ITIC’s cause-attribution data across recent survey years has been broadly stable: security incidents (roughly 40% of unplanned downtime), human error (35–40%), third-party or vendor issues (30–50% with overlap across categories), and hardware/software failure (25–35%). Certificate-related outages fall inside the security-incident and third-party categories — see the certificate outages statistics analysis for how 86% of enterprises hit one in the past year alone.
All questions