According to Tanium, a security and endpoint management company, more than 90% of organizations worldwide have been forced to delay key security projects as many organizations have resorted to remote work due to the outbreak of the COVID-19 pandemic, while they have stopped patching and updating systems . As a result, they are more exposed to cyberattacks. Specifically, the company conducted a survey, in which it asked 1000 CXOs (Chief Experiences Officers), to better understand how the pandemic has changed the cyber threat landscape.
According to the survey, identity and asset management (39%) and security strategy (39%) were the most critical security projects that organizations have been forced to delay. In the UK, for example, solutions for virus and malware (37%) and solutions related to networking zoning (36%) are most at risk of being delayed.

Patching has also been a key challenge for many organizations, with 88% admitting they have struggled during the pandemic. This is despite Microsoft’s massive Patch Tuesday for administrators in recent months, including the largest set of CVEs issued in June.
Many CXOs surveyed by Tanium seemed to be under the illusion that they wouldn’t face security issues at the start of the pandemic. Specifically, 85% of respondents said they felt ready to transition to remote work, but by the end, 98% admitted that they hadn’t considered security challenges in the first two months of the health crisis.

The top three challenges they faced were: detecting new personal computing devices (27%), VPN (22%), and security risks during video conferencing (20%). Additionally, 90% of respondents revealed that cyber threats had increased, noting that the most common attacks were data exposure and leakage (38%), BEC or transaction fraud (37%), and phishing (35%).
Tanium CISO Chris Hodson said that many organizations were unprepared for such a sudden shift to remote work at the beginning of the COVID-19 pandemic, while the increase in cyberattacks and critical vulnerabilities made it clear that a lot of time is still needed to adopt and implement an effective strategy that responds to the new reality prevailing in the IT sector.
