
IT managers are more likely to spot cybercriminals on their servers and networks than anywhere else, according to Sophos' 7 Uncomfortable Truths of Endpoint Security research
Discovering cyber attacks
In fact, IT managers discovered 37% of the most significant cyber attacks on their organization's servers and 37% on their networks.
Only 17% were discovered on endpoints and 10% were found on mobile devices. The survey surveyed more than 3,100 IT managers from mid-sized businesses in 12 countries, including the US, Canada, Mexico, Colombia, Brazil, the UK, France, Germany, Australia, Japan, India and South Africa.
“Servers store financial, employment and other sensitive data, and with stricter laws like GDPRrequiring organizations to report any data breaches, server security packages are at a high level. It makes sense for IT managers to focus on protecting business-critical servers to prevent attackers from entering the network, and this in turn leads to more hacker detections in these two areas,” said Chester Wisniewski, principal researcher at Sophos. “However, IT managers cannot ignore endpoints because most cyber attacks start there, yet a higher than expected number of IT managers still cannot identify how threats enter the system.”
Exposing the starting points of an attack
Twenty percent of IT managers who fell victim to one or more cyberattacks in the past year cannot identify how the attackers gained access and 17 percent do not know how long the threat was in their environment before they detected it, according to the survey.
To improve this latency, IT managers need endpoint detection and response (EDR) technology, which exposes the starting points of a threat and the digital footprints of attackers moving through a network.
“If IT managers don’t know the origin or movement of an attack, they can’t mitigate the risk and break the attack chain to prevent further penetration,” said Wisniewski. “EDR helps IT managers identify risks and implement a process to secure the network. If the technology is more focused on detection, EDR can find, block, and remediate the threat more quickly.”
Defense in depth
On average, organizations that investigate one or more potential security incidents each month spend about 48 days a year (four days a month) investigating them, according to the survey. Not surprisingly, IT managers rank suspicious event identification (27%), alert management (18%), and suspicious event prioritization (13%) as the top three features they need from EDR solutions.
Most cyberattacks can be stopped within seconds on endpoints without sending a notification. Persistent attackers, including those running targeted ransomware like SamSam, buy the time they need to compromise a system by finding poorly chosen passwords on systems that they can exploit remotely (RDP, VNC, VPN, etc.).
Fifty-seven percent of respondents said they plan to implement an EDR solution within the next 12 months. EDR also helps address a skills gap. 80% of IT administrators want to have a stronger team, according to the survey.
