UNDER CONSTRUCTION!!!

Tech News

Keeping You Up To Date With The Latest Tech News & Virus Threats
Font size: +

Study Reveals Massive Gap in Cyber Defenses

Study Reveals Massive Gap in Cyber Defenses

News

padlock icon on abstract background Alamy

XM Cyber recently published its third annual research report, "Navigating the Paths of Risk: The State of Exposure Management,” which sheds light on prominent risks and vulnerabilities that organizations face in today's dynamic threat environment.

The report reveals alarming gaps in the cyber defenses of many organizations, calling out misconfigured identity and access controls as a massive attack vector exploited by adversaries. For example, the study indicates that identity and credential misconfigurations account for a staggering 80% of security exposures across organizations, with one-third of these exposures directly jeopardizing critical assets. Many of these exposures stem from misconfigurations in Active Directory, a central system for managing user access, due to it inherently containing vulnerabilities often missed by many security tools. Blind spots in tasks such as user account management and password resets pose issues for nearly every organization.Top of Form

The report also shows that while vulnerabilities tracked by common identifiers like CVEs are a primary concern for most security programs, they represent only 1% of the massive exposure landscape. On average, organizations have about 15,000 exposures scattered across their environments, presenting opportunities for skilled attackers. Given that CVE-based vulnerabilities represent less than 1% of this vast risk surface, security strategies focused solely on vulnerability patching have critical blind spots. 

XM CyberAn example attack graph identifying entities, dead ends, choke points, and critical assets.

An example attack graph identifying entities, dead ends, choke points, and critical assets. (Credit: XM Cyber)

Cloud environments are not immune to the risk of exposure. As cloud adoption continues to increase, the report reveals how these risks extend to cloud environments, with more than half (56%) of exposures affecting critical assets residing in platforms like AWS, Azure, and Google Cloud Platform. Attackers can easily pivot between on-premises and cloud systems in 70% of organizations and then compromise 93% of critical assets in the cloud in just two hops. This presents significant threats to cloud-based assets.

Overall, the findings underscore the importance of comprehensive exposure management for organizations to understand and mitigate cyber risk effectively, extending beyond merely addressing vulnerabilities. Organizations with poor exposure management posture scores have six times as many security exposures compared to those with higher posture scores. Additionally, exposure management cannot be treated as a one-time or annual project; it must be an ongoing process to continually enhance an organization's cyber risk posture. Identifying all possible attack vectors, analyzing how threat actors can chain together disparate exposures, and prioritizing remediation efforts accordingly are critical in reducing risk. 

This report presents insights from the analysis of more than 40 million exposures affecting 11.5 million critical business entities. These exposures were uncovered through hundreds of thousands of attack path assessments conducted by XM Cyber's Continuous Exposure Management platform in 2023. The data collected from XM Cyber's platform was anonymized and provided to Cyentia Institute for independent analysis to generate the report's insights.

TAGS: Vulnerabilities and Threats Compliance and Risk Management

×
Stay Informed

When you subscribe to the blog, we will send you an e-mail when there are new updates on the site so you wouldn't miss them.

Helldivers 2 update: Sony reverses its decision to...
Randy Travis gets his voice back in a new Warner A...
 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Sunday, 19 May 2024

Captcha Image

I Got A Virus and I Don't Know What To Do!

I Need Help!