“Despite all the attention and investment in cybersecurity, the majority of businesses in the US and UK still remain open to attack.” So says a new cybersecurity survey conducted by 1E parameter management experts and Vanson Bourne researchers, a survey that questioned 600 IT businesses and IT security decision-makers in the US and UK and found that 60% had been breached in the past two years and 31% of businesses had been breached more than once.

Sumir Karayi, CEO of 1E, said the research showed that “the vast majority of successful attacks today exploit known vulnerabilities in software that have already been patched by software vendors.
So most of the successful attacks can be stopped simply by knowing what’s out there and making sure you’ve patched your vulnerabilities. But for about a third of these organizations’ on-premises installations, the CIO team doesn’t really know what hardware is out there or what software is running on it. How do you fix that?”
In an interview with Forbes the journalist asked if this meant that his message to the CIO and CISO community was that if you fall victim to a breach or get hacked, it is your own fault. He paused and then said “yes”.
Think about WannaCry or NotPetya (ransomware attacks of 2017 on computers with Microsoft Windows), explain. “The vulnerabilities were known and patched. ” Why were the solutions not implemented;” The reality is that most organizations do not focus on this. What many security teams do is postpone procedures while it is the best defense for businesses.”
This research supports that “despite significant investments in the field of cybersecurity across many sectors, there has been very limited improvement with the biggest error factor being in the organization: keeping endpoints properly patched and updated” and that 93% of respondents face challenges, the main ones being limited budgets, lack of understanding between IT operations and IT security, and legacy systems. ”
And it is getting worse, said Sumir. “An analyst at Forrester, who monitors about 150 security companies, said he hears about about five or ten new ones almost every week in the security space. And each one claims it can fix larger and worse threats than the others can. I feel there is an exaggeration from network security companies.”
“Only one device that is not fully updated is needed to create a foothold in the network, putting the entire organization at risk”, explains the research. “However, our data reveal how small the visibility – let alone control – IT Operations have far too many corporate endpoints, especially with the constantly growing number of remote workers. This lack of visibility and control undermines efforts for proper remediation and protection of the environment.
Simple issues
Sumir spoke many times about the following topics: automated updates and upgrades, remote work, expansion of the number of endpoints, lack of basic IT services and mainly tension and poor relationships between IT operations and security teams. “The respondents identified the main causes of breaches as lack of clear security protocols (52%) and unpatched software (51%), followed by lack of IT Security / Operations collaboration (42%) and lack of patch automation (40%).”
Microsoft MVP Jason Sandys, who is referenced in the report, says that it is a matter of behavior. IT Security is considered an enemy that hinders the productivity of IT Operations.
Time change
And remote work makes all of this almost impossible to fix. “Remote workers do not always have strong subordination to the company”, says Sumir. He also continues “many security tools were designed for people who work from the office and did not work from home, they were designed for machines inside the corporate perimeter, in a well-managed and rapidly connected environment, when work hours were also known. Nothing of that applies anymore. ”
And so, according to the research, “less than one quarter [of organizations] believe they are extremely ready to respond to a serious data breach”.
People have different work patterns. They also have more devices. “The number of devices is going up, and that’s such a big factor,” Sumir explained. “The same problems we solved with computers we now have to solve with IoT. Firmware has to be up to date and patched, devices have to have the right settings. Any IoT that’s networked, it’s an entry point into the corporate network, an entry point into the organization, whose security could be a problem. If it’s not secure then someone has direct access to your corporate network, which means your perimeter has been breached.”
What’s happening with IoT?
The report found that “the Dark Web has facilitated intruders to profit from stolen data. As the value of data has increased, so the funding and complexity of cybercriminals aim to exploit software vulnerabilities to gain access to them. Breaches are becoming increasingly frequent and devastating. ».
“The problem seems to be getting worse,” Sumir said, “and we need to address it because otherwise, the number of breaches will continue to increase. Going digital means more software which means more vulnerabilities and ultimately more attacks.
Remote working is a change that businesses are not used to until now. And so IoT is a big concern for the future.”
“It is clear that these issues cannot continue”, the report says. “Especially when more malicious, better funded and more organized attacks occur”.
Making improvements
The report concludes with advice and a ten‑point action plan from Michael Daniel, former special assistant to President Obama and currently CEO of the Cyber Threat Alliance. “While you can never drive network security to the highest levels”, he says in the report, “if IT and cybersecurity businesses collaborate, the risk could be dramatically reduced”.
Sumir continues, “IT teams are still slow to respond,” he said. “Days and weeks to respond, think about NotPetya infecting 40,000 to 50,000 endpoints in a matter of hours.” If you don’t react in the first few seconds or minutes, you’re in trouble. When it comes to budget allocation, the vast majority (90%) of respondents say their business prioritizes other cybersecurity issues. The most pressing question is: how do we prioritize the resources available?
Respondents believe more investment is needed in these areas: software migration automation (80%),
breach response and remediation (67%), and/or software patching (65%).
The report makes reading interesting. It is inevitably dangerous for the security of endpoints, given its sponsors. However, the issues surrounding remote operations and the Internet's vulnerabilities are clear to everyone, even if the idea that different IT organizations could set aside their policies and differences and perhaps collaborate is less so.
