100+ Server Security Statistics for 2026
Software vulnerability exploitation caused 31% of the breaches studied in Verizon’s 2026 Data Breach Investigations Report, making it the leading initial access vector. Organizations fully remediated only 26% of critical known exploited vulnerabilities during 2025, while the median resolution time rose to 43 days.
Server security now depends on much more than operating system patches. Internet-facing applications, remote services, cloud identities, APIs, firewalls, hypervisors, backup systems, and denial-of-service defenses all affect whether an attacker can enter, move through, or disrupt an environment.
This article presents 150 server security statistics covering breach entry, vulnerabilities, patching, internet scanning, remote access, ransomware, cloud workloads, web applications, DDoS attacks, detection, and recovery. Every numbered statistic names its source, while external source names remain unlinked.
Server Security Statistics at a Glance

- Software vulnerability exploitation caused 31% of breaches in Verizon’s 2026 dataset.
- Organizations fully remediated only 26% of critical known exploited vulnerabilities in 2025.
- GreyNoise measured 212 malicious exploitation attempts per second during the second half of 2025.
- Ransomware appeared in 48% of breaches studied in the 2026 DBIR.
- Cloudflare mitigated 935 network-layer DDoS attacks above 1 Tbps during the first half of 2026.
Server Breach and Initial Access Statistics

- Software vulnerability exploitation served as the initial access vector in 31% of breaches studied for the 2026 DBIR. Verizon
- Credential abuse served as the initial access vector in 13% of breaches. Verizon
- Ransomware appeared in 48% of breaches, up from 44% one year earlier. Verizon
- Third-party involvement appeared in 48% of breaches. Verizon
- Breaches involving third parties increased 60% from the previous DBIR dataset. Verizon
- The human element appeared in 62% of breaches, up from 60%. Verizon
- Social engineering represented 16% of all breaches. Verizon
- Pretexting served as an initial access vector in 6% of breaches. Verizon
- Vulnerability exploitation served as the initial access vector in 38% of manufacturing breaches. Verizon
- Vulnerability exploitation served as the initial access vector in 40% of public administration breaches. Verizon
- Vulnerability exploitation served as the initial access vector in 42% of retail breaches. Verizon
- Vulnerability exploitation caused 26% of breaches at small and midsize businesses. Verizon
- Unpatched web assets caused 18% of the breaches investigated by Microsoft Incident Response. Microsoft
- Exposed remote services caused 12% of the breaches investigated by Microsoft Incident Response. Microsoft
- Phishing or social engineering caused 28% of the breaches investigated by Microsoft Incident Response. Microsoft
Hyperconvergence’s server software guide explains the operating systems and service programs that require secure configuration and routine maintenance.
Server Vulnerability and Exploitation Statistics

- Researchers disclosed 8,539 high or critical severity CVEs during Q2 2026. Rapid7
- Researchers disclosed 4,268 high or critical severity CVEs during Q2 2025. Rapid7
- High and critical severity vulnerability disclosures doubled year over year in Q2 2026. Rapid7
- Forty newly exploited vulnerabilities entered Rapid7’s Q2 2026 tracking data. Rapid7
- Newly exploited vulnerabilities increased 8% year over year in Q2 2026. Rapid7
- Sixty-two percent of the exploited vulnerabilities studied in Q2 2026 required no authentication or user interaction and were remotely exploitable. Rapid7
- The corresponding share of remotely exploitable, unauthenticated, zero-interaction vulnerabilities was 53% in Q2 2025. Rapid7
- Researchers disclosed 3,453 remotely exploitable, unauthenticated, zero-interaction vulnerabilities in Q2 2026. Rapid7
- The corresponding disclosure count was 1,612 in Q2 2025. Rapid7
- Disclosures with those attacker-friendly properties increased 114% year over year. Rapid7
- Public proof-of-concept code was available for 270 vulnerabilities disclosed in Q2 2026. Rapid7
- Public proof-of-concept code was available for 153 vulnerabilities disclosed in Q2 2025. Rapid7
- The number of newly disclosed vulnerabilities with public proof-of-concept code increased 76% year over year. Rapid7
- Q2 2026 produced 156 missing-authentication vulnerability disclosures. Rapid7
- Missing-authentication disclosures increased 247% year over year. Rapid7
- Q2 2026 produced 476 SQL injection vulnerability disclosures. Rapid7
- Q2 2025 produced 318 SQL injection vulnerability disclosures. Rapid7
- SQL injection vulnerability disclosures increased 50% year over year. Rapid7
- Rapid7 found 124 exploit and access listings across underground sources during Q2 2026. Rapid7
- The listings involved 23 actively traded CVEs. Rapid7
Server Patching and Remediation Statistics

- Twenty of the 23 CVEs traded in the underground sources had public proof-of-concept code. Rapid7
- Nine of the 23 traded CVEs were already in CISA’s Known Exploited Vulnerabilities catalog. Rapid7
- Nineteen of the 23 traded CVEs required no authentication or user interaction. Rapid7
- The volume of critical vulnerability disclosures increased 21% from Q1 to Q2 2026. Rapid7
- The availability of public proof-of-concept code increased 12% from Q1 to Q2 2026. Rapid7
- Organizations fully remediated 26% of critical CISA Known Exploited Vulnerabilities during 2025. Verizon
- The full-remediation rate was 38% one year earlier. Verizon
- The median time to fully resolve a critical known exploited vulnerability rose to 43 days. Verizon
- The corresponding median resolution time was 32 days one year earlier. Verizon
- The median organization had 50% more critical vulnerabilities to patch than in the previous DBIR dataset. Verizon
- Only 23% of third-party organizations fully remediated missing or improperly secured MFA on cloud accounts. Verizon
- Half of the third-party cloud MFA findings were resolved within one month. Verizon
- Weak passwords and permission misconfigurations took almost eight months for half of the findings to be resolved. Verizon
- Third-party software exploitation caused 44.5% of initial access observed in a subset of Google Cloud incidents during H2 2025. Google Cloud
- Remote code execution caused 13.6% of initial access in that H2 2025 Google Cloud data, up from 2.9% in H1. Google Cloud
Hyperconvergence’s cloud server vs. physical server guide explains how patching, access control, hardware maintenance, and provider responsibility differ between deployment models.
Internet-Facing Server Scanning Statistics

- The mean time to exploit a vulnerability fell to an estimated negative seven days in Mandiant’s 2026 analysis. Google Cloud Mandiant
- GreyNoise recorded 2,969,010,478 malicious sessions targeting internet-facing infrastructure during the second half of 2025. GreyNoise
- Those sessions came from 3,804,232 unique source IP addresses. GreyNoise
- The observation period covered 162 days. GreyNoise
- Malicious activity averaged about 212 sessions per second. GreyNoise
- The GreyNoise sensor network covered more than 80 countries. GreyNoise
- Previously unseen IP addresses generated 52% of remote code execution attempts. GreyNoise
- Vulnerabilities disclosed before 2015 generated 7.3 million exploitation sessions. GreyNoise
- Those pre-2015 vulnerabilities generated four times as many sessions as vulnerabilities disclosed during 2023 and 2024 combined. GreyNoise
- Palo Alto GlobalProtect received 16.7 million malicious sessions. GreyNoise
- GlobalProtect received more than 3.5 times the combined traffic aimed at the Cisco and Fortinet services in the same comparison. GreyNoise
- One residential credential-spraying botnet grew to 300,000 IP addresses. GreyNoise
- That botnet expanded from 2,000 to 300,000 IP addresses in 72 days. GreyNoise
- Residential connections accounted for 73% of the botnet’s addresses. GreyNoise
- One hosting provider generated 392 million malicious sessions. GreyNoise
- That provider accounted for 14% of all malicious sessions in the dataset. GreyNoise
- AWS-associated addresses generated 80 million malicious sessions in the same analysis. GreyNoise
- Microsoft Azure-associated addresses generated 59 million malicious sessions. GreyNoise
- GreyNoise sensors recorded 91,403 sessions targeting LLM inference infrastructure. GreyNoise
- Censys and SentinelLABS counted about 175,000 internet-exposed Ollama instances in January 2026. GreyNoise, citing Censys and SentinelLABS
Hyperconvergence’s edge server guide covers distributed systems that may sit outside the visibility and controls used in a central data center.
Server Credentials and Remote Access Statistics

- Identity-based methods started 79% of ransomware attacks in Sophos’s 2026 survey. Sophos
- Compromised credentials were the technical root cause in 23% of ransomware attacks. Sophos
- Brute-force attacks were the technical root cause in 6% of ransomware attacks. Sophos
- Exposed applications and systems were the starting location in 38% of ransomware incidents involving vulnerabilities, compromised credentials, or brute force. Sophos
- User devices were the starting location in 30% of those incidents. Sophos
- Firewalls were the starting location in 21% of those incidents. Sophos
- VPNs were the starting location in 8% of those incidents. Sophos
- IoT devices were the starting location in 3% of those incidents. Sophos
- Compromised credentials caused 59% of the attacks that started in an exposed application or system. Sophos
- Exploited vulnerabilities caused 31% of the attacks that started in an exposed application or system. Sophos
- Brute-force attacks caused 10% of the attacks that started in an exposed application or system. Sophos
- Compromised credentials caused 41% of the attacks that started in a firewall. Sophos
- Exploited vulnerabilities caused 33% of the attacks that started in a firewall. Sophos
- Brute-force attacks caused 26% of the attacks that started in a firewall. Sophos
- Compromised credentials caused 44% of the attacks that started in a VPN. Sophos
- Exploited vulnerabilities caused 41% of the attacks that started in a VPN. Sophos
- Brute-force attacks caused 15% of the attacks that started in a VPN. Sophos
- Compromised credentials caused 48% of the attacks that started in an IoT device. Sophos
- Exploited vulnerabilities caused 36% of the attacks that started in an IoT device. Sophos
- Brute-force attacks caused 16% of the attacks that started in an IoT device. Sophos
Server Ransomware and Defense Statistics

- MFA was enabled in some capacity during 97% of ransomware incidents caused by compromised credentials. Sophos
- One-time passwords were available during 52% of those credential-based incidents. Sophos
- Push-based authentication applications were available during 51% of those incidents. Sophos
- Passkeys were available during 51% of those incidents. Sophos
- Affected organizations used an average of 2.5 MFA methods. Sophos
- Malicious email caused 26% of ransomware attacks. Sophos
- Phishing caused 24% of ransomware attacks. Sophos
- Exploited vulnerabilities caused 18% of ransomware attacks, down from 32% one year earlier. Sophos
- Known or unknown security gaps contributed to 62% of ransomware incidents. Sophos
- A lack of people or skills contributed to 58% of ransomware incidents. Sophos
- Missing or poor-quality protection contributed to 57% of ransomware incidents. Sophos
- Firewalls detected 61% of ransomware attacks before payload deployment. Sophos
- Firewalls detected 32% of ransomware attacks after payload deployment. Sophos
- Firewalls failed to detect 7% of ransomware attacks. Sophos
- Attackers encrypted data in 50% of incidents detected by a firewall before payload deployment. Sophos
- Attackers encrypted data in 65% of incidents detected by a firewall after payload deployment. Sophos
- Attackers encrypted data in 71% of incidents that a firewall failed to detect. Sophos
- Fifty-nine percent of ransom demands reached at least $1 million when an exploited firewall vulnerability started the attack. Sophos
- Sixty-seven percent of ransomware victims said the incident was also their most significant identity attack. Sophos
- Attackers successfully encrypted data in 56% of ransomware incidents. Sophos
Cloud, Web Server, and API Security Statistics

- Attackers both encrypted and stole data in 16% of ransomware incidents. Sophos
- Organizations stopped 41% of ransomware attacks before encryption. Sophos
- Backups restored data in 66% of incidents where ransomware encrypted it, up from 54% one year earlier. Sophos
- Ransom payments restored data in 48% of incidents where ransomware encrypted it. Sophos
- Two percent of organizations recovered none of their encrypted data. Sophos
- Identity issues underpinned initial access in 83% of major cloud and SaaS incidents studied during H2 2025. Google Cloud Mandiant
- Data theft was the objective in 73% of the cloud-related incidents in the same analysis. Google Cloud Mandiant
- Voice-based social engineering appeared in 17% of those cloud and SaaS cases. Google Cloud Mandiant
- Misconfiguration caused 21% of the Google Cloud incidents observed during H2 2025, down from 29.4% in H1. Google Cloud
- Exposed sensitive interfaces or APIs caused 4.9% of those H2 incidents, down from 11.8% in H1. Google Cloud
- HTTP DDoS attacks accounted for 37.1% of application traffic mitigated in Cloudflare’s 2024 application security study. Cloudflare
- Bots generated 31.2% of application traffic processed by Cloudflare. Cloudflare
- APIs generated 60% of dynamic, non-cacheable traffic. Cloudflare
- The web application firewall generated 67% of mitigations applied to API traffic. Cloudflare
- Machine-learning-based discovery found a median of 33% more public API endpoints than customers had reported. Cloudflare
Hyperconvergence’s cloud security statistics article contains broader figures on cloud data, controls, identities, and security spending.
Hyperconvergence’s web hosting statistics article provides related data on hosting platforms, web infrastructure, uptime, and service adoption.
Server DDoS and Availability Statistics

- Cloudflare mitigated 23.2 million network-layer DDoS attacks during the first half of 2026. Cloudflare
- Cloudflare processed 29.64 trillion HTTP requests associated with DDoS attacks during the first half of 2026. Cloudflare
- The network mitigated about 5,343 network-layer DDoS attacks per hour. Cloudflare
- Cloudflare mitigated 935 network-layer attacks exceeding 1 Tbps during the first half of 2026. Cloudflare
- Q2 2026 accounted for 805 of the attacks above 1 Tbps. Cloudflare
- Q1 2026 accounted for 130 of the attacks above 1 Tbps. Cloudflare
- Attacks above 1 Tbps increased 519% from Q1 to Q2 2026. Cloudflare
- DNS floods and DNS amplification generated 34.3% of network-layer attacks during the first half of 2026. Cloudflare
- DNS floods generated 40% of network-layer attacks during Q2 2026. Cloudflare
- DNS floods generated 25.7% of network-layer attacks during Q1 2026. Cloudflare
- CLDAP reflection attacks increased 580% from Q1 to Q2 2026. Cloudflare
- Attacks below 500 Mbps represented 96.62% of network-layer DDoS attacks during the first half of 2026. Cloudflare
- Attacks lasting less than 10 minutes represented 90.60% of network-layer DDoS attacks. Cloudflare
- Cloudflare mitigated 47.1 million DDoS attacks during 2025. Cloudflare
- The annual number of DDoS attacks increased 121% during 2025. Cloudflare
Hyperconvergence’s top cloud servers guide compares major compute platforms used for public-facing applications and services.
Server Incident Cost, Detection, and Recovery Statistics

- The average cost to recover from a ransomware attack, excluding the ransom, reached $1,700,200. Sophos
- Average ransomware recovery cost increased 11% from the 2025 survey. Sophos
- Median ransomware recovery cost was $375,000. Sophos
- Fifty-five percent of ransomware victims recovered within one week. Sophos
- Sixteen percent of ransomware victims recovered in less than one day. Sophos
- Eighty-three percent of ransomware victims recovered within one month. Sophos
- Three percent of ransomware victims needed more than three months to recover. Sophos
- Global median attacker dwell time reached 14 days in 2025, up from 11 days. Google Cloud Mandiant
- Organizations detected malicious activity internally in 52% of Mandiant investigations, up from 43%. Google Cloud Mandiant
- The global average cost of a data breach reached $4.99 million in 2026, up 12%. IBM
What the Server Security Data Means
Vulnerability exploitation now exceeds credential abuse as a measured breach-entry route, while remediation rates and patch times have moved in the wrong direction. Public servers need exposure-aware prioritization because disclosure volume is too high for severity scores alone to determine patch order.
Internet scanning is continuous and increasingly difficult to filter with static reputation data. Previously unseen addresses generated more than half of remote code execution attempts in GreyNoise’s research, while old vulnerabilities continued to attract millions of sessions.
Identity controls remain central to server defense. MFA presence alone does not prove complete coverage or resistance to token theft, social engineering, session hijacking, and compromised service credentials. Administrative interfaces, remote services, firewalls, VPNs, cloud accounts, and non-human identities need separate access policies and telemetry.
Ransomware resistance depends on early detection and recoverable infrastructure. The encryption rate rose from 50% when firewalls detected attacks before payload deployment to 71% when firewalls missed them, while backups restored data in two-thirds of encrypted incidents.
Sources
- Verizon, 2026 Data Breach Investigations Report Executive Summary
- Rapid7, Q2 2026 Quarterly Threat Report
- Microsoft, Digital Defense Report 2025
- Google Cloud Mandiant, M-Trends 2026
- Google Cloud, Cloud Threat Horizons Report H1 2026
- GreyNoise, 2026 State of the Edge Report
- GreyNoise, Blocklist Coverage Gap Research, May 2026
- Sophos, State of Ransomware 2026
- Cloudflare, DDoS Threat Report H1 2026
- Cloudflare, 2025 Q4 DDoS Threat Report
- Cloudflare, Application Security Report 2024 Update
- IBM, Cost of a Data Breach Report 2026
Editorial Note
The statistics use different definitions and populations. Breach studies examine confirmed incidents, incident response reports reflect investigated cases, scanning networks measure traffic that reaches their sensors, and vendor reports describe activity visible within their platforms. A scanning attempt does not prove compromise, and an observed attack rate is not a worldwide server average. Readers should review the named source methodology before placing a figure in a risk model, board report, or security budget.
Server Security Statistics FAQs
1. What Percentage of Breaches Start With an Exploited Server or Software Vulnerability?
Software vulnerability exploitation caused 31% of breaches in Verizon’s 2026 DBIR, making it the leading initial access vector. The figure covers exploited software across servers, applications, edge appliances, and other systems, so it is not a server-only percentage.
Microsoft Incident Response reported a narrower infrastructure view: unpatched web assets caused 18% of investigated breaches, while exposed remote services caused 12%. These figures use different case populations and should remain separate.
2. How Quickly Are Newly Disclosed Server Vulnerabilities Exploited?
Exploitation can begin before a patch exists. Mandiant estimated a negative seven-day mean time to exploit in its 2026 report, which means observed exploitation often preceded patch availability.
Google Cloud also recorded cryptocurrency miners targeting React Server Components about 48 hours after public disclosure of CVE-2025-55182. These are incident-based benchmarks, not a promise that every critical vulnerability will be exploited within the same period.
3. How Many High-Risk Vulnerabilities Are Security Teams Processing in 2026?
Rapid7 counted 8,539 high or critical severity CVEs in Q2 2026, twice the 4,268 recorded in Q2 2025. Public proof-of-concept code was available for 270 newly disclosed vulnerabilities, up 76% year over year.
Severity does not equal reachable risk. Server teams still need asset presence, internet exposure, exploit evidence, business importance, compensating controls, and CISA KEV status to set patch order.
4. What Percentage of Known Exploited Vulnerabilities Are Fully Patched?
Organizations fully remediated 26% of critical CISA Known Exploited Vulnerabilities during 2025, down from 38% one year earlier, according to Verizon. Median full resolution time rose from 32 to 43 days.
The data comes from the measured organizations and should not be treated as the patch rate for every server worldwide. It still provides a strong benchmark for evaluating whether a 30-day or 45-day remediation target closes known exposure quickly enough.
5. How Frequently Are Internet-Facing Servers Scanned or Attacked?
GreyNoise measured about 212 malicious sessions per second across its sensor network during a 162-day period in the second half of 2025. The dataset contained 2.97 billion sessions from 3.8 million source IP addresses across sensors in more than 80 countries.
This rate describes traffic seen across GreyNoise sensors, not the number of attacks received by one server. A public IP should still be treated as continuously scanned because automated systems search for open services and vulnerable software around the clock.
6. How Much Malicious Traffic Targets Older Server Vulnerabilities?
Vulnerabilities disclosed before 2015 generated 7.3 million exploitation sessions in GreyNoise’s 2026 State of the Edge analysis. That volume was four times the combined traffic for vulnerabilities disclosed during 2023 and 2024, although one 1999 X Server issue produced much of the older traffic.
The result shows why vulnerability age cannot serve as a removal rule for detection or patch programs. Old flaws remain useful to automated attackers when outdated or forgotten systems stay reachable.
7. What Percentage of Server Attacks Come From Previously Unknown IP Addresses?
Previously unseen IP addresses produced 52% of the remote code execution attempts in GreyNoise’s second-half 2025 dataset. Separate GreyNoise research found that 78% of residential IP addresses targeting the edge were visible no more than twice before disappearing.
Static blocklists therefore provide incomplete coverage against rotating cloud, proxy, and residential infrastructure. Behavior, service exposure, authentication, rate controls, and exploit detection remain necessary even when reputation filtering is active.
8. Which Internet-Facing Server and Edge Services Receive the Most Attack Traffic?
GreyNoise recorded 16.7 million malicious sessions aimed at Palo Alto GlobalProtect, more than 3.5 times the combined traffic aimed at the compared Cisco and Fortinet services. Its broader analysis also recorded sustained targeting of VPNs, routers, SSH, remote desktop services, and web applications.
The counts reflect GreyNoise’s sensor placement and service signatures, not each product’s installed base or compromise rate. Exposure reviews should focus on the services an organization actually publishes and the controls attached to their management interfaces.
9. Do Credentials or Vulnerabilities Cause More Server-Related Ransomware Attacks?
Sophos found that compromised credentials caused 23% of ransomware attacks, while exploited vulnerabilities caused 18%. Identity-based approaches, including attacks that obtained or abused credentials, started 79% of all ransomware incidents in the survey.
The starting point varied across infrastructure. Compromised credentials caused 59% of attacks beginning in exposed applications, while vulnerabilities caused 41% of attacks beginning in VPNs and 36% of attacks beginning in IoT devices.
10. Does MFA Stop Credential-Based Server Ransomware Attacks?
MFA was present in some capacity during 97% of the ransomware incidents caused by compromised credentials in Sophos’s 2026 survey. The finding does not show that MFA failed everywhere because the survey did not confirm complete enrollment across every account, service, protocol, and administrative path.
Attackers can exploit coverage gaps, stolen tokens, session cookies, social engineering, weak recovery processes, legacy authentication, and non-human credentials. Phishing-resistant MFA and complete administrative-service coverage provide a stronger benchmark than simple MFA presence.
11. How Important Are Exposed Applications and Systems in Ransomware Entry?
Exposed applications and systems were the starting location in 38% of Sophos ransomware incidents that began with a vulnerability, compromised credential, or brute-force attack. User devices followed at 30%, firewalls at 21%, VPNs at 8%, and IoT devices at 3%.
The 38% figure applies only to the three technical root causes included in that location analysis. It does not include ransomware incidents that began through malicious email or phishing.
12. How Effective Are Firewalls at Detecting Ransomware Before Encryption?
Firewalls detected 61% of surveyed ransomware attacks before payload deployment, detected 32% after deployment, and missed 7%. Attackers encrypted data in 50% of early-detected cases, 65% of late-detected cases, and 71% of missed cases.
The correlation supports rapid use of firewall telemetry, but it does not prove that a firewall alone prevented encryption. Endpoint, identity, email, network, and response controls also affect the outcome.
13. What Percentage of Ransomware Attacks Encrypt Server Data?
Attackers encrypted data in 56% of ransomware incidents in Sophos’s 2026 survey. The total included 40% where data was encrypted without reported theft and 16% where attackers both encrypted and stole data.
Organizations stopped 41% of attacks before encryption, while 2% involved extortion without encryption. These percentages describe organizations already hit by ransomware, not the likelihood that any server will be encrypted.
14. How Often Do Backups Recover Data After Server Ransomware?
Backups restored data in 66% of incidents where ransomware encrypted it, up from 54% in the 2025 Sophos report. Ransom payments restored data in 48%, while 2% of affected organizations recovered no data.
Multiple recovery methods were permitted in the survey, so the backup and payment percentages can overlap. The data does not measure backup completeness, restoration speed, or whether every affected server returned to its preattack state.
15. What Are the Main Initial Access Methods in Cloud Server Incidents?
Third-party software exploitation caused 44.5% of initial access in a subset of Google Cloud incidents during H2 2025. Weak or absent credentials caused 27.2%, misconfiguration caused 21%, and exposed sensitive interfaces or APIs caused 4.9%.
The figures describe observed activity in Google Cloud customer environments and do not represent every public cloud. The software was customer-managed third-party software, not a compromise of Google’s underlying infrastructure.
16. How Much Cloud and SaaS Intrusion Activity Involves Identity Compromise?
Identity issues underpinned initial access in 83% of the major cloud and SaaS incidents reviewed by Mandiant for H2 2025. Data theft was the objective in 73% of cloud-related incidents, and voice-based social engineering appeared in 17% of cases.
The 83%, 73%, and 17% figures measure different parts of an incident and can overlap. Adding them would produce an invalid combined rate.
17. How Much Web Server Traffic Comes From Bots and APIs?
Bots produced 31.2% of application traffic in Cloudflare’s 2024 application security study. APIs produced 60% of dynamic, non-cacheable traffic, while machine-learning discovery found a median of 33% more public API endpoints than customers had reported.
These results describe traffic and assets observed across Cloudflare customers. They do not mean that 31.2% of traffic to every server is malicious or that every organization has the same API inventory gap.
18. How Common Are Large DDoS Attacks Against Servers in 2026?
Cloudflare mitigated 935 network-layer attacks above 1 Tbps during the first half of 2026. The quarterly count rose from 130 in Q1 to 805 in Q2, a 519% increase.
Extreme events remained a small part of total attack volume. Cloudflare reported that 96.62% of network-layer attacks stayed below 500 Mbps and 90.60% ended within 10 minutes.
19. How Much Does a Server Security Incident Cost?
IBM placed the 2026 global average data breach cost at $4.99 million, up 12%. Sophos measured an average ransomware recovery cost of $1,700,200 and a median of $375,000, excluding ransom payments.
These figures are not interchangeable. IBM measures the broader cost of a data breach, while Sophos measures remediation after ransomware among organizations in its survey.
20. How Long Does Detection and Recovery Take After a Server Compromise?
Mandiant reported a global median attacker dwell time of 14 days in 2025, up from 11 days. Sophos found that 55% of ransomware victims recovered within one week, 83% recovered within one month, and 3% needed more than three months.
Dwell time measures how long an attacker remains in an environment before detection, while recovery time measures how long an organization needs to resume normal operations. A mature program tracks both because fast detection does not automatically produce fast restoration.
johnminnix
web









