694 sourced statistics on SaaS management: sprawl, shadow IT, shadow AI, AI agents, license waste and security. Torii's own discovery data first, then every credible number we could trace to its original source.
Popular:
694 statistics
106 publishers
10 topics
1 source link under every number
Torii research
The SaaS Benchmark Annual Report 2026
The observed data behind every Torii figure on this page: app sprawl by company size, the shadow IT leaderboard, AI adoption and shadow rates, license waste and contract overage.
Torii is a Leader in the 2026 Gartner® Magic Quadrant™ for SaaS Management Platforms
Gartner evaluated 16 SaaS management platform vendors. Torii has been named a Leader in every edition since the first Magic Quadrant for the category in 2024.
61.3% of apps in the average portfolio are shadow IT, discovered through usage, browser activity or direct signup rather than procurement, according to Torii's 2026 SaaS Benchmark.Torii, SaaS Benchmark Annual Report 2026
Torii discovered 694 new AI-native applications in 2025, more than double the 2023 figure of 317, according to its 2026 SaaS Benchmark.Torii, SaaS Benchmark Annual Report 2026
Salesforce tops Torii's License Utilization Audit with a 55% non-utilization rate, followed by PagerDuty (45%) and monday.com (40%), according to Torii's 2026 SaaS Benchmark.Torii, SaaS Benchmark Annual Report 2026
An average of 2.5% of license seats are assigned to offboarded users, roughly 1 in 40, according to Torii's 2026 SaaS Benchmark.Torii, SaaS Benchmark Annual Report 2026
According to CyberArk's 2025 Identity Security Landscape, there are 82 machine identities for every human in organizations worldwide.CyberArk, 2025 Identity Security Landscape
Threat actors exploited identity issues to gain initial access in 83% of incidents involving major cloud and SaaS-hosted environments, according to Google Cloud's H1 2026 Threat Horizons Report.Google Cloud, Cloud Threat Horizons Report H1 2026
App assignment requests make up 28.1% of all IT help desk tickets, more than four times the next most common request, according to Fixify's 2026 IT Help Desk Benchmark Report.Fixify, 2026 IT Help Desk Benchmark Report
The average organization runs 831 apps, and every one of them lands on someone's screen.
Who's counting?"How many apps does a company use" has five honest answersEach source counts something different. The further right, the more of the stack the method can see.
Observed data · thousands of Okta customers · 2025
Method and full statement
According to Okta's Businesses at Work 2025 report, the average company now deploys 101 apps, crossing 100 for the first time after years of flat growth.
Method
Telemetry: anonymized Okta customer data on apps deployed through the Okta Integration Network (OIN)
Sample
thousands of Okta customers (exact count not stated on page)
Observed data · nearly 100 million SaaS licenses · 2024
Method and full statement
According to Productiv data reported by CIO Dive, organizations cut their app portfolios 10% in 2023, but the average still stood at 342 apps, down from 374.
Method
Telemetry: Productiv analysis of 100+ billion app usage data points across nearly 100 million SaaS licenses
Okta's 2024 Businesses at Work report found the average company's app count grew 4% to 93, after stalling at 89 for two years.
Method
Telemetry: aggregated, anonymized data from Okta's 18,800+ global customers and the Okta Integration Network (7,000+ integrations); data Nov 1, 2022 to Oct 31, 2023
According to Okta, large companies with 2,000 or more employees deploy an average of 231 apps each, up 10% from 211 a year earlier.
Method
Telemetry: aggregated, anonymized data from Okta's 18,800+ global customers and the Okta Integration Network (7,000+ integrations); data Nov 1, 2022 to Oct 31, 2023
Okta's data shows companies with fewer than 2,000 employees deploy an average of 72 apps, up from 69 a year earlier.
Method
Telemetry: aggregated, anonymized data from Okta's 18,800+ global customers and the Okta Integration Network (7,000+ integrations); data Nov 1, 2022 to Oct 31, 2023
Tech startups (100 or fewer employees) grew their app count 15% in a year to an average of 47 apps, according to Okta.
Method
Telemetry: aggregated, anonymized data from Okta's 18,800+ global customers and the Okta Integration Network (7,000+ integrations); data Nov 1, 2022 to Oct 31, 2023; 'tech startups' = technology-sector companies with 100 or fewer employees
Okta found US companies deploy an average of 105 apps, while Canadian companies deploy just 66.
Method
Telemetry: aggregated, anonymized data from Okta's 18,800+ global customers and the Okta Integration Network (7,000+ integrations); data Nov 1, 2022 to Oct 31, 2023
According to BetterCloud, the average company's SaaS app count peaked at 130 in 2022, then fell 14% to 112 in 2023, the first decline in over a decade.
Method
Annual survey of IT professionals (sample size not stated in release)
Employees lose nearly seven hours a week, almost a full workday, to complicated processes and fragmented tools, according to Freshworks.
Method
Survey of 706 practitioners and decision-makers in IT, CX, finance and operations across the US, UK, India, France, Germany and Australia, plus 25 qualitative interviews
Workers toggle between apps and websites roughly 1,200 times a day, losing just under four hours a week (about 9% of work time) to reorienting, according to a Harvard Business Review study.
Method
Observational study: app-usage data from 20 teams (137 users) at three Fortune 500 companies, tracked for up to five weeks (3,200 days of work)
Workers juggle an average of 15 different software tools and four communication channels every day, according to Freshworks.
Method
Survey of 706 practitioners and decision-makers in IT, CX, finance and operations across the US, UK, India, France, Germany and Australia, plus 25 qualitative interviews
36% of customer experience teams name toggling between too many tools as a top frustration, according to Freshworks.
Method
Survey of 706 practitioners and decision-makers in IT, CX, finance and operations across the US, UK, India, France, Germany and Australia, plus 25 qualitative interviews
Survey · 3,300+ IT professionals and end users · 2025
Method and full statement
74% of IT professionals see clear evidence of technology overlaps and redundancies in their organizations, yet 63% say consolidating tools is not a high priority, according to Ivanti.
Observed data · one Fortune 500 consumer goods organization · 2022
Method and full statement
At one Fortune 500 company, a single supply-chain transaction meant switching about 350 times between 22 apps and websites, adding up to more than 3,600 toggles per employee per day.
Method
Observational study: app-usage data from 20 teams (137 users) at three Fortune 500 companies, tracked for up to five weeks (3,200 days of work); this figure is a single-company example
Context switching between digital tools hurts productivity for 45% of workers, according to a Qatalog study run with Cornell University's Ellis Idea Lab.
Method
Survey of 1,000 workers, run with the Ellis Idea Lab at Cornell University
Organizations now deploy an average of 27 AI-powered SaaS apps, about 22% of their total portfolio, according to BetterCloud's 2026 State of SaaS report.
Method
Survey of 525 IT and security professionals at SaaS-first organizations
Anthropic was the fastest-growing software vendor across SMB, mid-market and enterprise buyers in Q2 2026, the first time one vendor topped all three segments, according to Tropic.
Method
Transaction data: negotiated outcomes across $23B+ in tracked spend, 100,000+ negotiations, 30,000+ SKUs across 14,000+ suppliers (Tropic customers)
Mid-market companies use an average of 4.2 AI tools, but only 33% have a formal, consistently applied AI governance framework, according to Freshworks.
Method
Survey of 12,021 IT decision makers (director and above) in the US, UK, Germany, France, Singapore and India at organizations with 250+ employees, including 9,000+ mid-market (up to 5,000 employees)
Google Gemini adoption among organizations rose from 46% to 69% in a year, a sign that companies increasingly pay for multiple overlapping generative AI apps, according to Netskope.
Method
Telemetry: anonymized usage data from Netskope security platform customers
OpenAI was the fastest-growing software vendor of 2024 at 146% year-over-year growth, and 19 of the 20 fastest-growing vendors prominently featured AI, according to Tropic.
Method
Transaction data: analysis of $11B in corporate technology spending across 500+ Tropic customers
Compliance tool Vanta was the fastest-growing app in Okta's 2024 report, with 338% year-over-year growth in customers deploying it.
Method
Telemetry: aggregated, anonymized data from Okta's 18,800+ global customers and the Okta Integration Network (7,000+ integrations); data Nov 1, 2022 to Oct 31, 2023
61.3% of apps in the average portfolio are shadow IT, discovered through usage, browser activity or direct signup rather than procurement, according to Torii's 2026 SaaS Benchmark.
Method
Observed: aggregated, anonymized discovery data from environments Torii connects to
Survey · 680 companies, 18 industries, 21 countries · 2025
Method and full statement
Shadow IT, purchased by business units without IT oversight, represents 24% of total IT budgets, according to IBM Institute for Business Value research.
Method
Benchmarking data from IT leaders (CIOs, CTOs, VPs/directors of IT)
Businesses underestimate their software usage by 40% on average: for every 10 tools a company thinks it uses, 14 are actually in play, according to Cledara.
Method
Cledara transaction data (1M+ transactions with 5,000+ vendors) plus a survey of 200+ tech companies with fewer than 200 staff in the US, UK and EU
Productivity, Developer Tools, Design, and Sales and Marketing tools account for about 70% of all shadow apps, according to Torii's 2026 SaaS Benchmark.
Method
Observed: aggregated, anonymized discovery data from environments Torii connects to
The number of SaaS applications used in an enterprise grew 40% over two years, with an 85% increase in SaaS accounts per user, according to Grip Security.
Method
Telemetry: anonymized data from Grip's SaaS Security Control Plane covering 29M+ SaaS user accounts, 1.7M identities and 23,987 SaaS applications
Sample
29M+ SaaS user accounts, 1.7M identities, 23,987 SaaS apps
Observed data · Productiv customer portfolios · 2024
Method and full statement
Productiv's 2024 State of SaaS analysis found shadow IT made up 48% of the average enterprise app portfolio in 2023, down from 53% the year before.
Method
Telemetry: Productiv analysis of 100B+ app usage data points across nearly 100M SaaS licenses; shadow IT = non-managed apps that are expensed, found by network monitoring, or seen via Google SSO
Capterra found 57% of small and midsize businesses have had high-impact shadow IT efforts, and 85% of those have a shadow IT team operating right now.
Method
Survey: Capterra survey, January 2023, of 300 IT project managers, SMB leaders and IT leaders at businesses with 1,000 or fewer employees and <=$500M revenue that had high-impact shadow IT experience
Cledara's State of Shadow IT study found 65% of all SaaS applications accessed at 200 companies were shadow IT, an average of 75 unapproved tools per company.
Method
Telemetry: Cledara Engage browser tool deployed on all employees' computers at 200 companies, counting page loads of unauthorized SaaS products over 30 days in Sept to Oct 2023
Sample
200 companies (many in regulated sectors; small/mid-size tech companies)
Only 3.5% of companies in Cledara's study had shadow IT making up less than 20% of their tool usage.
Method
Telemetry: Cledara Engage browser tool deployed on all employees' computers at 200 companies, counting page loads of unauthorized SaaS products over 30 days in Sept to Oct 2023
Gartner found 74% of technology purchases are funded at least partly by business units outside of IT; only 26% are funded entirely by the IT organization.
Method
Survey: Gartner survey of 1,120 manager-level-or-higher respondents at organizations with $1M+ annual revenue in North America, Western Europe and Asia/Pacific, about large technology purchases
According to 1Password's 2025 Access-Trust Gap report, 52% of employees have downloaded apps without IT approval.
Method
Survey: online survey of 5,200 desk-based knowledge workers (including IT and security professionals) in the U.S., Canada, UK, Germany, France and Singapore
1Password's 2025 Access-Trust Gap report found 42% of employees bypass IT to boost their productivity.
Method
Survey: online survey of 5,200 desk-based knowledge workers (including IT and security professionals) in the U.S., Canada, UK, Germany, France and Singapore
Sample
n=5,200 knowledge workers; press release says its North American figures reflect 1,500 workers
Shadow IT varies by country: 55% of employees in Singapore admit downloading apps without IT approval, versus 46% in Germany, 44% in the U.S., 43% in the UK and 33% in France, per 1Password's 2025 report.
Method
Survey: online survey of 5,200 desk-based knowledge workers (including IT and security professionals) in the U.S., Canada, UK, Germany, France and Singapore
Sample
n=5,200 knowledge workers (per-country sizes not stated)
Survey · n=3,300+ IT professionals and end users · 2025
Method and full statement
27% of office workers say they regularly use unauthorized tools and apps out of frustration with their employer-provided tools, according to Ivanti's 2025 Digital Employee Experience Report.
Method
Survey: Ivanti survey of 3,300+ IT professionals and end users worldwide, administered by Ravn Research (panel via MSI Advanced Customer Insights); results unweighted
Survey · n=3,300+ IT professionals and end users · 2025
Method and full statement
Nearly 40% of office workers say they bypass employer-provided tech support entirely when they hit a technology problem, usually because they can fix it faster themselves, per Ivanti.
Method
Survey: Ivanti survey of 3,300+ IT professionals and end users worldwide, administered by Ravn Research (panel via MSI Advanced Customer Insights); results unweighted
Across 200 companies, Cledara counted 23.6 million instances of shadow IT usage over 30 days: an employee opened an unauthorized app every 4.9 seconds of the workday.
Method
Telemetry: Cledara Engage browser tool deployed on all employees' computers at 200 companies, counting page loads of unauthorized SaaS products over 30 days in Sept to Oct 2023
Where BYOD is banned, 78% of employees use personal devices for work anyway, according to Ivanti's Securing the Borderless Digital Landscape report.
Method
Survey: two Ivanti surveys (Oct 2024 and Feb 2025) of 600+ executive leaders, 3,000 IT and cybersecurity professionals and 6,000 office workers worldwide, administered by Ravn Research; unweighted
Observed data · Netskope One customer organizations · 2026
Method and full statement
Google Drive is the personal app organizations most often control, with 43% applying real-time protections, followed by Gmail (31%) and OneDrive (28%), per Netskope.
Method
Telemetry: anonymized usage data collected by the Netskope One platform, Oct 1, 2024 to Oct 31, 2025
Sample
Netskope One customer organizations (count not stated; 'millions of users')
LayerX's Browser Security Report 2025 found 43% of SaaS applications in organizational networks are accessed with personal (non-corporate) credentials.
Method
Telemetry: LayerX browser-extension telemetry from 'millions of enterprise browser sessions' across LayerX enterprise customers
87% of employee activity in chat and instant-messaging apps happens through personal, non-corporate accounts, according to LayerX's Browser Security Report 2025.
Method
Telemetry: LayerX browser-extension telemetry from 'millions of enterprise browser sessions' across LayerX enterprise customers
38% of file uploads to file storage and sharing platforms are made through personal accounts, and 41% of files uploaded there contain PII or payment card data, per LayerX.
Method
Telemetry: LayerX in-browser enterprise browsing telemetry from its enterprise customer base
Observed data · tens of thousands of enterprise users · 2025
Method and full statement
99% of enterprise users have at least one browser extension installed, and 53% have more than 10, according to LayerX's Enterprise Browser Extension Security Report 2025.
Method
Telemetry: real-life usage data from enterprise users in LayerX's customer base ('tens of thousands of real enterprise users'), combined with public extension-store data
Observed data · tens of thousands of enterprise users · 2025
Method and full statement
53% of enterprise users have installed browser extensions with 'high' or 'critical' permission scopes, able to access cookies, passwords and browsing data, per LayerX.
Method
Telemetry: real-life usage data from enterprise users in LayerX's customer base ('tens of thousands of real enterprise users'), combined with public extension-store data
17% of browser extensions installed by enterprise users come from non-official stores and 26% are side-loaded by external applications, according to LayerX's Browser Security Report 2025.
Method
Telemetry: LayerX browser-extension telemetry from 'millions of enterprise browser sessions' across LayerX enterprise customers
Observed data · tens of thousands of enterprise users · 2025
Method and full statement
54% of browser extension publishers use a free webmail account, and 79% have published only a single extension, per LayerX.
Method
Telemetry: real-life usage data from enterprise users in LayerX's customer base ('tens of thousands of real enterprise users'), combined with public extension-store data
Observed data · tens of thousands of enterprise users · 2025
Method and full statement
51% of all browser extensions haven't received an update in over a year, LayerX reports.
Method
Telemetry: real-life usage data from enterprise users in LayerX's customer base ('tens of thousands of real enterprise users'), combined with public extension-store data
Verizon's 2025 Data Breach Investigations Report found 46% of systems compromised by infostealer malware that held corporate logins were non-managed devices, most likely personal devices or devices used outside policy.
Method
Breach data: analysis of infostealer credential logs and marketplace postings; DBIR analyzed 22,000+ incidents incl. 12,195 confirmed breaches
Sample
Subset of infostealer logs with business-app domains and OS info
Three in four IT workers say BYOD is a regular occurrence at their organization, though only 52% say it is explicitly allowed, per Ivanti.
Method
Survey: two Ivanti surveys (Oct 2024 and Feb 2025) of 600+ executive leaders, 3,000 IT and cybersecurity professionals and 6,000 office workers worldwide, administered by Ravn Research; unweighted
One in two office workers use personal devices to log into work networks and software, and 32% of them say their employer doesn't know, according to Ivanti research.
Method
Survey: based in part on three Ivanti surveys (2024 Everywhere Work, 2024 State of Cybersecurity, 2024 DEX) covering 20,000+ executives, IT pros, security pros and office workers
Sample
20,000+ across three surveys (subset for this question not stated)
47% of companies let employees access company resources from unmanaged devices using credentials alone, according to Kolide's (now 1Password) Shadow IT report.
Method
Survey: Kolide survey of knowledge workers incl. IT, security, developers, executives (late 2023); sample size not stated on this page
49% of developers report doing software development on personal devices, and 35% of security professionals use personal devices to manage cloud infrastructure, per Kolide's Shadow IT report.
Method
Survey: Kolide survey of knowledge workers (late 2023); sample size not stated on this page
Companies with more than 2,000 employees have an average of 1,454 different browser extensions installed, according to Spin.AI's analysis of its customers.
Method
Telemetry: Spin.AI assessment of 1,000,000+ browser extensions and third-party OAuth apps seen across its customers
Observed data · Netskope One customer organizations · 2026
Method and full statement
Regulated data (personal, financial and healthcare information) accounts for 54% of data policy violations linked to personal cloud apps, per Netskope's Cloud and Threat Report 2026.
Method
Telemetry: anonymized usage data collected by the Netskope One platform, Oct 1, 2024 to Oct 31, 2025
Sample
Netskope One customer organizations (count not stated; 'millions of users')
In 1Password's 2025 survey, 49% of security and IT professionals said employee use of unapproved software has compromised their ability to maintain adequate protections.
Method
Survey: online survey of 5,200 desk-based knowledge workers (including IT and security professionals) in the U.S., Canada, UK, Germany, France and Singapore; this figure is from the IT/security professional subset
Sample
n=5,200 knowledge workers (IT/security subset size not stated)
Survey · n=420 IT and security professionals · 2025
Method and full statement
56% of organizations say employees upload sensitive data to unauthorized SaaS apps, per the Cloud Security Alliance's 2025 State of SaaS Security Report.
Method
Survey: CSA survey of IT and security professionals conducted January 2025, commissioned by Valence Security
In JumpCloud's Q1 2025 SME IT Trends survey, 90% of SME IT professionals said they worry about employees using unauthorized apps, yet 38% have no full app discovery process.
Method
Survey: JumpCloud-commissioned survey of 900 SME IT professionals in the U.S., UK and Australia
38% of SME IT professionals say they don't have a full process for discovering the apps employees use, according to JumpCloud's Q1 2025 SME IT Trends report.
Method
Survey: JumpCloud-commissioned survey of 900 SME IT professionals in the U.S., UK and Australia
45% of IT professionals say they lack sufficient data about shadow IT, and 38% lack sufficient data about the devices accessing their network, per Ivanti.
Method
Survey: two Ivanti surveys (Oct 2024 and Feb 2025) of 600+ executive leaders, 3,000 IT and cybersecurity professionals and 6,000 office workers worldwide, administered by Ravn Research; unweighted
Kaspersky research found 11% of companies worldwide suffered cyber incidents caused by employees' use of shadow IT over two years; in the IT industry, 16% of incidents were due to shadow IT.
Method
Survey: Arlington Research for Kaspersky, 1,260 interviews with manager-level IT and IT security staff at SMEs (100+ employees) and enterprises (1,000+) in 19 countries, 2023
76% of SMBs that had high-impact shadow IT efforts say the effort posed a moderate to severe cybersecurity threat, per Capterra.
Method
Survey: Capterra survey, January 2023, of 300 IT project managers, SMB leaders and IT leaders at businesses with 1,000 or fewer employees and <=$500M revenue that had high-impact shadow IT experience
89% of SMBs with high-impact shadow IT efforts report negative financial consequences, yet 80% also report a positive long-term financial impact, Capterra found.
Method
Survey: Capterra survey, January 2023, of 300 IT project managers, SMB leaders and IT leaders at businesses with 1,000 or fewer employees and <=$500M revenue that had high-impact shadow IT experience
91% of SMBs that had high-impact shadow IT efforts report challenges integrating the shadow IT work into their official environments, according to Capterra.
Method
Survey: Capterra survey, January 2023, of 300 IT project managers, SMB leaders and IT leaders at businesses with 1,000 or fewer employees and <=$500M revenue that had high-impact shadow IT experience
Cledara's analysis of SaaS spend data finds shadow IT accounts for about 35-40% of total SaaS spend at the median company, and as much as 60-70% at some.
Method
Cledara analysis of its customers' software spend data; method not stated in detail
Survey · n=48,340 people across 47 countries · 2025
Method and full statement
According to the University of Melbourne and KPMG's 2025 global study, 57% of employees admit to hiding their AI use or presenting AI-generated content as their own.
Method
Online survey of nationally representative samples of adults in 47 countries; workplace findings from the employed subsample
ChatGPT leads Torii's AI Leaders of 2025 with a 95.3% adoption rate, followed by Zapier (93.9%) and Grammarly (93.3%), according to Torii's 2026 SaaS Benchmark.
Method
Observed: aggregated, anonymized discovery data from environments Torii connects to
Grok has a 76% shadow rate against 65% adoption, compared with ChatGPT's 28% shadow rate, according to Torii's 2026 SaaS Benchmark LLM adoption vs shadow IT chart.
Method
Observed: aggregated, anonymized discovery data from environments Torii connects to
Observed data · subset of Netskope customers · 2026
Method and full statement
According to Netskope's AI Report 2026, the share of enterprise users using AI apps weekly rose from 34% to 59% in the median organization over the past year.
Method
Telemetry: aggregate usage data collected by the Netskope One platform for a subset of Netskope customers
According to Harmonic Security's analysis of 22.4 million enterprise AI prompts in 2025, 16.9% of all sensitive data exposures flowed through personal free-tier AI accounts where IT has no visibility.
Method
Telemetry: 22,458,240 enterprise GenAI prompts and file uploads across 665 AI tools observed by Harmonic's browser product
According to LayerX's State of AI Usage Report 2026, 47% of enterprise AI conversations are done through personal identities rather than corporate accounts.
Method
Telemetry: enterprise browser data from LayerX customers (method details not stated on the report page)
Survey · n=3,400+ digital trust professionals · 2026
Method and full statement
According to ISACA's 2026 AI Pulse Poll, 90% of digital trust professionals believe employees are using AI in their organization, but only 22% say AI ROI has met or exceeded expectations.
Method
Global ISACA poll of digital trust professionals in IT audit, governance, cybersecurity, privacy and emerging tech roles
Survey · n=48,340 people across 47 countries · 2025
Method and full statement
According to the University of Melbourne and KPMG's 2025 global study, 56% of employees say they have used AI tools at work without knowing if it is allowed.
Method
Online survey of nationally representative samples of adults in 47 countries; workplace findings from the employed subsample
According to UpGuard's State of Shadow AI report, 8 out of 10 employees use unauthorized AI tools, and 68% of security leaders admit to incorporating unauthorized AI into their daily workflows.
Method
Two surveys: security leaders via Dynata (companies with 200+ employees in US, Canada, APAC, India) and employees via Prolific (US and UK)
According to Ivanti's 2025 Technology at Work Report, nearly a third (32%) of employees who use GenAI tools at work keep it a secret from their employer.
Method
Survey of office workers and IT and cybersecurity professionals
Sample
n=6,000+ office workers and 1,200 IT/security professionals
According to MIT NANDA's State of AI in Business 2025 report, only 40% of companies say they purchased an official LLM subscription, yet workers at over 90% of companies surveyed reported regular use of personal AI tools for work.
Method
Multi-method: review of 300+ public AI initiatives, structured interviews with representatives of 52 organizations, survey of 153 senior leaders at four industry conferences
According to 1Password's 2025 Access-Trust Gap report, 73% of employees are encouraged to use AI at work, but 37% say they follow their company's AI policies only 'most of the time.'
Survey · ~500 U.S. enterprise decision-makers · 2025
Method and full statement
Menlo Ventures found that 27% of all AI application spend enters companies through product-led growth (individual users), nearly 4x the 7% rate in traditional software, and close to 40% when personal-card shadow AI is counted.
Method
Survey of ~500 U.S. enterprise AI decision-makers combined with a bottoms-up model of the generative AI market (model APIs, infrastructure, applications)
According to a Software AG study of 6,000 knowledge workers, half of all employees use shadow AI, and 46% would refuse to stop even if their organization banned it.
Method
Survey of knowledge workers commissioned by Software AG
According to Salesforce's 2023 Generative AI Snapshot research, 28% of workers use generative AI at work, and over half of them do so without formal approval from their employer.
Method
Double-anonymous survey conducted with YouGov of full-time employees in 14 countries
Survey · n=48,340 people across 47 countries · 2025
Method and full statement
According to the University of Melbourne and KPMG's 2025 global study of 48,000 people in 47 countries, about half (48 to 49%) of employees have uploaded sensitive company information or copyrighted material into public AI tools.
Method
Online survey of nationally representative samples of adults in 47 countries; workplace findings from the employed subsample
According to Netskope's Cloud and Threat Report 2026, the average organization sees 223 incidents per month of users sending sensitive data to genAI apps, double the year before.
Method
Telemetry: anonymized usage data collected by the Netskope One platform from Netskope customers
According to Netskope's Cloud and Threat Report 2026, source code (42%), regulated data (32%) and intellectual property (16%) were the top data types in genAI data policy violations.
Method
Telemetry: anonymized usage data collected by the Netskope One platform from Netskope customers
According to Cyberhaven's 2025 AI Adoption and Risk Report, 34.8% of the corporate data employees put into AI tools is sensitive, up from 10.7% two years earlier.
Method
Telemetry: actual AI usage patterns of 7 million workers observed by Cyberhaven's data security platform
According to Cyberhaven's 2025 AI Adoption and Risk Report, 71.7% of AI tools used in workplaces are high or critical risk, and 83.8% of enterprise data going to AI flows to these risky tools.
Method
Telemetry: actual AI usage patterns of 7 million workers observed by Cyberhaven's data security platform
According to Harmonic Security's Q3 2025 analysis, 26.38% of files uploaded to GenAI tools contained sensitive information, up from 22% in Q2.
Method
Telemetry: anonymized enterprise data from Harmonic Protect covering over three million prompts and file uploads across 300 GenAI and AI-embedded tools, US and UK organizations
According to LayerX's Enterprise AI and SaaS Data Security Report 2025, GenAI tools account for 32% of all corporate-to-personal data transfers, making AI the top data exfiltration channel.
Method
Telemetry: real-world enterprise browsing data from LayerX's enterprise customers
According to a TELUS Digital survey, 57% of enterprise employees who use GenAI at work admit to entering sensitive information into public AI assistants.
Method
Pollfish survey of US adults at companies with 5,000+ employees who had used an AI assistant at work
Survey · n=2,600 privacy and security professionals · 2025
Method and full statement
According to Cisco's 2025 Data Privacy Benchmark Study, 64% of privacy and security professionals worry about inadvertently sharing sensitive information through GenAI, yet nearly half admit inputting personal employee or non-public data into GenAI tools.
Method
Survey of privacy and security professionals in 12 countries
Survey · n=2,600 privacy and security professionals · 2024
Method and full statement
According to Cisco's 2024 Data Privacy Benchmark Study, 48% of privacy and security professionals admit entering non-public company information into GenAI tools.
Method
Survey of privacy and security professionals across 12 geographies
According to Harmonic Security's Q1 2025 research, the average company interacted with 254 distinct AI applications, not counting mobile or API access.
Method
Telemetry: over 176,000 AI prompts and thousands of file uploads from a sample of 8,000 enterprise users
According to Netskope's Cloud and Threat Report 2026, the amount of data sent to SaaS genAI apps grew sixfold in a year, from 3,000 to 18,000 prompts per month per organization, while user counts tripled.
Method
Telemetry: anonymized usage data collected by the Netskope One platform from Netskope customers
According to Netskope's Cloud and Threat Report 2026, the number of genAI apps it tracks grew fivefold to more than 1,600, while the average organization uses 8 AI apps, up from 6.
Method
Telemetry: anonymized usage data collected by the Netskope One platform from Netskope customers
According to Cyberhaven's 2026 AI Adoption & Risk Report, the top 1% of early-adopter organizations use more than 300 GenAI tools, while cautious enterprises use fewer than 15.
Method
Telemetry: billions of real-world data movements around GenAI SaaS apps, endpoint AI apps and AI agents observed by Cyberhaven
According to Harmonic Security, enterprise employees sent prompts to 665 different AI tools in 2025, but six applications accounted for 92.6% of sensitive data exposure.
Method
Telemetry: 22,458,240 enterprise GenAI prompts and file uploads across 665 AI tools observed by Harmonic's browser product
According to LayerX's State of AI Usage Report 2026, nearly 75% of AI browser extensions are granted high or critical permissions, and 16.31% have known CVEs.
Method
Telemetry: enterprise browser data from LayerX customers (method details not stated on the report page)
According to Reco's State of Agent Security 2026, small and mid-size firms average 414 unsanctioned AI tools per 1,000 employees, even where 79% of SaaS is authorized.
Method
Reco platform telemetry, independent analysis of 500 published npm MCP servers, and the public CVE record
Sample
500 MCP servers; 260+ AI agents and apps in telemetry
According to Zscaler's ThreatLabz 2026 AI Security Report, the number of applications driving AI/ML transactions quadrupled year over year to more than 3,400.
Method
Telemetry: 989.3 billion AI/ML transactions generated by about 9,000 organizations on the Zscaler Zero Trust Exchange
According to Harmonic Security's Q3 2025 analysis, the average organization's employees used 27 distinct AI tools in the quarter.
Method
Telemetry: anonymized enterprise data from Harmonic Protect covering over three million prompts and file uploads across 300 GenAI and AI-embedded tools, US and UK organizations
Observed data · tens of thousands of enterprise users · 2025
Method and full statement
According to LayerX's Enterprise Browser Extension Security Report 2025, over 20% of enterprise users have a GenAI-enabled browser extension installed, and 58% of GenAI extensions have high or critical permissions.
Method
Telemetry: real-life usage data from enterprise users in LayerX's customer base combined with public extension store data
Sample
tens of thousands of enterprise users (per release)
Observed data · hundreds of global organizations · 2025
Method and full statement
According to Menlo Security's 2025 report, web traffic to GenAI sites jumped 50%, from 7 billion visits in February 2024 to 10.53 billion in January 2025.
Method
Telemetry: browser data from hundreds of global organizations using Menlo Security
Observed data · 50+ enterprise environments · 2025
Method and full statement
According to Reco's 2025 State of Shadow AI Report, small businesses average 269 shadow AI tools per 1,000 employees, and 27% of employees at companies with 11 to 50 workers use unsanctioned AI tools.
Method
Telemetry: Reco platform monitoring across 50+ enterprise environments and 55,000+ SaaS applications
Survey · n=3,400+ digital trust professionals · 2026
Method and full statement
According to ISACA's 2026 AI Pulse Poll, only 38% of organizations have a formal, comprehensive AI policy, up from 28% in 2025, and 25% have no active policy.
Method
Global ISACA poll of digital trust professionals in IT audit, governance, cybersecurity, privacy and emerging tech roles
Survey · n=3,400+ digital trust professionals · 2026
Method and full statement
According to ISACA's 2026 AI Pulse Poll, 56% of digital trust professionals do not know how quickly they could halt an AI system during a security incident.
Survey · n=3,400+ digital trust professionals · 2026
Method and full statement
According to ISACA's 2026 AI Pulse Poll, 20% of respondents don't know who would be responsible if an AI system caused harm or serious error in their organization.
According to Check Point's 2026 Cloud Security Report, 77% of organizations have updated their security strategy in response to AI, but only 26% have the architecture to enforce it.
According to Check Point's 2026 Cloud Security Report, 24% of organizations have no AI-specific access controls, and only 16% enforce controls consistently.
Flexera found nearly half of organizations don't always know how or when employees are using AI tools, and 85% say IT visibility gaps pose a major risk.
Method
method not stated on page (Flexera survey research)
According to IBM's Cost of a Data Breach Report 2025, 63% of breached organizations either don't have an AI governance policy or are still developing one.
Method
Ponemon Institute interviews/analysis of real data breaches experienced by organizations globally
According to IBM's Cost of a Data Breach Report 2025, only 34% of organizations with AI governance policies perform regular audits for unsanctioned AI.
Method
Ponemon Institute interviews/analysis of real data breaches experienced by organizations globally
According to a TELUS Digital survey, only 24% of enterprise employees who use AI assistants say their company requires mandatory AI assistant training.
Method
Pollfish survey of US adults at companies with 5,000+ employees who had used an AI assistant at work
According to a Gartner survey of 302 cybersecurity leaders, 69% of organizations suspect or have evidence that employees are using prohibited public GenAI.
Method
Gartner survey of cybersecurity leaders, plus Gartner analyst prediction
Survey · n=48,340 people across 47 countries · 2025
Method and full statement
According to the University of Melbourne and KPMG's 2025 global study, only two in five employees say their organization has a policy guiding generative AI use.
Method
Online survey of nationally representative samples of adults in 47 countries; workplace findings from the employed subsample
Survey · n=48,340 people across 47 countries · 2025
Method and full statement
According to the University of Melbourne and KPMG's 2025 global study, uploading sensitive data to public AI was most common at organizations that had banned generative AI (67%), versus 33% where there was no policy.
Method
Online survey of nationally representative samples of adults in 47 countries; workplace findings from the employed subsample
According to Komprise's 2025 IT survey, 90% of IT leaders are concerned about shadow AI from a privacy and security standpoint, and 46% are extremely worried.
Method
Survey of IT directors and executives at US enterprises with 1,000+ employees
According to Gallup, 44% of US employees say their organization has begun integrating AI, but only 22% say it has communicated a clear plan or strategy for doing so.
Method
Self-administered web surveys of a random, probability-based sample of US full- and part-time employees in the Gallup Panel, weighted for nonresponse
Survey · n=2,600 privacy and security professionals · 2024
Method and full statement
According to Cisco's 2024 Data Privacy Benchmark Study, 27% of organizations had banned the use of generative AI, at least temporarily, over privacy and data security risks.
Method
Survey of privacy and security professionals across 12 geographies
According to Check Point's 2026 Cloud Security Report, 78% of organizations reported confirmed or suspected AI-related security incidents over the past year.
According to Komprise's 2025 IT survey, nearly 80% of IT leaders say their organization has experienced negative outcomes from employee use of generative AI, including 44% citing sensitive data leaking into AI.
Method
Survey of IT directors and executives at US enterprises with 1,000+ employees
A company's top 10 software vendors account for roughly 74% of its tracked software spend, a share that hasn't moved in three years, according to Tropic.
Method
Transaction data: negotiated outcomes across $23B+ in tracked spend, 100,000+ negotiations, 30,000+ SKUs across 14,000+ suppliers (Tropic customers)
Observed data · $18B+ spend under management · 2026
Method and full statement
Mid-market and enterprise companies grew software spend nearly 58% year over year, and SMB/growth companies 50%, according to Tropic.
Method
Transaction data: analysis of $18B+ in spend under management across Tropic customers; cohorts SMB/Growth (1-250 employees) and Mid-Market/Enterprise (251+)
Gartner estimates up to $234 billion in enterprise application software spending, about 20% of enterprise SaaS spend, is at risk from AI agents by 2030.
Companies with 1,000 to 10,000 employees spend an average of $21 million a year on software, against $1.9 million for small businesses, according to Tropic.
Method
Transaction data: analysis of $11B in corporate technology spending across 500+ Tropic customers
Mid-market companies spend about $14,000 per employee on software, more than enterprises ($9,000), while growth-stage companies spend the most at $17,000, according to Tropic.
Method
Transaction data: analysis of $11B in corporate technology spending across 500+ Tropic customers
The share of IT budgets going to on-demand technology (cloud, SaaS and GenAI) is expected to rise from 29% to 41% within a year, according to Capgemini.
Method
Survey of 1,000 executives at organizations with $1B+ annual revenue using cloud, SaaS and GenAI, across 12 sectors and 14 countries; fielded May 2025
Gartner predicts that by 2030, 35% of point-product SaaS tools will be replaced by AI agents or absorbed into the agent ecosystems of major SaaS providers.
Software vendors are opening renewal talks with AI-linked price increases of 20-37%, against a typical 3-9% SaaS uplift, according to Tropic's 2026 data.
Method
Transaction data: negotiated outcomes across $23B+ in tracked spend, 100,000+ negotiations, 30,000+ SKUs across 14,000+ suppliers (Tropic customers)
Salesforce raised list prices by an average of 6% on August 1, 2025 for Enterprise and Unlimited Editions of Sales Cloud, Service Cloud, Field Service and select Industries Clouds.
Atlassian raised cloud list prices on October 15, 2025: 5% for Standard, 7.5% for Premium and 7.5% to 10% for Enterprise editions of Jira, Confluence and Jira Service Management, with Bitbucket up 10%.
Google raised Workspace Business Standard from $12 to $14 per user per month on annual plans in 2025 as it bundled Gemini AI into all Business plans, a roughly 17% increase.
ICONIQ found that while many software companies include AI features for free today, 37% plan to change their pricing in the next year to reflect AI value and usage.
Method
Survey of executives at software companies plus interviews with AI leaders in the ICONIQ community
Microsoft is raising Microsoft 365 E3 from $36 to $39 per user per month (8%) and Office 365 E3 from $23 to $26 (13%) on July 1, 2026, alongside new AI capabilities in the suites.
When Google bundled Gemini into Workspace in January 2025, Business Standard rose to $14 per user per month, $2 (about 17%) more than the plan cost without Gemini.
Microsoft raised U.S. Microsoft 365 Personal and Family prices by $3 per month in January 2025, the first increase since launch, when it bundled Copilot into the plans.
Vertice's SaaS Inflation Index found that 73% of software vendors raised their prices in 2023, and SaaS inflation ran at 8.7%, more than double US CPI.
Method
Price index from purchasing data on 16,000 software vendors
Per-usage pricing became the single most common SaaS pricing model in Q2 2026 at 36.5% of contracts, overtaking per-user pricing at 32.4%, according to Vertice.
Method
Contract data: over $75bn of global processed spend managed by Vertice in 2026
Pure consumption pricing drives the effective cost per user up by as much as 37%, and hybrid models by 21% on average, compared with seat-based pricing, Vertice reports.
Method
Contract data: over $75bn of global processed spend managed by Vertice in 2026
82% of senior leaders at organizations investing in AI expect traditional per-seat SaaS pricing to become less relevant in their industry within five years, according to EY's US AI Pulse Survey.
Method
Online survey of US-employed decision-makers (SVP+) across sectors, commissioned by EY
Hybrid pricing rose from 27% to 41% of software companies in a year while pure seat-based pricing fell from 21% to 15%, according to Growth Unhinged's 2025 State of B2B Monetization survey.
Method
Survey of software companies, typical respondent $1-20M ARR, US-headquartered
Only 5% of software companies use outcome-based pricing as their primary model today, but 25% expect to by 2028, per Growth Unhinged's 2025 State of B2B Monetization survey.
Method
Survey of software companies, typical respondent $1-20M ARR, US-headquartered
Salesforce tops Torii's License Utilization Audit with a 55% non-utilization rate, followed by PagerDuty (45%) and monday.com (40%), according to Torii's 2026 SaaS Benchmark.
Method
Observed: aggregated, anonymized discovery data from environments Torii connects to
As of Q2 2026, Vertice's spend data shows 14% of SaaS licenses are fully unused and a further 51% are underutilized (under half of purchased seats in use), so over half of all licenses sit in the underused bucket.
Method
Telemetry/platform data: over $75bn of global processed spend managed by Vertice in 2026
Vertice estimates that enterprises with 10,000+ employees waste $18.9M a year on unused and underutilized software, roughly 10 times what a 1,000 to 2,500-employee company wastes.
Method
Telemetry/platform data: over $75bn of global processed spend managed by Vertice in 2026
Vertice found that wasted software spend ranges from $1.75M a year at companies with 500 to 1,000 employees up to $18.9M at enterprises with 10,000+ employees.
Method
Telemetry/platform data: over $75bn of global processed spend managed by Vertice in 2026
Estimated wasted cloud spend rose to 29% in 2026, the first increase in five years, driven by AI workloads, according to Flexera's 2026 State of the Cloud Report.
Gartner predicts that through 2028, organizations that fail to attain centralized visibility and coordinate SaaS life cycles will overspend on SaaS by at least 25%, due to unused entitlements and overlapping tools.
Companies waste $1 of every $5 spent on software to failed implementations, underused tools and unexpected costs, according to Freshworks' 2025 Cost of Complexity report.
Method
Survey of 706 practitioners and decision-makers in IT, CX, finance and operations across the US, UK, India, France, Germany and Australia, plus 25 qualitative interviews
Nearly one in three IT professionals (31%) say their organizations do not track unused or underused software licenses, according to Ivanti's 2025 Technology at Work report.
Method
Survey of office workers and IT/cybersecurity professionals (Ravn Research)
Sample
1,200 IT and cybersecurity professionals + 6,000+ office workers
33% of midsized-enterprise IT leaders estimate they waste 10% of their IT budget on underused software and SaaS licenses, 46% say 25%, and 17% say half or more, according to a Block 64 survey.
Method
Survey of midsized enterprise IT leaders across North America
Even advanced IT asset management practitioners self-estimate that 20% of SaaS spend is wasted, alongside 30% of desktop software spend, according to Flexera's 2024 State of ITAM Report.
Method
Survey of professionals in organizations with 1,000+ employees who manage or participate in ITAM, SAM and HAM processes
Nexthink found that half (49.96%) of all installed software went unused by employees, costing businesses about $45M per month across 30+ popular tools.
Method
Telemetry: endpoint data from more than 6 million customer environments across 8 industries and 12 regions; cost modeled on 30+ tools at $8-$83 per user per month
The number-one product-related reason for software purchase regret is the software being more expensive than expected, cited by 35% of regretful US buyers, according to Capterra.
Method
Online survey of software purchase decision-makers at businesses with 5+ employees
Organizations that begin negotiating 120+ days before a SaaS contract expires save an average of 23.3% more than those who wait until the final month, according to Vertice.
Method
Negotiation outcome data: over $75bn of global processed spend managed by Vertice in 2026
Cledara found that companies starting renewal negotiations 90 days ahead achieved average savings of 49%, compared with 19% when they started 30 to 90 days out.
Method
Platform data from Cledara's SaaS management platform across thousands of subscriptions
45% of leaders name price hikes as their top frustration at SaaS renewal time, and 30% say they miss contract alerts and get auto-renewed, according to Spendflo.
Method
method not stated (survey of finance/procurement leaders implied)
Multi-year commitments made up just 18% of software renewal transactions on Vendr's platform in 2023, as multi-year renewals fell 28% compared with 2021, according to Vendr.
Method
Transaction data: more than $3B of software spend processed by Vendr
Vertice's benchmarks show a poorly negotiated deal in categories like CRM, ERP and project management can cost up to three times what a well-negotiated one does for comparable software.
Method
Pricing benchmark data: over $75bn of global processed spend managed by Vertice in 2026
Vendr reported that average contract values fell 20%, from $50,000 to $40,000, during 2024 as buyers rightsized at renewal in what it called the 'Year of the Descope'.
Method
Transaction data from Vendr's buying platform; sampling method not detailed
56% of organizations are rightsizing contracts and subscriptions and 59% are actively tracking usage to cut SaaS costs, Flexera's 2025 State of ITAM Report found.
Method
Survey of global IT professionals across industries
63% of IT teams say too many unused or underutilized SaaS apps and licenses, or budget pressure, are driving app consolidation, per BetterCloud's 2025 State of SaaS report.
Reusing licenses instead of buying new ones (non-cloud) was the top way SAM teams achieved significant savings in the past year, cited by 45%, ahead of better vendor negotiation at 37%, per Flexera's 2024 State of ITAM Report.
Method
Survey of professionals in organizations with 1,000+ employees who manage or participate in ITAM, SAM and HAM processes
55% of organizations saved more than $1 million through software asset management in a year, and 16% saved more than $10 million, according to Flexera's 2023 State of ITAM Report.
Method
Survey of global professionals in organizations with at least 1,000 employees
Respondents reporting Oracle audit activity rose to 38% from 24% a year earlier, and Adobe from 24% to 32%, according to Flexera's 2026 State of ITAM Report.
Method
Survey of technology professionals worldwide across industries
IT asset management teams spend 32% of their time on software optimization and another 22% responding to audits, according to Flexera's 2026 State of ITAM Report.
Method
Survey of technology professionals worldwide across industries
Half of organizations say Microsoft audited them in the past three years, followed by IBM at 37% and SAP at 32%, per Flexera's 2025 State of ITAM Report.
Method
Survey of global IT professionals across industries
23% of software producers report customer license overuse (unintentional or otherwise) as a major problem and another 47% as a moderate concern, according to Revenera's Monetization Monitor 2026 Outlook.
Method
Survey of leaders at software producers (42% C-level, 34% director)
22% of IT leaders paid more than $5 million in software audit costs over three years, up from 15% the previous year, according to Flexera's 2024 State of ITAM Report.
Method
Survey of professionals in organizations with 1,000+ employees who manage or participate in ITAM, SAM and HAM processes
Survey · ~500 U.S. enterprise decision-makers · 2025
Method and full statement
According to Menlo Ventures, enterprise generative AI spend reached $37B in 2025, up from $1.7B in 2023, and now equals 6% of the global SaaS market.
Method
Survey of ~500 U.S. enterprise AI decision-makers combined with a bottoms-up model of the generative AI market (model APIs, infrastructure, applications)
Observed data · $18B+ spend under management · 2026
Method and full statement
For mid-market and enterprise companies, spend on AI-native software grew 94% year over year while spend on traditional SaaS grew just 8%, according to Tropic.
Method
Transaction data: analysis of $18B+ in spend under management across Tropic customers; cohorts SMB/Growth (1-250 employees) and Mid-Market/Enterprise (251+)
According to KPMG's Q1 2026 AI Quarterly Pulse, large U.S. organizations plan to spend an average of $207 million on AI over the next 12 months, nearly double a year earlier.
Method
Survey of U.S.-based C-suite and business leaders at organizations with $1B+ annual revenue
According to the Atlanta Fed, more than half of firms expect to spend no more than $200 per employee on AI in 2026, while the top 10% plan at least $2,800, a 14-fold gap.
Method
Survey of senior U.S. business executives (Atlanta Fed survey work with Stanford/Chicago researchers); employment-weighted
a16z found that innovation budgets fell from a quarter of enterprise LLM spending to just 7% in 2025, as AI moved into centralized IT and business-unit budgets.
Method
Survey of 100 CIOs across 15 industries plus conversations with 25+ enterprise buyers
According to CloudZero, the share of organizations planning to spend over $100,000 a month on AI tools more than doubled, from 20% in 2024 to 45% in 2025.
Method
Survey of software professionals at the manager level and above in the U.S.
Sample
500+ software professionals (manager level and above)
Deloitte found that when the CFO had full decision-making authority over digital investments, 42% of organizations achieved above-average profitability, versus 18% where the CFO had none.
Method
Predictive analysis of a survey of business and technology leaders
ICONIQ's 2025 State of AI report found AI-enabled software companies allocate 10-20% of R&D budgets to AI development, a share growing in every revenue band.
Method
Survey of executives at software companies plus interviews with AI leaders in the ICONIQ community
According to the Ramp AI Index, 43.8% of U.S. businesses paid for Anthropic subscriptions or tokens in August 2026, ahead of OpenAI at 39.8%.
Method
Telemetry: corporate card, invoice and ACH transactions from 70,000+ U.S. businesses on Ramp; adoption = share of businesses with an observed payment for an AI product in the month
Ramp's Spring 2026 spending report found that more than half of businesses (50.4%) now pay for AI services, and Anthropic's share of paid AI customers jumped from 16.7% to 30.6% in one quarter.
Method
Telemetry: $100B+ of anonymized card and bill pay transactions from 50,000+ businesses
Mavvrik found engineering organizations run an average of 2.4 AI coding tools at once, 39% report coding-tool costs above expected license or usage, and only 42% include developer AI tools in AI cost reporting.
Method
Survey of enterprise organizations across Technology/SaaS, Financial Services, Retail, Manufacturing and other industries
Stanford's 2026 AI Index reports organizational AI adoption rose to 88% of surveyed organizations in 2025, but AI agent deployment was still in the single digits across nearly all business functions.
Method
Compilation of third-party data; organizational adoption figures drawn from an employer survey (McKinsey State of AI)
Survey · ~500 U.S. enterprise decision-makers · 2025
Method and full statement
Menlo Ventures found that 76% of enterprise AI use cases are now purchased rather than built internally, up from 53% purchased in 2024.
Method
Survey of ~500 U.S. enterprise AI decision-makers combined with a bottoms-up model of the generative AI market (model APIs, infrastructure, applications)
Survey · ~500 U.S. enterprise decision-makers · 2025
Method and full statement
According to Menlo Ventures, Anthropic holds 40% of enterprise LLM API market share in 2025, versus 27% for OpenAI.
Method
Survey of ~500 U.S. enterprise AI decision-makers combined with a bottoms-up model of the generative AI market (model APIs, infrastructure, applications)
Survey · ~500 U.S. enterprise decision-makers · 2025
Method and full statement
Menlo Ventures found that only 16% of enterprise AI deployments (and 27% of startup deployments) qualify as true agents.
Method
Survey of ~500 U.S. enterprise AI decision-makers combined with a bottoms-up model of the generative AI market (model APIs, infrastructure, applications)
a16z and Mercury's ranking of the top 50 AI apps by actual startup spend found horizontal tools make up 60% of the list, led by #1 OpenAI and #2 Anthropic.
Method
Telemetry: spend transactions (ACH, card, wires) across Mercury's 200,000+ customers, ranked to a top 50 of AI-native application companies
MIT NANDA found that AI tools bought from external partners reached deployment about 67% of the time, versus about 33% for internally built tools.
Method
Review of 300+ publicly disclosed AI initiatives, structured interviews with representatives of 52 organizations, and survey responses from 153 senior leaders at four industry conferences
Sample
52 organizations interviewed; 153 leaders surveyed; 300+ public initiatives
MIT NANDA estimates about 50% of generative AI budgets go to sales and marketing, even though back-office automation often delivers better ROI.
Method
Review of 300+ publicly disclosed AI initiatives, structured interviews with representatives of 52 organizations, and survey responses from 153 senior leaders at four industry conferences
Sample
52 organizations interviewed; 153 leaders surveyed; 300+ public initiatives
Gartner predicts that through 2029, organizations that do not centrally monitor and manage SaaS-hosted AI tools will incur at least 50% higher expense and be at least five times more likely to suffer a cyber incident.
Ramp's token price index shows the effective price businesses pay per million AI tokens fell 41% to $0.68 by September 2026, down from a 2026 peak of $1.15 in March.
Method
Telemetry: effective price per million tokens from Ramp's token spend data
Sample
Ramp business customers using token spend tracking
Gartner predicts AI inference costs per agentic workflow will rise more than fivefold through 2028, even as per-token prices fall, because agents consume far more tokens per task.
According to Mavvrik, 40% of organizations had to escalate a surprise AI cost to the board in the past year, 33% imposed emergency spending freezes and 25% delayed or cancelled an AI initiative.
Method
Survey of enterprise organizations across Technology/SaaS, Financial Services, Retail, Manufacturing and other industries
Mavvrik found only 44% of organizations include on-prem AI infrastructure in cost reporting, and 15% of those running agentic workloads cannot attribute agent costs at any level.
Method
Survey of enterprise organizations across Technology/SaaS, Financial Services, Retail, Manufacturing and other industries
According to Flexera's 2026 AI Pulse Report, 80% of organizations increased AI investment, yet more than a third say they overspent on AI applications and 14% report wasted AI spend.
Method
method not stated on page (Flexera survey research)
KPMG's Q3 2026 AI Pulse found 74% of large organizations now include cost reviews in AI approvals (up from 61% a quarter earlier), and 43% have usage or token budgets.
Method
Survey of U.S.-based C-suite and business leaders at organizations with $1B+ annual revenue
According to KPMG, organizations with full visibility into AI operating costs are five times more likely to report established ROI than those without (15% vs. 3%).
Method
Survey of senior leaders with direct knowledge of AI use; organizations with US$50M+ revenue (US$1B+ for U.S. sample); 20 countries
Goldman Sachs Research says chipmakers are cutting the cost per token for AI inference by 60-70% a year, while forecasting agentic AI will drive a 24-fold increase in token consumption by 2030.
85% of technology executives lack full visibility into real-time AI spend, and AI is projected to grow from under 15% of IT budgets in 2025 to nearly 25% by 2027, according to IBM.
80% of IT leaders report increased spending on AI applications and over a third believe they are overspending, according to Flexera's 2026 IT Priorities report.
MIT NANDA's GenAI Divide report found that despite $30-40 billion in enterprise investment, 95% of organizations are getting zero return from generative AI.
Method
Review of 300+ publicly disclosed AI initiatives, structured interviews with representatives of 52 organizations, and survey responses from 153 senior leaders at four industry conferences
Sample
52 organizations interviewed; 153 leaders surveyed; 300+ public initiatives
A Gartner survey of 782 infrastructure and operations leaders found only 28% of AI use cases in I&O fully succeed and meet ROI expectations, while 20% fail outright.
Method
Survey of infrastructure and operations (I&O) leaders
Workday research found nearly 40% of the time employees save with AI is lost to rework, and only 14% consistently get clear, positive net outcomes from AI.
Method
Survey by Workday, fielded by Hanover Research, of full-time employees at $100M+ revenue organizations who actively use AI
Survey · ~500 U.S. enterprise decision-makers · 2025
Method and full statement
According to Menlo Ventures, 47% of AI deals go to production once an organization commits to exploring a solution, nearly twice the 25% rate for traditional SaaS.
Method
Survey of ~500 U.S. enterprise AI decision-makers combined with a bottoms-up model of the generative AI market (model APIs, infrastructure, applications)
According to Menlo Ventures, implementation costs were cited in 26% of failed generative AI pilots, ahead of data privacy (21%) and disappointing ROI (18%).
Method
Survey of 600 U.S. IT decision-makers at enterprises with 50+ employees
Gartner predicted at least 30% of generative AI projects would be abandoned after proof of concept by the end of 2025, citing poor data quality, risk controls, escalating costs or unclear value.
Method
Analyst prediction (Gartner Data & Analytics Summit, Sydney)
BCG's 2024 research found 74% of companies have yet to show tangible value from their use of AI, and only 4% have cutting-edge AI capabilities across functions.
Method
Survey of CxOs and senior executives from 20+ sectors in 59 countries
38% of employees say they have successfully accessed a prior employer's account, according to 1Password's 2025 Access-Trust Gap report.
Method
Survey: online survey of 5,200 desk-based knowledge workers (including IT and security professionals) in the U.S., Canada, UK, Germany, France and Singapore
Veza's 2026 State of Identity & Access report found 38% of identity provider accounts were dormant (inactive 90+ days) but still active, up from 20% the year before.
Method
Telemetry: aggregated, anonymized analysis of millions of identities and billions of entitlements across identity providers, cloud, SaaS and data systems at hundreds of large enterprises; normalized by median/IQR
Sample
millions of identities from hundreds of large enterprises (exact count not stated)
Only 1 in 4 organizations automates offboarding, according to BetterCloud's 2026 State of SaaS report, and 18% experienced a data breach caused by an offboarded user who still had access.
Method
Survey of IT and security professionals at SaaS-first organizations
51% of organizations lack the ability to properly offboard dormant identities and accounts across their SaaS estate, according to Valence Security's 2025-26 State of SaaS Security research with the Cloud Security Alliance.
Method
Survey designed and run by the Cloud Security Alliance (commissioned by Valence Security) in January 2025; 420 IT and security professionals
88% of organizations have stale but still-enabled 'ghost' user accounts, according to Varonis's 2025 State of Data Security Report.
Method
Observed data: Varonis analysis of 1,000 real-world IT environments (Microsoft 365, AWS, Box, Salesforce, Google and other SaaS/IaaS) from its data risk assessments
Across enterprises Veza analyzed, 78,000 ex-employees (3% of all employees) still held active credentials.
Method
Telemetry: aggregated, anonymized analysis of millions of identities and billions of entitlements across identity providers, cloud, SaaS and data systems at hundreds of large enterprises; normalized by median/IQR
Sample
millions of identities from hundreds of large enterprises (exact count not stated)
Veza found 8% of identity provider accounts were orphaned, with no matching owner in HR systems, a 40% year-over-year increase.
Method
Telemetry: aggregated, anonymized analysis of millions of identities and billions of entitlements across identity providers, cloud, SaaS and data systems at hundreds of large enterprises; normalized by median/IQR
Sample
millions of identities from hundreds of large enterprises (exact count not stated)
70% of IT professionals have experienced the impacts of ineffective offboarding, from business disruption to unauthorized access (Nudge Security, 2023).
74% of business leaders surveyed by Beyond Identity said their company had been negatively impacted by a former employee breaching its digital security.
Method
Survey: 903 employees who had left a previous job (500 US, 200 UK, 203 Ireland) plus 218 US business leaders
According to Veza, 16.5% of all permissions belong to inactive users, up from 12% a year earlier.
Method
Telemetry: aggregated, anonymized analysis of millions of identities and billions of entitlements across identity providers, cloud, SaaS and data systems at hundreds of large enterprises; normalized by median/IQR
Sample
millions of identities from hundreds of large enterprises (exact count not stated)
The average worker in Veza's 2026 dataset holds 96,000 entitlements.
Method
Telemetry: aggregated, anonymized analysis of millions of identities and billions of entitlements across identity providers, cloud, SaaS and data systems at hundreds of large enterprises; normalized by median/IQR
Sample
millions of identities from hundreds of large enterprises (exact count not stated)
Veza reports that 'safe, compliant' permissions fell from 70% in 2024 to 55.3% in 2025, driven by ungoverned permissions rising from 5% to 27.8%.
Method
Telemetry: aggregated, anonymized analysis of millions of identities and billions of entitlements across identity providers, cloud, SaaS and data systems at hundreds of large enterprises; normalized by median/IQR
Sample
millions of identities from hundreds of large enterprises (exact count not stated)
Veza classed 3.3% of enterprise permissions as 'residual': access that should have been revoked after a termination, job change or finished task.
Method
Telemetry: aggregated, anonymized analysis of millions of identities and billions of entitlements across identity providers, cloud, SaaS and data systems at hundreds of large enterprises; normalized by median/IQR
Sample
millions of identities from hundreds of large enterprises (exact count not stated)
82% of security leaders say their organization suffered a cyberattack or breach in the past year due to improper access or over-privileged users, up from 77% in 2024 (ConductorOne).
Method
Survey of IT security professionals, manager level and above, at US companies with 500+ employees
Microsoft's 2023 State of Cloud Permissions Risks report found identities used just 1% of the permissions they were granted, and over 60% of all identities were inactive.
Method
Telemetry: 500+ risk assessments run with Microsoft Entra Permissions Management across Azure, AWS and GCP
Observed data · 50,000+ tickets across 30+ organizations · 2026
Method and full statement
App assignment requests make up 28.1% of all IT help desk tickets, more than four times the next most common request, according to Fixify's 2026 IT Help Desk Benchmark Report.
Method
Telemetry: analysis of anonymized help desk tickets
Access requests have surged more than 12x and access certifications more than 9x over the past two years, according to Okta's Businesses at Work 2026 report.
Method
Telemetry: anonymized Okta customer data (Businesses at Work is based on Okta Integration Network usage); method not stated on page for this figure
Only 45% of employees had their accounts, software and system access fully set up on their first day; 48% said some access was missing or delayed (allwhere survey).
Method
Survey of desk workers who use a computer most of the day (10 questions)
Observed data · 50,000+ tickets across 30+ organizations · 2026
Method and full statement
App assignment, permissions management and employee offboarding together account for 40% of all IT help desk tickets, according to Fixify's 2026 benchmark.
Method
Telemetry: analysis of anonymized help desk tickets
Access requests and account provisioning are among the top three tasks security leaders expect to hand to AI agents, cited by 46% (ConductorOne, 2025).
Method
Survey of IT security professionals, manager level and above, at US companies with 500+ employees
Only 40% of organizations automate offboarding and 34% automate onboarding, even though IT ranks them as top challenges, according to BetterCloud's 2025 State of SaaS report.
57% of organizations report fragmented SaaS administration and 54% lack automation for identity lifecycle management, according to the Cloud Security Alliance's State of SaaS Security 2025 report.
Method
Survey of security and IT professionals; sample not stated on landing page
In IDSA's 2024 study, 42% of organizations said more timely reviews of access to sensitive data could have prevented their identity incidents, and 50% pointed to privileged access reviews.
Method
Online survey of identity and security professionals at organizations with 1,000+ employees
47% of security leaders say their identity security strategy and access policies hinder team productivity, per ConductorOne's 2024 Identity Security Outlook.
Method
Online survey of US IT professionals, director level and up, at companies with 250 to 10,000 employees
70% of new hires decide whether a job is the right fit within the first month, and companies have about 44 days to convince them to stay (BambooHR, 2023).
Method
Survey of US full-time office/computer workers plus HR managers
The 2026 Ponemon Cost of Insider Risks report puts the average annual cost of insider security incidents at $19.5M per organization.
Method
Ponemon Institute benchmark study of insider-risk costs (sponsored by DTEX); methodology not stated on landing page (2025 edition was based on 8,306 interviews with IT and IT security professionals)
Insider incidents took 67 days on average to contain in Ponemon's 2026 study, down from 86 days in 2023.
Method
Ponemon Institute benchmark study of insider-risk costs (sponsored by DTEX); methodology not stated on landing page (2025 edition was based on 8,306 interviews with IT and IT security professionals)
Negligent insiders cost organizations $10.3M a year on average, up 17% year over year, per Ponemon's 2026 Cost of Insider Risks report.
Method
Ponemon Institute benchmark study of insider-risk costs (sponsored by DTEX); methodology not stated on landing page (2025 edition was based on 8,306 interviews with IT and IT security professionals)
Organizations now allocate 19% of their IT budget to insider risk management, up from 8.2% in 2023, according to Ponemon and DTEX.
Method
Ponemon Institute benchmark study of insider-risk costs (sponsored by DTEX); methodology not stated on landing page (2025 edition was based on 8,306 interviews with IT and IT security professionals)
Deliberate privilege misuse by insiders accounted for just under 4% of breaches in the 2026 DBIR, and 60% of those were motivated by convenience rather than money.
Method
Breach data: VERIS-coded incidents and confirmed breaches from Verizon and its global data contributors
Sample
1,141 incidents, 766 with confirmed data disclosure
Verizon's 2026 DBIR notes that insiders walking off with proprietary data are 'frequently the hardest to catch without specific offboarding processes in place.'
Method
Breach data: VERIS-coded incidents and confirmed breaches from Verizon and its global data contributors
For every insider incident, companies spend about $211,021 on containment but just $37,756 on monitoring, per Ponemon's 2025 Cost of Insider Risks report.
Method
Ponemon Institute interviews with IT and IT security professionals at organizations that experienced insider incidents
Monthly insider-driven data exposure, loss, leak and theft events have risen 28% on average since 2021, according to Code42's 2024 Data Exposure Report, a survey of 700 US cybersecurity professionals.
Method
Survey of US cybersecurity practitioners, managers and leaders at companies with 500+ employees
Cybersecurity professionals surveyed for Code42's 2024 Data Exposure Report say they spend an average of 3 hours a day investigating insider-driven data events.
Method
Survey of US cybersecurity practitioners, managers and leaders at companies with 500+ employees
Machine identities outnumber people many times over, and AI agents are the newest and least governed.
Machines per personFor every employee, a crowd of keys, tokens and service accountsTwo sources, two methods: a survey of security leaders and observed identity data.
Survey · n=418 IT and security professionals · 2026
Method and full statement
82% of organizations discovered previously unknown AI agents in their environment in the past year, according to a 2026 Cloud Security Alliance survey.
Method
Online survey by CSA, commissioned and co-designed by Token Security
According to SailPoint's 2025 AI agent research, 80% of companies say their AI agents have taken unintended actions, such as accessing unauthorized systems.
Method
Survey conducted by Dimensional Research of technology professionals across 5 continents
Observed data · subset of Netskope customers · 2026
Method and full statement
According to Netskope's AI Report 2026, MCP traffic increased 4x as organizations connect AI systems to sensitive data stores, driving a sharp rise in downstream data policy violations.
Method
Telemetry: aggregate usage data collected by the Netskope One platform for a subset of Netskope customers
Vendor or analysis · 18,000+ configuration files · 2026
Method and full statement
According to UpGuard's analysis of 18,000+ AI agent configuration files on GitHub, 1 in 5 developers have granted AI coding agents unrestricted access to perform high-risk actions without human oversight.
Method
Analysis of more than 18,000 AI agent configuration files from public GitHub repositories
According to Ivanti's 2026 research, 87% of security teams say adopting agentic AI is a priority, and 77% report at least some comfort allowing autonomous AI to act without human review.
Method
Survey of security professionals (details not stated in release)
Observed data · Billions of public GitHub commits · 2026
Method and full statement
GitGuardian found 24,008 unique secrets exposed in Model Context Protocol (MCP) configuration files on public GitHub in 2025.
Method
Telemetry: GitGuardian scan of all public GitHub commits in 2025, plus anonymized internal-repository and collaboration-tool incident data from GitGuardian customers
Survey · n=285 IT and security professionals · 2026
Method and full statement
44% of organizations use or plan to use static API keys to authenticate AI agents, and 43% username and password combinations, per the Cloud Security Alliance.
Method
Online survey by CSA, commissioned and co-designed by Strata Identity
According to Deloitte, only one in five companies has a mature governance model for autonomous AI agents, even as agentic AI use is poised to rise sharply.
Method
Global survey of senior leaders (board, C-suite, president, VP and director levels), split equally between IT and line-of-business
According to SailPoint's 2025 AI agent research, 96% of technology professionals consider AI agents a growing risk, yet 98% of organizations plan to expand their use within the next year.
Method
Survey conducted by Dimensional Research of technology professionals across 5 continents
According to Microsoft's 2025 Work Trend Index, 81% of leaders expect AI agents to be moderately or extensively integrated into their company's AI strategy in the next 12 to 18 months.
Method
Online survey by Edelman Data x Intelligence of full-time employed or self-employed knowledge workers in 31 markets (1,000 per market), plus LinkedIn and Microsoft 365 signals
According to Microsoft's 2025 Work Trend Index, 46% of leaders say their companies are using AI agents to fully automate workflows or processes.
Method
Online survey by Edelman Data x Intelligence of full-time employed or self-employed knowledge workers in 31 markets (1,000 per market), plus LinkedIn and Microsoft 365 signals
Observed data · 5,205 MCP server implementations · 2025
Method and full statement
Of more than 5,200 open-source MCP servers Astrix analyzed, 88% require credentials, 53% rely on long-lived static API keys or personal access tokens, and only 8.5% use OAuth.
Method
Code analysis: Astrix Research analyzed README files of 5,205 open-source MCP server repositories on GitHub with an LLM-based classifier
Survey · more than 2,500 CIOs and technology executives · 2025
Method and full statement
Gartner found that 64% of technology executives plan to deploy agentic AI within the next 24 months, while AI investment is expected to grow more than 35% year over year in a constrained IT budget environment.
Observed data · Billions of public GitHub commits · 2026
Method and full statement
GitGuardian detected about 29 million new hardcoded secrets in public GitHub commits in 2025, a 34% increase year over year and the largest single-year jump it has recorded.
Method
Telemetry: GitGuardian scan of all public GitHub commits in 2025, plus anonymized internal-repository and collaboration-tool incident data from GitGuardian customers
Observed data · Billions of public GitHub commits · 2026
Method and full statement
GitGuardian found that 64% of valid secrets first detected in 2022 were still not revoked in 2026.
Method
Telemetry: GitGuardian scan of all public GitHub commits in 2025, plus anonymized internal-repository and collaboration-tool incident data from GitGuardian customers
Observed data · Billions of public GitHub commits · 2026
Method and full statement
Leaked secrets tied to AI services rose 81% year over year in 2025, to 1,275,105, according to GitGuardian.
Method
Telemetry: GitGuardian scan of all public GitHub commits in 2025, plus anonymized internal-repository and collaboration-tool incident data from GitGuardian customers
Observed data · Billions of public GitHub commits · 2026
Method and full statement
Internal repositories are about 6 times more likely than public ones to contain hardcoded secrets, per GitGuardian.
Method
Telemetry: GitGuardian scan of all public GitHub commits in 2025, plus anonymized internal-repository and collaboration-tool incident data from GitGuardian customers
Observed data · Billions of public GitHub commits · 2026
Method and full statement
About 28% of secrets-leak incidents GitGuardian found originate in collaboration and productivity tools rather than code repositories.
Method
Telemetry: GitGuardian scan of all public GitHub commits in 2025, plus anonymized internal-repository and collaboration-tool incident data from GitGuardian customers
Observed data · Billions of public GitHub commits · 2026
Method and full statement
Claude Code-assisted commits leaked secrets at about 3.2%, roughly twice the public GitHub baseline, according to GitGuardian.
Method
Telemetry: GitGuardian scan of all public GitHub commits in 2025, plus anonymized internal-repository and collaboration-tool incident data from GitGuardian customers
Observed data · Billions of public GitHub commits · 2026
Method and full statement
About 60% of secrets policy violations GitGuardian sees are long-lived credentials that persist over time.
Method
Telemetry: GitGuardian scan of all public GitHub commits in 2025, plus anonymized internal-repository and collaboration-tool incident data from GitGuardian customers
Observed data · Billions of public GitHub commits · 2026
Method and full statement
Since 2021, leaked secrets have grown about 1.6 times faster than the active developer population, per GitGuardian.
Method
Telemetry: GitGuardian scan of all public GitHub commits in 2025, plus anonymized internal-repository and collaboration-tool incident data from GitGuardian customers
Survey · n=383 IT and security professionals · 2026
Method and full statement
Only 14% of organizations have fully automated the creation and removal of AI-related identities; 27% do it entirely by hand, per the Cloud Security Alliance.
Method
Online survey by CSA, commissioned and co-designed by Oasis Security
Survey · n=383 IT and security professionals · 2026
Method and full statement
Nearly a quarter (24%) of organizations take more than 24 hours to rotate or revoke a credential after a potential exposure, per the Cloud Security Alliance.
Method
Online survey by CSA, commissioned and co-designed by Oasis Security
Survey · n=nearly 2,000 IT and security practitioners · 2026
Method and full statement
The average organization oversees more than 114,000 internal certificates but has only four full-time staff dedicated to managing them, according to Ponemon research for CyberArk.
Method
Survey by Ponemon Institute, commissioned by CyberArk, of IT and security practitioners globally
55% of Google Cloud service accounts have active keys older than a year, and 40% of Microsoft Entra ID applications have credentials older than a year, per Datadog.
Method
Telemetry: security posture data from a sample of thousands of organizations using AWS, Azure or Google Cloud monitored by Datadog
86% of companies suffered at least one outage from expired or mismanaged digital certificates in the past year, and 10% have one every week, according to Keyfactor.
Method
Survey by Wakefield Research of PKI and certificate management practitioners at companies with 1,000+ employees in North America and Europe
The median time to remediate leaked secrets discovered in a GitHub repository was 94 days, according to Verizon's 2025 DBIR.
Method
Breach data: analysis of 22,000+ security incidents and 12,000+ confirmed breaches from Verizon and contributing organizations; secrets analysis of public code repositories
GitLab tokens made up 50% of all development and CI/CD secrets found leaked in public code repositories, per Verizon's 2025 DBIR.
Method
Breach data: analysis of 22,000+ security incidents and 12,000+ confirmed breaches from Verizon and contributing organizations; secrets analysis of public code repositories
Survey · n=1,201 security and IT decision-makers · 2025
Method and full statement
72% of organizations suffered at least one certificate-related outage in the past year, and 45% have one weekly, per CyberArk, up from 12% weekly in 2022.
Method
Survey by Censuswide of security and IT decision-makers at organizations with 500+ employees in the USA, UK, Australia, France, Germany and Singapore
Lack of credential rotation was the most common cause of NHI-related attacks (45%), ahead of inadequate monitoring (37%) and over-privileged identities (37%), per CSA and Astrix.
Method
Survey of 800+ IT and security experts, coupled with data from 2M+ NHIs monitored by Astrix in Fortune 500 companies
The average organization experienced nine certificate-related incidents in the past 12 months, taking 2.6 hours to identify and 2.7 hours to fix each outage, according to Keyfactor.
Method
Survey conducted with the Ponemon Institute of IT and security professionals (sample size not stated on this page)
Only 1% of organizations have fully implemented just-in-time privileged access, and 91% say at least half of their privileged access is always on, per CyberArk.
Method
Survey by Censuswide of U.S. practitioners in PAM, identity and infrastructure roles
Survey · n=383 IT and security professionals · 2026
Method and full statement
79% of organizations rate their confidence in preventing attacks via non-human identities as low or moderate, per a 2026 Cloud Security Alliance survey commissioned by Oasis Security.
Method
Online survey by CSA, commissioned and co-designed by Oasis Security
Survey · n=383 IT and security professionals · 2026
Method and full statement
92% of IT and security professionals are not confident their legacy IAM tools can manage the risks of AI and non-human identities, per the Cloud Security Alliance.
Method
Online survey by CSA, commissioned and co-designed by Oasis Security
Survey · n=418 IT and security professionals · 2026
Method and full statement
65% of organizations experienced an AI agent-related incident in the past 12 months, with 61% reporting data exposure, per the Cloud Security Alliance.
Method
Online survey by CSA, commissioned and co-designed by Token Security
Survey · n=445 IT and security professionals · 2026
Method and full statement
53% of organizations have had AI agents exceed their intended permissions, and only 8% say their agents never do, according to the Cloud Security Alliance.
Method
Online survey by CSA, commissioned and co-designed by Zenity
Survey · n=445 IT and security professionals · 2026
Method and full statement
54% of organizations report between 1 and 100 unsanctioned AI agents, and only 15% say most of their agents have a defined owner, per the Cloud Security Alliance.
Method
Online survey by CSA, commissioned and co-designed by Zenity
78% of organizations cite controlling non-human identity access and permissions as a top concern, but only 10% have a strategy for governing them (Okta, 2026).
12.2% of third-party integrations into AWS accounts are dangerously overprivileged, letting the vendor access all data or take over the account, per Datadog.
Method
Telemetry: security posture data from a sample of thousands of organizations using AWS, Azure or Google Cloud monitored by Datadog
Survey · n=1,201 security and IT decision-makers · 2025
Method and full statement
Half (50%) of security leaders reported security incidents or breaches linked to compromised machine identities in the past year, according to CyberArk's 2025 State of Machine Identity Security Report.
Method
Survey by Censuswide of security and IT decision-makers at organizations with 500+ employees in the USA, UK, Australia, France, Germany and Singapore
Survey · n=420 IT and security professionals · 2025
Method and full statement
46% of organizations struggle to monitor non-human identities created by SaaS-to-SaaS integrations and GenAI tools, and 56% worry about over-privileged API access, per the Cloud Security Alliance.
Method
Online survey by CSA of IT and security professionals at large organizations
Nearly 1 in 5 organizations have experienced a security incident related to non-human identities, according to a 2024 Cloud Security Alliance and Astrix survey.
Method
Survey of 800+ IT and security experts, coupled with data from 2M+ NHIs monitored by Astrix in Fortune 500 companies
Only 15% of organizations are highly confident in their ability to secure non-human identities, versus nearly 1 in 4 for human identities, per CSA and Astrix.
Method
Survey of 800+ IT and security experts, coupled with data from 2M+ NHIs monitored by Astrix in Fortune 500 companies
38% of organizations report no or low visibility into third-party vendors connected by OAuth apps, and another 47% have only partial visibility, according to CSA and Astrix.
Method
Survey of 800+ IT and security experts, coupled with data from 2M+ NHIs monitored by Astrix in Fortune 500 companies
Survey · n=800 security and IT decision-makers · 2024
Method and full statement
56% of organizations had a security incident involving machine identities such as access tokens used with service accounts in the past year, according to Venafi.
Method
Survey of security and IT decision-makers at large organizations in the U.S., U.K., France and Germany
Survey · n=800 security and IT decision-makers · 2024
Method and full statement
88% of security leaders believe machine identities, specifically access tokens and their connected service accounts, are the next big target for attackers, per Venafi.
Method
Survey of security and IT decision-makers at large organizations in the U.S., U.K., France and Germany
Observed data · Mandiant IR and MTD engagements · 2026
Method and full statement
Threat actors exploited identity issues to gain initial access in 83% of incidents involving major cloud and SaaS-hosted environments, according to Google Cloud's H1 2026 Threat Horizons Report.
Method
Incident response data: Mandiant Incident Response and Mandiant Threat Defense engagements in H2 2025 involving major cloud and SaaS-hosted environments
Sample
Mandiant IR and MTD engagements (count not stated)
For the first time in the DBIR's history, vulnerability exploitation (31% of breaches) overtook credential abuse (13%) as the most common way attackers get in, per Verizon's 2026 report.
Method
Breach data: Verizon VTRAC caseload plus contributor data (law enforcement, forensic firms, insurers, ISACs) across 145 countries; 31,000+ incidents and 22,000+ confirmed breaches
Sample
n=19,905 non-Error, non-Misuse breaches with known initial access vector
Observed data · CrowdStrike Falcon detections · 2026
Method and full statement
82% of CrowdStrike detections in 2025 were malware-free, as adversaries used valid credentials, trusted identity flows and approved SaaS integrations.
Method
Threat intelligence and incident telemetry: CrowdStrike Counter Adversary Operations tracking of 280+ adversaries and Falcon platform detections during calendar 2025
Observed data · CrowdStrike-observed cloud incidents · 2026
Method and full statement
Valid account abuse accounted for 35% of cloud incidents in 2025, and cloud-conscious intrusions rose 37%, according to CrowdStrike's 2026 Global Threat Report.
Method
Threat intelligence and incident telemetry: CrowdStrike Counter Adversary Operations tracking of 280+ adversaries and Falcon platform detections during calendar 2025
Sample
CrowdStrike-observed cloud incidents (count not stated)
In the 2024 Snowflake customer breaches, about 80% of the accounts the attacker used had prior credential exposure, and around 165 organizations were affected, per Verizon's 2025 DBIR.
Method
Breach data: analysis of 22,000+ security incidents and 12,000+ confirmed breaches from Verizon and contributing organizations; secrets analysis of public code repositories
Compromised credentials were the root cause of 53% of material breaches over the past three years, according to 1Password's 2025 Access-Trust Gap report.
Method
Online survey of 5,200 desk-based knowledge workers (including IT and security professionals) in the US, Canada, UK, Germany, France and Singapore
Observed data · Accounts leveraged in the campaign · 2024
Method and full statement
At least 79.7% of the Snowflake customer accounts used in the 2024 UNC5537 campaign had prior credential exposure, much of it from infostealer infections dating back to 2020, Mandiant found.
Method
Mandiant and Snowflake joint analysis of accounts used by the threat actor against infostealer data
Sample
Accounts leveraged in the campaign (count not stated)
For weak passwords and permission misconfigurations in third parties' cloud accounts, it took almost eight months to resolve half of all findings, per Verizon's 2026 DBIR.
Method
Breach data: analysis of 31,000+ security incidents, 22,000+ confirmed breaches in 145 countries, from Verizon and contributing organizations
Observed data · Mandiant IR and MTD engagements · 2026
Method and full statement
21% of cloud and SaaS intrusions in the second half of 2025 involved compromised trusted relationships with third parties, such as stolen Salesloft Drift and Gainsight OAuth tokens, per Google Cloud's H1 2026 Threat Horizons Report.
Method
Incident response data: Mandiant Incident Response and Mandiant Threat Defense engagements in H2 2025 involving major cloud and SaaS-hosted environments
Sample
Mandiant IR and MTD engagements (count not stated)
78% of organizations say their cybersecurity programs cover less than half of their vendor ecosystem, according to SecurityScorecard's 2026 Supply Chain Cybersecurity Trends Report.
Method
Survey of 'hundreds of professionals managing vendor risk' (exact n not stated on page)
Obsidian Security found the blast radius of the Salesloft Drift supply chain attack was 10 times greater than previous incidents in which attackers went after Salesforce directly.
More than 70% of organizations had at least one material third-party cybersecurity incident in the past year, according to SecurityScorecard's 2025 Supply Chain Cybersecurity Trends survey.
Method
Survey of 546 IT directors and above whose roles involve cybersecurity, enterprise organizations worldwide
49% of frequent Microsoft 365 users thought fewer than 10 apps were connected to their tenant; AppOmni's platform data shows more than 1,000 connections on average.
Method
Survey of security decision makers at 644 organizations in the US, UK, France, Germany, Japan and Australia (nearly half with 2,500+ employees), plus AppOmni aggregated platform data
Sample
n=644 (survey); AppOmni customer data (size not stated)
Observed data · Hundreds of enterprise SaaS applications · 2024
Method and full statement
Every organization in Valence Security's 2024 data granted API access to at least one third-party vendor, and 33% of those integrations had access to sensitive permissions and data.
Method
EMA survey of 125 security executives, plus anonymized 2024 data from hundreds of enterprise SaaS applications monitored by the Valence platform
Sample
Hundreds of enterprise SaaS applications (platform data)
99% of Global 2000 companies are directly connected to vendors that have had a recent breach, and supply chain incidents cost 17 times more to remediate than first-party breaches, according to SecurityScorecard and the Cyentia Institute.
Method
Observed data: SecurityScorecard vendor-relationship and breach data for Global 2000 companies, analyzed with the Cyentia Institute
1Password's 2025 report found at least one-third (34%) of SaaS apps are not protected by single sign-on.
Method
Survey: online survey of 5,200 desk-based knowledge workers (including IT and security professionals) in the U.S., Canada, UK, Germany, France and Singapore; figure reported by IT/security respondents
Observed data · n=7,513 third-party cloud MFA exposures · 2026
Method and full statement
Only 23% of third-party organizations fully remediated missing or weak MFA on their cloud accounts, according to Verizon's 2026 DBIR.
Method
Observed data: resolution times of exposures collected from inside third-party cloud environments by a third-party cyber risk management research partner
In a cloud exposure snapshot in Verizon's 2026 DBIR, 37% of organizations had an admin account with MFA disabled on an IaaS platform, versus 14% on Snowflake after its 2024 breach campaign.
Method
Observed data: point-in-time snapshot from a cloud exposure dataset (contributor data)
46% of SaaS breaches were linked to weak or exploited MFA protections, according to Valence Security's State of SaaS Security: Trends and Insights for 2026.
Nearly half of organizations cannot enforce consistent MFA and single sign-on across all users and SaaS applications, according to Valence Security's 2025-26 research with the Cloud Security Alliance.
Method
Survey designed and run by the Cloud Security Alliance (commissioned by Valence Security) in January 2025; 420 IT and security professionals
1 in 7 organizations do not use or enforce MFA across their SaaS and multi-cloud environments, according to Varonis's 2025 State of Data Security Report.
Method
Observed data: Varonis analysis of 1,000 real-world IT environments (Microsoft 365, AWS, Box, Salesforce, Google and other SaaS/IaaS) from its data risk assessments
Veza found 13% of enterprise users still lack MFA, a figure that did not change year over year.
Method
Telemetry: aggregated, anonymized analysis of millions of identities and billions of entitlements across identity providers, cloud, SaaS and data systems at hundreds of large enterprises; normalized by median/IQR
Sample
millions of identities from hundreds of large enterprises (exact count not stated)
Survey · 1,000 U.S. employees + 500 U.S. IT leaders · 2025
Method and full statement
39% of employees use apps not managed by their company on work devices, and IT leaders estimate 37% of corporate apps are not behind single sign-on, according to Dashlane.
Method
Survey of U.S. employed adults and U.S. IT leaders
Observed data · Mandiant IR and MTD engagements · 2026
Method and full statement
Attackers targeted data in 73% of cloud-related incidents in the second half of 2025, according to Google Cloud's H1 2026 Threat Horizons Report.
Method
Incident response data: Mandiant Incident Response and Mandiant Threat Defense engagements in H2 2025 involving major cloud and SaaS-hosted environments
Sample
Mandiant IR and MTD engagements (count not stated)
41% of SaaS security incidents stemmed from permission issues and 29% from misconfigurations, according to AppOmni's 2025 report.
Method
Survey of 803 security leaders and practitioners in the US, UK, Germany, Australia and Japan (finance, healthcare, manufacturing, software); three-quarters from organizations with 2,000+ employees
63% of organizations report external data oversharing in their SaaS apps, according to the Cloud Security Alliance's State of SaaS Security 2025 survey.
Method
Survey designed and run by the Cloud Security Alliance (commissioned by Valence Security) in January 2025; 420 IT and security professionals
66% of companies have cloud data exposed to anonymous users, according to Varonis's 2025 State of Data Security Report.
Method
Observed data: Varonis analysis of 1,000 real-world IT environments (Microsoft 365, AWS, Box, Salesforce, Google and other SaaS/IaaS) from its data risk assessments
Observed data · Hundreds of enterprise SaaS applications · 2024
Method and full statement
94% of external data shares in enterprise SaaS apps are inactive, meaning outsiders keep access they no longer need, according to Valence Security's 2024 State of SaaS Security report.
Method
EMA survey of 125 security executives, plus anonymized 2024 data from hundreds of enterprise SaaS applications monitored by the Valence platform
Sample
Hundreds of enterprise SaaS applications (platform data)
75% of organizations had a SaaS security incident in the past year, up 33% from 2024, according to AppOmni's State of SaaS Security 2025 report.
Method
Survey of 803 security leaders and practitioners in the US, UK, Germany, Australia and Japan (finance, healthcare, manufacturing, software); three-quarters from organizations with 2,000+ employees
91% of organizations say they are confident in their SaaS security posture, even though three-quarters had a SaaS incident in the past year, per AppOmni's 2025 report.
Method
Survey of 803 security leaders and practitioners in the US, UK, Germany, Australia and Japan (finance, healthcare, manufacturing, software); three-quarters from organizations with 2,000+ employees
94% of organizations report cloud intrusions that resulted in data exposure or exfiltration, according to CrowdStrike's 2026 State of Cloud Detection and Response survey.
Method
Survey; method not stated (sample size and respondent profile not given on page)
Cloud applications are among the top three attack targets for 34% of organizations, and only about half of sensitive data in the cloud is encrypted, according to Thales's 2026 Data Threat Report.
Method
Global web survey of security and IT management professionals, conducted by S&P Global 451 Research
Survey · Respondents whose orgs had an incident · 2025
Method and full statement
89% of organizations that suffered a SaaS incident believed they had 'appropriate visibility' into their SaaS environment, according to AppOmni's 2025 report.
Method
Survey of 803 security leaders and practitioners in the US, UK, Germany, Australia and Japan (finance, healthcare, manufacturing, software); three-quarters from organizations with 2,000+ employees
Sample
Respondents whose orgs had an incident (subset of n=803)
Just 13% of organizations use a dedicated SaaS Security Posture Management (SSPM) tool, though nearly a third say they need one, per AppOmni's 2025 report.
Method
Survey of 803 security leaders and practitioners in the US, UK, Germany, Australia and Japan (finance, healthcare, manufacturing, software); three-quarters from organizations with 2,000+ employees
SaaS security is a high priority for 86% of organizations and 76% are increasing their SaaS security budgets, per the Cloud Security Alliance's 2025 survey.
Method
Survey designed and run by the Cloud Security Alliance (commissioned by Valence Security) in January 2025; 420 IT and security professionals
42% of organizations lack comprehensive SaaS discovery and cannot tell whether employees are using risky GenAI apps, according to Valence Security's 2025-26 research with the Cloud Security Alliance.
Method
Survey designed and run by the Cloud Security Alliance (commissioned by Valence Security) in January 2025; 420 IT and security professionals
34% of organizations with policies requiring only sanctioned SaaS apps admit those rules are not strictly enforced, up 12 points from 2023, per AppOmni's 2024 report.
Method
Survey of security decision makers at 644 organizations in the US, UK, France, Germany, Japan and Australia (nearly half with 2,500+ employees), plus AppOmni aggregated platform data
The average time to identify and contain a breach rose to 247 days in IBM's 2026 Cost of a Data Breach Report, reversing five straight years of decline.
Method
Ponemon Institute research (sponsored and analyzed by IBM) on breaches at 602 organizations globally, March 2025 to February 2026
Observed data · CrowdStrike-observed eCrime intrusions · 2026
Method and full statement
The average eCrime breakout time fell to 29 minutes in 2025, with the fastest observed at 27 seconds, according to CrowdStrike's 2026 Global Threat Report.
Method
Threat intelligence and incident telemetry: CrowdStrike Counter Adversary Operations tracking of 280+ adversaries and Falcon platform detections during calendar 2025
Sample
CrowdStrike-observed eCrime intrusions (count not stated)
68% of organizations take 15 minutes or more to detect a cloud intrusion and over half need at least an hour, according to CrowdStrike's 2026 State of CDR survey.
The median time between initial access and hand-off to a second threat group collapsed from more than 8 hours in 2022 to 22 seconds in 2025, according to Mandiant's M-Trends 2026.
Method
Incident response data: Mandiant Consulting investigations of targeted attack activity between Jan 1 and Dec 31, 2025 (500k+ investigation hours)
Organizations detected 52% of intrusions themselves in 2025, up from 43% in 2024, while 14% were disclosed by the attackers, according to Mandiant's M-Trends 2026.
Method
Incident response data: Mandiant Consulting investigations of targeted attack activity between Jan 1 and Dec 31, 2025 (500k+ investigation hours)
Observed data · ~165 notified organizations · 2024
Method and full statement
Mandiant and Snowflake notified about 165 organizations potentially exposed in the 2024 UNC5537 campaign that used stolen credentials against Snowflake customer accounts without MFA.
Method
Incident response investigation by Mandiant with Snowflake
29% of IT leaders name automating more IT and SaaS operations as their top priority for the next 12 to 18 months, ahead of SaaS security (19%), according to BetterCloud.
Observed data · subset of 30+ organizations with headcount data · 2026
Method and full statement
The median company has 1.6 IT and security staff per 100 employees, with a practical range of 0.7 to 4.3, according to Fixify's 2026 IT Help Desk Benchmark Report.
Method
Customer headcount data alongside ticket telemetry
69% of IT leaders expect their IT budgets to increase in 2026, with an average expected rise of 6.93%, according to Foundry's 2026 State of the CIO study.
Method
Online survey of heads of IT plus line-of-business respondents; 36% North America, 20% EMEA, 42% APAC
Three quarters of CIOs say it is difficult to balance business innovation with operational excellence, and the average CIO juggles 1.6 roles, according to Foundry.
78% of organizations plan to add (56%) or replace (22%) an IT automation platform in the near term, according to Stonebranch's 2026 Global State of IT Automation report.
Method
Quantitative survey of enterprise IT Ops, DevOps, CloudOps, DataOps and PlatformOps professionals
Survey · 1,200 IT and cybersecurity professionals · 2025
Method and full statement
38% of IT professionals say tech complexity has become a significant barrier to effective IT operations, up four points in a year, according to Ivanti.
74% of IT leaders say their IT environment is too complex, and organizations rely on more than nine platforms to run IT, according to JumpCloud's Q3 2025 IT Trends Report.
Highly automated organizations employ only 90 IT staff per $1 billion in revenue, versus 140 for less automated peers, according to IBM Institute for Business Value.
76% of IT professionals say AI and automation can help decrease ticket volume and provide better service, according to Ivanti's 2024 Everywhere Work report.
In a Gartner Peer Community poll, 84% of IT leaders said at least one of their direct reports showed signs of burnout in the past year, and 68% blamed work overload.
Method
Gartner Peer Community One-Minute Insights poll of IT leaders
In a Gartner Peer Community poll, 60% of IT leaders said they had personally felt burnout in their role in the past 12 months, with 67% citing an unmanageable workload.
Method
Gartner Peer Community One-Minute Insights poll of IT leaders
A quarter of IT professionals were seriously considering leaving their jobs within six months, and only 8% of organizations prioritized automation for repetitive tasks, according to Ivanti's 2023 Defending IT Talent report.
Method
Survey of IT professionals and C-level executives globally
70% of CIOs and CTOs say teams across the business are deploying technology faster than IT can track, according to a 2026 IBM Institute for Business Value study.
Method
Survey of senior executives responsible for IT, technology or AI decisions across 33 geographies and 19 industries
Tropic has found more than $3 billion in 'shadow spend' across customer software portfolios, spending that existed before organizations had the visibility to see it.
Method
Transaction data: negotiated outcomes across $23B+ in tracked spend, 100,000+ negotiations, 30,000+ SKUs across 14,000+ suppliers (Tropic customers)
Gartner predicts that by 2028 over 70% of organizations will centralize SaaS management using SaaS management platforms, up from less than 30% in 2025.
Gartner's 2024 (inaugural) Magic Quadrant for SaaS Management Platforms predicted that through 2027, over 50% of organizations will centralize SaaS management using an SMP, up from less than 10% in 2024.
IT asset management teams spend the largest share of their time (32%) on software optimization, followed by audit response (22%), according to Flexera's 2026 State of ITAM Report.
Security and governance became IT's biggest SaaS management challenge for 47% of IT leaders in 2026, up from 28% a year earlier, according to BetterCloud.
90% of FinOps practitioners now manage SaaS spend or plan to within a year, up from 65% in 2025, according to the FinOps Foundation's State of FinOps 2026.
Gartner warns that through 2027, organizations that fail to centrally manage SaaS life cycles will remain five times more susceptible to a cyber incident or data loss.
According to Gartner's 2026 CIO and Technology Executive Survey, 57% of CIOs face pressure to improve productivity and 52% face pressure to reduce costs.
Method
Survey of CIOs and technology executives
Sample
n=2,501 CIOs and technology executives, all regions
ITAM teams increasingly work with FinOps: 38% collaborate with FinOps teams and 44% with cloud teams, according to Flexera's 2025 State of ITAM Report.
70% of IT teams prefer a unified SaaS management platform, and 51% find point solutions harder to manage SaaS with, according to BetterCloud's 2025 State of SaaS report.
88% of IT decision-makers are open to switching at least some tech vendors, and re-evaluating vendors or contracts (39%) is their top cost-saving measure, according to Spiceworks' 2026 State of IT.
Method
Survey of IT decision-makers; method not stated on page
71% of finance leaders list SaaS fees among their top three cost-saving priorities, and 55% blame a lack of transparency from tech leaders, according to a Vertice survey.
Method
Survey of senior finance and tech leaders in the US and UK
In its 2022 Market Guide for SaaS Management Platforms, Gartner predicted that by 2027, 40% of organizations using multiple SaaS applications would centralize management using an SMP, up from less than 25% in 2022.
Figures marked Torii data come from the Torii SaaS Benchmark Annual Report 2026: aggregated, anonymized discovery data covering the apps, licenses and spend that actually appear in the environments Torii connects to. The 2026 report covers January to December 2025. It does not publish a sample size, and some charts state no measurement window of their own. Where that is the case, the figure says so.
Every other number links to its origin
Each third-party statistic links to the page or PDF where the organization that ran the research published it. We excluded roundups and aggregator sites, re-fetched every source to confirm the number is there, and labeled each one as observed data, a survey or a forecast. Vendor research carries the vendor's name, since most of it comes from companies that sell into the problem they measured.
Numbers disagree, and that is information
Apps per company ranges from 101 to 957 depending on what is counted. Waste estimates range from 20% to 65%. Read the method line on any card before comparing two figures. A few CyberArk links point to archived copies because the original pages now redirect after its acquisition.
Download the data
Every statistic on this page, with its source link, method and sample, in one file.
Use Copy citation on any card, or link straight to a statistic with its # link. For Torii figures: Torii, SaaS Benchmark Annual Report 2026, toriihq.com/articles/saas-statistics.
Go deeper
Get the data behind the numbers
Read Torii's full benchmark, and see why Gartner named Torii a Leader in SaaS management platforms.
Gartner, Magic Quadrant for SaaS Management Platforms, Tom Cipolla, et al, 18 June 2026. GARTNER is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally, and MAGIC QUADRANT is a registered trademark of Gartner, Inc. and/or its affiliates and are used herein with permission. All rights reserved. Gartner does not endorse any vendor, product or service depicted in its research publications and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner's research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.
Frequently asked questions
How many SaaS apps does the average company use?
It depends on what is counted. Torii's discovery data finds 831 apps in the average organization (median 682), shadow IT included. Okta counts 101 apps connected to its single sign-on, and BetterCloud's survey of IT teams puts it at 106.
What percentage of apps are shadow IT?
In Torii's 2026 SaaS Benchmark, 61.3% of apps in the average portfolio are shadow IT, discovered through usage, browser activity or direct sign-up rather than procurement. Only 15.5% are formally approved.
How common is shadow AI?
Very. 26 of the top 50 shadow IT apps in Torii's 2025 data were pure-play AI tools, and Torii discovered 694 new AI-native apps in 2025. In Microsoft and LinkedIn's 2024 survey, 78% of AI users said they bring their own AI tools to work.
How much SaaS spend is wasted?
Estimates vary by method. Vertice's platform data puts 65% of SaaS licenses as unused or underutilized, while Flexera's survey respondents estimate 20% to 32% of SaaS spend is wasted. Torii finds Salesforce licenses have a 55% non-utilization rate.
How many machine identities are there per employee?
CyberArk's 2025 survey reports 82 machine identities for every human. Entro's observed data puts the ratio at 144 to 1.
Which SaaS management platforms does Gartner rate as Leaders?
Torii is named a Leader in the 2026 Gartner Magic Quadrant for SaaS Management Platforms, which evaluated 16 vendors. Torii has been a Leader in every edition since the first Magic Quadrant for the category in 2024. The report is available from Torii.
Where do these statistics come from?
Torii's own figures come from the 2026 SaaS Benchmark Annual Report, based on aggregated, anonymized discovery data. Every other figure links to the organization that published the research. The page holds 694 statistics from 106 publishers.