Top Cybersecurity Marketing Agencies

Threat Landscape Reports vs Vendor State-of-the-Industry Reports

Telemetry shows what's actually happening; surveys show what people fear.

Features Editor · · 8 min read
Cover illustration for “Threat Landscape Reports vs Vendor State-of-the-Industry Reports”
cybersecurity research agencies · September 12, 2026 · 8 min read · 1,803 words

Two report types get treated like the same product, and they're not. Threat landscape reports (TLRs) come from telemetry: logged incidents, forensic case files, actual attacker behavior caught in the act. State-of-the-industry reports (SoIRs) come from surveys: what security professionals believe is happening, what keeps them up at night, what they tell a pollster over the phone. Confuse the two and you'll build a defense plan around anxiety instead of evidence.

Why the same threat can look different depending on which report type you read

Ivanti's 2026 SoIR has 63% of respondents calling ransomware a "high" or "critical" risk, and 60% saying the same about phishing. Those are opinion numbers. People rating fear on a scale.

Now check the 2025 Verizon DBIR, built entirely from incident telemetry. Vulnerability exploitation jumped to 20% of all breaches, passing phishing at 15%. That's not what people think is happening. That's what actually got logged.

So which one's wrong? Neither, technically. But if a security lead only reads the survey, they'll pour budget into phishing training while attackers are busy hammering unpatched software. FortiGuard Labs put a number on that pressure: 122 billion exploitation attempts observed, active scanning up 16.7% worldwide, hitting 36,000 scans per second. No survey respondent could ever report that figure, because no human being watches 36,000 scans a second and jots it down. Telemetry catches what people can't feel happening. Surveys catch what people are worried about. Neither one is lying, they're just answering different questions.

Diagram: Perception vs. Reality: Where Phishing and Exploitation Actually Rank. Visualizes: Show the contrast between two data sources measuring the same question — which threats are most significant — to reveal a meaningful gap.

The bias baked into vendor-produced threat landscape reports

A lot of threat intelligence gets written by the same companies selling threat intelligence platforms. That fact, unremarkable as it is, is worth sitting with for a second. A vendor with a product to sell has a reason to make its own data look sharp, its own coverage look wide, and its own findings line up neatly with whatever it's pitching next quarter.

Coverage gaps make this worse. Research into open-source threat feeds has found some reports flagging malicious activity well after it first showed up, and a lean toward certain countries over others. Even feeds tracking the exact same threat barely overlapped on the details. Nobody had full coverage of what they claimed to be watching.

Geography plays favorites too. Kaspersky publishes very little on Russian cyber activity. CrowdStrike covers Russian activity heavily, but goes quiet on anything originating from a particular country. soil. Neither company is hiding something sinister, most likely. Their vantage point just determines what they can see, the way a security camera only films what's in frame. Point it at the parking lot, and the lobby stays a mystery.

There's a pull toward whatever's shiny and new. Analysts chase novel threats because novel threats get clicks, get quoted, get cited in next year's report. Meanwhile the boring, common, garden-variety attack that hits ten thousand companies a year gets a paragraph, if that. The fix isn't complicated: vendors who show their methodology, sourcing, and blind spots let readers correct for the bias. Vendors who don't are just asking to be trusted on faith, and faith isn't a security control.

The bias baked into vendor state-of-the-industry reports

Surveys measure memory, ego, and office politics dressed up as data. What a respondent remembers, what they're willing to admit to a stranger with a clipboard, what their boss would prefer they say. That's the raw material of an SoIR, none of it neutral.

Take the preparedness gap from Ivanti's 2026 report: it widened meaningfully year over year. Sounds alarming until the metrics behind it show up. Only 51% of companies use a risk-based exposure score. 47% track mean time to remediate. 41% track percentage of exposures remediated. Those are speed metrics, not safety metrics. A company can remediate exposures fast and still be sitting on the risk that actually gets it breached. Fast isn't the same as safe, the way a fire drill that empties the building in ninety seconds says nothing about whether the sprinklers work.

Survey questions also carry fingerprints. A vendor selling vulnerability management tools asks about vulnerability metrics. A vendor selling phishing simulations asks about phishing readiness. The questionnaire is built around the product before a single respondent logs in to answer it.

And sample composition rarely gets disclosed with any precision. Who answered, from which industries, at what size company, matters enormously, and most reports bury that detail in an appendix nobody reads. Treat SoIRs as a read on collective mood and spending plans. Not as a measurement of what's actually breaking down.

What threat landscape reports are actually good for, and where they fail practitioners

TLRs earn their keep by showing what no single company could ever see alone. Recorded Future's 2024 Annual Threat Report tracked ransomware payments hitting $459.8 million by mid-2024, with one victim paying a record $75 million. That's a number no in-house security team stumbles onto by accident.

Trend direction is where TLRs really shine. CyberProof's 2025 Mid-Year Report clocked a 60% surge in ransomware attacks during the first half of the year, with the Akira group alone responsible for 72 attacks in January. Manufacturing logged 75 incidents globally. The United States stayed the top target with 259 incidents. None of that tells a single company whether it's about to get hit, but it tells them whether the water's rising or receding.

Where TLRs stumble is scope. A report reflects the vendor's own sensor network and customer base, not the reader's actual environment. An organization sitting outside that footprint might read a report full of statistics that simply don't apply to them. ENISA's Threat Landscape report offers a partial fix here, since it draws on sources beyond any single company's telemetry, though currency remains a limitation and there's a lag built in.

If a company's profile looks nothing like the statistics in a TLR, that mismatch is information in itself. It might mean the detection tools in place are missing incidents the report would've counted, not that the company dodged a bullet.

What state-of-the-industry reports are actually good for, and where they fail practitioners

SoIRs are built for comparison. Budget size, headcount, tool adoption, program maturity, the stuff telemetry simply can't show because telemetry doesn't know what a company's org chart looks like.

The workforce shortage figure, 3.4 million unfilled cybersecurity roles globally as of 2024, comes from this kind of survey and workforce research, not from any incident log. It's context. It explains why a security team of four is doing the job a team of ten should be handling, and why some of the findings in a threat report never get acted on: there's nobody left to act on them.

SoIRs also surface the gap between what a company plans to do and what it can actually pull off, which is genuinely useful when pitching a board on more headcount or more budget.

But CompTIA's own State of Cybersecurity research admits the sheer volume of information in these reports tends to wear out both business leaders and IT staff trying to turn recommendations into action. Breadth comes at the cost of specificity, and specificity is what gets things fixed.

The deeper issue is metric choice. When the most common KPIs measure speed (how fast something gets patched, what percentage gets closed) instead of risk reduction, the resulting benchmarks feel comforting without proving much of anything. Use SoIRs for peer comparison and for framing investment conversations. Never treat them as evidence of what attackers are actually doing out there.

How to read either report without being misled by either

Before trusting a single statistic, ask who collected the data, from whom, and over what stretch of time. That question alone filters out half the noise.

For a TLR, find the vendor's sensor footprint and customer base first. Findings are strongest in the sectors and regions that footprint actually covers, and weakest everywhere else. For an SoIR, find the sponsor's product category and the makeup of who got surveyed. Numbers about perceived threats and spending plans deserve more trust than numbers claiming to describe actual incident rates.

Transparency is the real test. A report that explains its methodology in enough detail for a reader to spot its own bias is more trustworthy than one that just hands over conclusions and expects applause. That standard applies to both report types equally, no exceptions for the friendly-looking ones.

Cross-referencing helps too. When a TLR and an SoIR agree on a threat's importance, confidence goes up. When they disagree, like phishing anxiety in the SoIR versus vulnerability exploitation surging to become the second most common breach entry point in the 2025 DBIR, ahead of phishing, that disagreement is the finding worth paying attention to, not a contradiction to shrug off.

And if a company's profile doesn't match the sectors most represented in a given report, its findings should be read as background, not gospel. That instruction shows up as a footnote in most reports. It deserves to be read as the headline.

One more wrinkle: plenty of the commentary written about these reports comes from security vendors interpreting someone else's data. That interpretation carries its own commercial lens, so it earns the same scrutiny as the original report, maybe more.

Why the format of a report signals its purpose before you read page one

The format of a report is never neutral packaging. It encodes who funded it, what data they had access to, and who they're hoping reads it. A glossy PDF full of pull-quotes signals a different intent than a dense appendix of raw incident counts, even when both claim to describe the same threat landscape.

Only 5% of organizations say they fully trust their cybersecurity vendors. That leaves the other 95% operating with a low simmer of doubt about whether their security stack actually holds up, which makes report credibility less of an academic debate and more of a daily operational headache.

CISOs seem to have already reached their own quiet verdict on this. Around 64%, per available research, lean on peer conversations as their main way of checking whether something's true, while analyst reports get trusted by only 9%. Separate data from Gartner in 2024 found 70% of CISOs favor peer recommendations and independent analyst insight over vendor-produced content when making technology decisions. The market worked out its own hierarchy of trust without waiting for anyone to announce it.

The vendors producing the most credible material tend to be the ones whose work is anchored in real telemetry and disclosed methodology, not the ones simply repackaging someone else's report with a new logo on the cover. Reading critically is, itself, a skill worth having here. How a vendor handles someone else's research, whether it interrogates the numbers or just cites them, says more about that vendor's grasp of the threat landscape than any slide deck ever will.

Sources

  1. 2024 Threat Analysis and 2025 Predictions │ Recorded Future Annual Threat Report
  2. CyberProof 2025 Mid-Year Cyber Threat Landscape Report
  3. 2024 Cybersecurity and Compliance Landscape: 50 Critical Statistics Shaping Our Digital Future
  4. fortinet.com
  5. Fortinet 2026 Global Threat Landscape Report
  6. State of Cybersecurity 2025 | CompTIA Report
  7. State of Cybersecurity Trends Report 2026 | Ivanti
  8. verizon.com

More in cybersecurity research agencies