ANALYSIS: The Cybersecurity and Infrastructure Agency’s (CISA) Secure by Design Pledge shows a lot of promise. CISA’s recommendations for the future are a reflection of the current state of affairs – one in which vulnerabilities run rampant, and organizations struggle to gain visibility into their risk and exposures.Legacy devices and systems are particularly vulnerable. These older technologies often lack modern security features, making them a prime target for cyberattacks. For example, research reveals that older Windows server OS versions (2012 and earlier) are 77% more likely to experience attack attempts compared to newer Windows Server versions.[SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Read more Perspectives here.]Amid such a vulnerable threat landscape – global attack attempts more than doubled in 2023 – there’s an urgent need for organizations to focus on the "boring basics" of cybersecurity to effectively mitigate risks.Identify and address blind spots: Continuously monitor and assess networks to discover and remediate vulnerabilities. Conduct regular asset inventories: Regularly inventory and review assets to identify critical systems and prioritize their protection. Prioritize risks: Focus on the most critical vulnerabilities by assessing their potential impact and likelihood of different threats, allowing for strategic resource allocation and effective security measures. Practice proactive vulnerability management: Continuously improve processes for vulnerability patch management, emphasizing prompt deployment and effective remediation. CISA’s Secure by Design Pledge offers a visionary roadmap for the future of cybersecurity, reinforcing the importance of security operations teams addressing the pervasive vulnerabilities that matter most. By leveraging the principles of the pledge—such as proactive vulnerability management—organizations can fortify their defenses against escalating cyber threats. Ultimately, the success of the Secure by Design Pledge initiative hinges on a fundamental commitment to the "boring basics" of cybersecurity so that all systems, old and new, are resilient against potential attacks.Nadir Izrael, co-founder and CTO, ArmisSC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Each contribution has a goal of bringing a unique voice to important cybersecurity topics. Content strives to be of the highest quality, objective and non-commercial.
Vulnerability Management
Here’s why it’s important to take CISA’s ‘Secure by Design Pledge’ seriously

Today’s columnist, Nadir Izrael of Armis, explains CISA’s “Secure By Design Pledge.” (Adobe Stock)
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds