Cybersecurity vulnerability management is a
continuous race against time compounded by device and application proliferation
across cloud, IoT and mobile workers. This expanding attack surface increases
pressure on resource-constrained security teams to patch before possible
exploitation. Scanning platforms have improved, but comprehensive vulnerability
management solutions still lack timely patch management capabilities.In a recent Ponemon study, 57 percent of
organizations said the root cause of a breach was due to an unpatched known
vulnerability, with 34 percent of those organizations aware of the
vulnerability before they were breached. While research is valuable (quantity
of vulnerabilities, speed of weaponization and exploitation trends), organizations
have been challenged with predicting future risk of exploitation and allocating
vulnerability management resources appropriately.
Using data from more than 2,000 deployed
eSentire sites, our Threat Intelligence team built a probability tool to depict
risk rates for organizations that do not have a threat monitoring service in
place. This tool generates statistical projections based on the ongoing and
cumulative chance
exploit attacks would have been picked up by our Security Operations Center,
which watches for things getting through a gap in your security perimeter or
firewall. Attack data was parsed according to industry to
provide greater accuracy and context to the projections. Using a 12-month view,
our findings painted an alarming picture with wide variances across industries.
To understand these variances, let’s first examine the collective global
probability across all industries.Global trends present an instantaneous view of
detected exploitation probability month-to-month for a single location. While
the probability appears relatively low month-to-month, compounded (cumulative)
probability rises to 27 percent over a 12-month period per protected location.As many organizations have more than one
location, cumulative probability of detected exploitation increases
exponentially as more locations are included.Looking at cumulative detected probability
over a 12-month period per location, wide variances emerged across industries.And, cumulative probabilities plotted over a
12-month period with 10 protected locations resulted in virtually all
organizations detecting an exploit that bypassed the perimeter at a minimal of
83 percent or higher.Organizations familiar with the complexity and
resource-intensive nature of managing vulnerabilities are likely not surprised
by these statistics. In an imbalanced equation, threat actors have to find one
blind spot while resource-constrained cybersecurity teams must account for
every potential blind spot.To visualize the disparity, the following is a
high-level comparison of a threat actor’s approach vs. a security team:Notice the distinct differences between the
two approaches:
Time required to execute
Complexity required to execute
Resources required to execute
While this may seem to paint a picture of
impending doom, the reality is that mitigating risk of exploitation against
critical assets is for the most part avoidable. Research proves that organizations
with a fully functioning and resourced vulnerability management program is an
effective preventative measure to the risk of exploitation. If you believe your
organization may be at risk or under resourced to effectively operationalize an
effective vulnerability management program, read more about the vulnerabilities
organizations like yours are facing in our latest Threat
Intelligence Report or learn more about how we help organizations with eSentire
Managed Vulnerability Service.
Wes Hutcherson,
Director of Product Marketing at eSentire
There are many ways to do DevSecOps, and each organization — each security team, even — uses a different approach. Questions such as how many environments you have and the frequency of deployment of those environments are important in understanding how to integrate a security scanner into your DevSecOps machinery. The ultimate goal is speed […]
It’s Cybersecurity Awareness Month, but security awareness is about much more than just dedicating a month to a few activities. Security awareness is a journey, requiring motivation along the way. And culture. Especially culture.That’s the point Proofpoint Cybersecurity Evangelist Brian Reed drove home in a recent appearance on Business Security Weekly.“If your security awareness program […]
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news