Comprehensive software reviews to make better IT decisions
Rapid7 Penetration Tests Show That Businesses Are Getting Better at Network Security
We often hear that businesses are continually cyber insecure or under attack. However, recent penetration testing from Rapid7 shows that businesses are getting better at securing their networks against cyberattacks. While organizations continue to have exploitable weaknesses, attackers are having greater difficulty penetrating deeper into businesses’ networks.
A combination of better adherence to best practices and use of monitoring programs and new tools in vulnerability and patch management is forcing attackers to change their tactics. Awareness of security and observation of a company’s network is on the rise, decreasing open attack vectors for attackers.
Source: SoftwareReviews Product Scorecard, Accessed May 11, 2020.
However, data pulled from hundreds of penetration tests conducted by Rapid7 have shown that even with improvement, businesses are still failing basic security practices. Patch management, password quality, and a lack of visibility remain common problems for businesses. In 72% of their penetration tests, Rapid7 was able to gather user credentials through standard password spraying. While this is serious, the testers were unable to break the boundary between the external and internal networks. Implementation of network segmentation has prevented these credential losses from becoming an extreme security threat, showing promise for the future of security adherence.
The consensus from the hundreds of penetration tests conducted by Rapid7 is that businesses are slowly getting better at securing their networks, but they can still encounter issues with the basics. Chris Nickerson, CEO at Lares, another penetration testing firm, notes that tooling debt is an overarching problem. Over the years organizations have spent a great deal of money on security tools, adding and discarding them as the business changes. This creates a problem in which organizations will often have multiple poorly integrated tools with no oversight or cohesive strategy.
These continual changes in a program library can be a net negative for the security side of the business, making it hard for consistency and business customization to stay in effect. They can also lead to unpatched security systems, unsupported programs, and open vulnerabilities for the enterprise and can also make it harder to detect alerts from previous penetration tests. A solid vulnerability management suite often comes with programs that include both patch management (a noted issue) and network and inventory assessment tools. These tools can tell you exactly what is on your network, unveiling legacy programs and potential vulnerable entry points.
While businesses are doing better in efforts to secure their networks, there is always room for improvement. Consider your security program against the Rapid7’s list of identified common flaws. Locate where there is room for improvement on best practices and common vulnerabilities to ensure that you’re staying ahead of attackers.
Want to Know More?
The Department of Justice is looking to acquire a GRC tool for the Office of the CIO within the FBI’s Enterprise Information Security Section.
Google has identified “unsafe” code in the Chromium web browser engine. This flaw introduces a potential vulnerability that effects Google Chrome, as well as all Chromium-based web browsers.
The International Association of Privacy Professionals (IAPP) has released its 2020 Privacy Tech Vendor report, reviewing key software solution vendors within the space. This year’s report highlighted the recent addition of Data Subject Request (DSR) to the feature categories.
Among the full set of features available in Zecurion’s new DLP product is the ability to perform user behavior analytics to help spot data loss events before they occur.
Zecurion has one of the most robust DLP products on the market and this fact was recently recognized by SC Magazine, who placed the product in its “pick-of-the-litter" category for DLP.
In early March, Titus released Titus Illuminate 2020, which was the company’s answer to the question of analyzing data at rest. This latest version of Illuminate leverages machine learning and AI in an effort to manage data that contains potentially sensitive or high-risk personal information.
More than ever, cybersecurity solutions are core to any MSPs offering. No longer should technology service providers be farming this out to dedicated security providers. Trust and peace of mind are the core tenets of what they are selling and solutions like Acronis Cyber Protect Cloud can provide the platform upon which to deliver on those promises.
PHEMI is a data privacy solution focused on keeping data-processing activities secure by redacting information based on the role of the accessor. Thus, allowing such data to be used for multiple use cases without compromising privacy.
Kenna Security deployed their new data driven vulnerability management program, Kenna.VM and accessory program, Kenna.VI. Released on April 28th, Kenna.VM was created with the purpose to set service-level agreements (SLAs) with risk tolerance in mind.