  • Top concerns among all survey respondents include sensitive information disclosure (46%), model poisoning or theft (42%), and training data leakage (37%), all pointing to an urgent need to protect the integrity of data pipelines.
  • Overall, 69% of serious findings across all pentest categories are resolved but this falls to just 21% of the high-severity vulnerabilities found in LLM pentests. This is a concern given that 32% of LLM pentest findings are serious and is the lowest resolution rate across all test types conducted by Cobalt.

“Much like the rush to cloud adoption, genAI has exposed a fundamental gap between innovation and security readiness,” Ollmann added. “Mature controls were not built for a world of LLMs. Security teams must shift from reactive audits to programmatic, proactive AI testing—and fast.”

Methodology

The report analyzes two different datasets. The majority of analysis is based on data collected during Cobalt pentests. This is supplemented by insights collected via a survey by a third-party research firm, Emerald Research. All penetration testing data analyzed in this report was collected through Cobalt pentests. This spans more than 2,700 organizations. Metadata from these pentests was exported from the Cobalt Offensive Security Platform, sanitized to remove client-identifying and other sensitive details, and provided to Cyentia Institute for independent analysis.

Additional Resources:

About Cobalt

Cobalt is the pioneer in pentesting as a service (PTaaS) and a leader in offensive security services. We are focused on combining talent and technology with speed, scalability, and expertise. Thousands of customers and hundreds of partners rely on the Cobalt Offensive Security Platform, along with 450+ trusted security experts, to find and fix vulnerabilities across their environments. By enabling faster pentest launches, real-time collaboration with pentesters, and seamless integration with remediation workflows, we help organizations identify critical issues and accelerate risk mitigation so they can operate fearlessly and innovate securely.

Cobalt maintains an outstanding NPS of 9.12, reflecting its dedication to customer satisfaction. Read our reviews on G2 to see why customers love us. More at https://www.cobalt.io. Follow Cobalt on LinkedIn and X.

Contacts

Media Contact:
Leslie Kesselring
Kesselring Communication for Cobalt
leslie@kesscomm.com

Cobalt


Release Versions

Contacts

Media Contact:
Leslie Kesselring
Kesselring Communication for Cobalt
leslie@kesscomm.com

More News From Cobalt

Cobalt Helps Organizations Embed Security Into Operations and Reduce Risk Faster

SAN FRANCISCO--(BUSINESS WIRE)--Cobalt, the pioneer of penetration testing as a service (PTaaS) and leading provider of offensive security services, has undergone a large-scale expansion of its Cobalt Offensive Security Platform to transform offensive security from ad-hoc tests into a continuous, centrally managed program. The human led, AI-powered platform provides the visibility, control, and efficiency needed to secure organizations—from code to company—at scale. According to the 2025 Gartne...

Attackers Evolve Too Quickly to Maintain a Truly Resilient Security Posture, Cobalt ‘CISO Perspectives’ Report Finds

SAN FRANCISCO--(BUSINESS WIRE)--Cobalt, the pioneer of penetration testing as a service (PTaaS) and leader in offensive security services, today announced the release of its CISO Perspectives Report 2025: AI and Digital Supply Chain Risks. This report examines the results of surveyed security leaders who were asked questions regarding topics such as third-party software risks, concerns on AI, insider threats and the current mindset on offensive security strategies. Findings in this report inclu...

Cobalt Appoints Chris Essex as Chief Revenue Officer to Drive Next Phase of Company Growth

SAN FRANCISCO--(BUSINESS WIRE)--Cobalt, the pioneer of Pen Testing as a Service (PTaaS) and leading provider of Offensive Security solutions, today announced the appointment of Chris Essex as Chief Revenue Officer (CRO). Essex will be key to realizing Cobalt’s mission of becoming the leader in offensive cybersecurity services. Cobalt was founded on a transformative vision to make pentesting faster, more effective, and better suited to today’s dynamic security needs. Seeing the limitations of tr...
Back to Newsroom