A recent survey of more than 30,000 websitesfound that most of them had at least one serious security hole for at least 150 days.
“These vulnerabilities are potentially damaging,” says Jeremiah Grossman, founder of WhiteHat, which conducted the study. “They could compromise entire systems or data and accounts.” These are the kinds of vulnerabilities that need to be fixed immediately before they become public knowledge.
Commercial sites came in second on the list with the most vulnerabilities, with 55% of websites having at least one serious hole almost every day. Which were the worst? websites , with 64% vulnerable every day of the year. Only 1 or 2% of the vulnerabilities were fixable, according to Grossman.
To dig deeper into why these vulnerabilities were not being fixed, WhiteHat conducted in-depth surveys with 118 of its client companies, ranging from start-ups to large enterprises. The biggest question was whether the company’s remediation efforts were driven by compliance or risk reduction.
Those that focused on compliance had the fewest vulnerabilities, just 12 per website. They also had the highest remediation rates, with a ratio of fixed to unfixed vulnerabilities during the study period of 86%.
Organizations that initially acted on a risk reduction basis had an average of 23 vulnerabilities per website and remediation rates of 18%.
One of the reasons why companies focus on risk could be that they categorize vulnerabilities based on their danger level and only fix the absolutely dangerous ones.
Meanwhile, companies that are compliance-driven take longer to patch vulnerabilities, about 158 days compared to 115 days for companies that are risk-driven. This is likely because they can’t afford to wait until the next audit to patch the vulnerability.
Another factor was whether the vulnerabilities were detected by a vulnerability detection system.
Fixing the problem requires companies to have their staff transcribe vulnerability reports, or work with security vendors to properly feed the results into the vulnerability detection system.

