Urgences 24 sur 7 – (888) 287-5858     Support     Contactez-nous    Blogue

Main attack vectors found by penetration testers are not perceived as essential elements contributing to cybersecurity professionals’ perception of the security maturity of their organization.

La Jolla, CA – GoSecure, a leading provider of Managed Detection and Response (MDR) market, services, and a predictive Endpoint Detection and Response (EDR) platform, today released a new research report, Cybersecurity Perceptions Versus Reality, which revealed a disconnect between defenders’ perceptions of how best to protect their organizations, what has been implemented, and what is needed based on what GoSecure penetration testers see in the real world.

« This report illustrates what cybersecurity professionals perceive as important to an organization’s overall security maturity, » said Neal Creighton, CEO of GoSecure. « It also highlights that the reality of what is implemented can be vastly different. The perceptions of what is important align well for defending some of the most common attack techniques used by penetration testers. Yet our pentesters continue to identify missing controls or highlight critical findings related to each survey topic. »

To distinguish perception from reality, GoSecure’s research team developed a survey in collaboration with Serene-risc, a knowledge mobilization network in cybersecurity. The survey focused on the importance of specific security measures or controls and whether they are implemented. Security measures called out in the survey include multi-factor authentication, password policies, specific security measures, patch management, products’ features enabled by default, asset inventories, and endpoint visibility. The results of the survey were then cross-referenced against findings from the GoSecure penetration testing team.

Key findings include:

  • Multi-Factor Authentication is valued by security professionals, as 93% of survey respondents rated MFA as « important » or « very important. » Unfortunately, only 47% have fully implemented MFA, with 13% having zero MFA. GoSecure penetration testing identified MFA as a missing control in 36% of engagements.
  • Password Policies are well established but vary in complexity. Passwords over six characters in length are supported by 56.3% of respondents, while 74.8% said that passwords need to be a mix of letters, numbers, and special characters. However, the requirement for regular password changes was mixed with 43.7% saying it is important and 43.7% disagreeing. Interestingly, 40% of respondents have not, or have only partially, implemented their perceived « ideal » password policy. And for all the talk of password policies and complexities, GoSecure penetration testers are still successful 25% of the time cracking passwords using password spraying, a fairly basic password cracking technique.
  • Patch Management is rated as « important » or « very important » by 90% of respondents. The reality, though, is 52.6% of respondents say it takes weeks, months, or even years to apply patches. GoSecure penetration testing experience highlighted that while Microsoft Windows patching was generally well managed owing to the abundance of free tools, this is not the case for the rest of line-of-business applications. Crucial applications, such as Java, Flash, or non-Microsoft browsers, are usually less well maintained and account for many vulnerabilities.

Overall, the report’s outcomes concluded that although there are concerted efforts in the industry to protect systems, significant security gaps continue to exist. In addition to highlighting the disconnects, the report includes actionable insights and pro tips from GoSecure pentesters to remedy the security gaps uncovered in the research.

« Cybersecurity teams are under constant pressure, and, as this report illustrates, sometimes the simplest changes are missed. » Creighton continued, « As a member of the cybersecurity community, we are proud to offer this insight along with actionable recommendations. Every small step incrementally increases an organization’s security maturity, which, ultimately, is required to stay ahead of today’s attackers. »

 

French Version (PDF)



About GoSecure
GoSecure is a recognized cybersecurity leader, delivering innovative managed security solutions and expert advisory services. GoSecure Titan® managed security solutions deliver multi-vector protection to counter modern cyber threats through a complete suite of offerings that extend the capabilities of our customers’ in-house teams. GoSecure Titan Managed Detection & Response (MDR) offers a best in class mean-time-to-respond, with comprehensive coverage across customers’ networks, endpoints and inboxes. For over 10 years, GoSecure has been helping customers better understand their security gaps, improve organizational risk and enhance security posture through advisory services provided by one of the most trusted and skilled teams in the industry.

    Media Contact

      info@gosecure.net

Détection et réponse gérées et étendues GoSecure TitanMC (MXDR)

Détection et réponse gérées et étendues GoSecure TitanMC (MXDR) Fondation

Gestion des vulnérabilités en tant que service GoSecure TitanMC (VMaaS)

Surveillance des événements liés aux informations de sécurité gérée GoSecure TitanMC (SIEM)

Défense du périmètre gérée GoSecure TitanMC (pare-feu)

Détection et réponse des boîtes de messagerie GoSecure TitanMC (IDR)

Passerelle de messagerie sécurisée GoSecure TitanMC (SEG)

Modélisateur de menaces GoSecure TitanMC

Identity GoSecure TitanMC

Plateforme GoSecure TitanMC

Services de sécurité professionnels de GoSecure

Services de réponse aux incidents

Évaluation de la maturité de la sécurité

Services de confidentialité

Services PCI DSS

Services de piratage éthique

Opérations de sécurité

MicrosoftLogo

GoSecure MXDR pour Microsoft

Visibilité et réponse complètes au sein de votre environnement de sécurité Microsoft

CAS D'UTILISATION

Cyberrisques

Mesures de sécurité basées sur les risques

Sociétés de financement par capitaux propres

Prendre des décisions éclairées

Sécurité des données sensibles

Protéger les informations sensibles

Conformité en matière de cybersécurité

Respecter les obligations réglementaires

Cyberassurance

Une stratégie précieuse de gestion des risques

Rançongiciels

Combattre les rançongiciels grâce à une sécurité innovante

Attaques de type « zero-day »

Arrêter les exploits de type « zero-day » grâce à une protection avancée

Consolider, évoluer et prospérer

Prenez de l'avance et gagnez la course avec la Plateforme GoSecure TitanMC.

24/7 MXDR

Détection et réponse sur les terminaux GoSecure TitanMC (EDR)

Antivirus de nouvelle génération GoSecure TitanMC (NGAV)

Détection et réponse sur le réseau GoSecure TitanMC (NDR)

Détection et réponse des boîtes de messagerie GoSecure TitanMC (IDR)

Intelligence GoSecure TitanMC

À PROPOS DE GOSECURE

GoSecure est un leader et un innovateur reconnu en matière de cybersécurité, pionnier de l'intégration de la détection des menaces au niveau des terminaux, du réseau et des courriels en un seul service de détection et réponse gérées et étendues (MXDR). Depuis plus de 20 ans, GoSecure aide ses clients à mieux comprendre leurs failles en matière de sécurité et à améliorer leurs risques organisationnels ainsi que leur maturité en matière de sécurité grâce aux solutions MXDR et aux services professionnels fournis par l'une des équipes les plus fiables et les plus compétentes de l'industrie.

CALENDRIER D’ÉVÉNEMENTS

DERNIER COMMUNIQUÉ DE PRESSE

BLOGUE GOSECURE

AVIS DE SÉCURITÉ

Urgences 24 sur 7 – (888) 287-5858