Risk

6/25/2018
02:30 PM
Connect Directly
Twitter
Twitter
RSS
E-Mail
50%
50%

Midsized Organizations More Secure Than Large Ones

New report offers data and analysis as to why midsized organizations hit a cybersecurity sweet spot in terms of security efficacy.

A new report based on data from an extensive body of penetration tests shows that while prevailing opinion believes big enterprises do the best job at securing their systems and data, it is actually midsized organizations that outperform small and large businesses.

Based on over 300 individual penetration tests conducted over the course of seven months, the Coalfire Labs Penetration Risk Report examines data about vulnerabilities and risks with relation to a number of company factors. 

Most surprising among the findings are those related to company size. For the purpose of this report, small organizations are defined as those with up to $100 million in revenue, medium as those between $100 million and $1 billion in revenue, and large as those with greater than $1 billion in revenue. The study showed that large organizations fared the worst in terms of the overall number of high-risk vulnerabilities exposed to attackers, and medium organizations fared the best. 

The report proposes that midsized organizations occupy a cybersecurity sweet spot because small enterprises may be too unsophisticated or underfunded, while larger ones with a large volume of cybersecurity funds have such diverse IT operations — complex, dynamic and geographically diverse — that security teams struggle to keep up even with deep pockets at their disposal. 

"Our extensive penetration tests flip the thinking that large enterprises are the most secure, even with the largest cybersecurity budgets and investments in staffing and other resources," says Mike Weber, vice president of Coalfire Labs.

Some of the other findings won't surprise most veteran security practitioners. For example, by sector financial services tends to perform best, while healthcare and retail performs the worst. Similarly unsurprising, the study showed that organizations of all sizes still struggle in the basic blocking and tackling efforts of overall security hygiene.

"Too often, companies spend too much time and money trying to identify really complex, sophisticated technical cybersecurity challenges when, if they spent the same time and energy doing the basics, they could reduce their overall corporate risk by literal orders of magnitude," explains Mark Weatherford, chief cybersecurity strategist at vArmour and member of the Coalfire Advisory Board. 

Also not a shocker: companies of all sizes also tend to do a better job protecting themselves from external-based threats, but leave their internal network connections less secured. The report shows that the majority of high-risk vulnerabilities were associated with application and internal attack vectors. In other words, most companies are still caught up in the perimeter-centric mode of protection. 

Why Cybercriminals Attack: A DARK READING VIRTUAL EVENT Wednesday, June 27. Industry experts will offer a range of information and insight on who the bad guys are – and why they might be targeting your enterprise. Go here for more information on this free event.

Consequently, humans tend to be the weakest link when it comes to keeping attackers from reaching organizations' most sensitive assets. Organizations suffer the most significant risk from threats when employees allow attackers to gain an insider position through phishing or other social engineering means. The weaknesses in internal network protections then give those attackers free rein to move at will in pursuit of high value IT assets. 

"Overall, our results conclude that humans — employees, vendors, and customers — still represent the greatest vulnerability as they are prone to social engineering techniques, shortcuts, or inadvertent oversights in the IT/security management process," Weber says.

Interestingly, though midsized organizations perform best when it comes to security operations, they actually did most poorly when it came to social engineering and phishing. This likely comes down to smaller organizations operating in more intimate environments, according to the report, whereas larger organizations tend to operate in more bureaucratic environments that require and audit security awareness training and strictly administer rules and processes that prevent social engineering. 

Related Content:

 

 

 

 

Ericka Chickowski specializes in coverage of information technology and business innovation. She has focused on information security for the better part of a decade and regularly writes about the security industry as a contributor to Dark Reading.  View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
WebAuthn, FIDO2 Infuse Browsers, Platforms with Strong Authentication
John Fontana, Standards & Identity Analyst, Yubico,  9/19/2018
Turn the NIST Cybersecurity Framework into Reality: 5 Steps
Mukul Kumar & Anupam Sahai, CISO & VP of Cyber Practice and VP Product Management, Cavirin Systems,  9/20/2018
NSS Labs Files Antitrust Suit Against Symantec, CrowdStrike, ESET, AMTSO
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/19/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Flash Poll
The Risk Management Struggle
The Risk Management Struggle
The majority of organizations are struggling to implement a risk-based approach to security even though risk reduction has become the primary metric for measuring the effectiveness of enterprise security strategies. Read the report and get more details today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-17283
PUBLISHED: 2018-09-21
Zoho ManageEngine OpManager before 12.3 Build 123196 does not require authentication for /oputilsServlet requests, as demonstrated by a /oputilsServlet?action=getAPIKey request that can be leveraged against Firewall Analyzer to add an admin user via /api/json/v2/admin/addUser or conduct a SQL Inject...
CVE-2018-17282
PUBLISHED: 2018-09-20
An issue was discovered in Exiv2 v0.26. The function Exiv2::DataValue::copy in value.cpp has a NULL pointer dereference.
CVE-2018-14592
PUBLISHED: 2018-09-20
The CWJoomla CW Article Attachments PRO extension before 2.0.7 and CW Article Attachments FREE extension before 1.0.6 for Joomla! allow SQL Injection within download.php.
CVE-2018-15832
PUBLISHED: 2018-09-20
upc.exe in Ubisoft Uplay Desktop Client versions 63.0.5699.0 allows remote attackers to execute arbitrary code. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of URI ha...
CVE-2018-16282
PUBLISHED: 2018-09-20
A command injection vulnerability in the web server functionality of Moxa EDR-810 V4.2 build 18041013 allows remote attackers to execute arbitrary OS commands with root privilege via the caname parameter to the /xml/net_WebCADELETEGetValue URI.