Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

6/25/2018
02:30 PM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

Midsized Organizations More Secure Than Large Ones

New report offers data and analysis as to why midsized organizations hit a cybersecurity sweet spot in terms of security efficacy.

A new report based on data from an extensive body of penetration tests shows that while prevailing opinion believes big enterprises do the best job at securing their systems and data, it is actually midsized organizations that outperform small and large businesses.

Based on over 300 individual penetration tests conducted over the course of seven months, the Coalfire Labs Penetration Risk Report examines data about vulnerabilities and risks with relation to a number of company factors. 

Most surprising among the findings are those related to company size. For the purpose of this report, small organizations are defined as those with up to $100 million in revenue, medium as those between $100 million and $1 billion in revenue, and large as those with greater than $1 billion in revenue. The study showed that large organizations fared the worst in terms of the overall number of high-risk vulnerabilities exposed to attackers, and medium organizations fared the best. 

The report proposes that midsized organizations occupy a cybersecurity sweet spot because small enterprises may be too unsophisticated or underfunded, while larger ones with a large volume of cybersecurity funds have such diverse IT operations — complex, dynamic and geographically diverse — that security teams struggle to keep up even with deep pockets at their disposal. 

"Our extensive penetration tests flip the thinking that large enterprises are the most secure, even with the largest cybersecurity budgets and investments in staffing and other resources," says Mike Weber, vice president of Coalfire Labs.

Some of the other findings won't surprise most veteran security practitioners. For example, by sector financial services tends to perform best, while healthcare and retail performs the worst. Similarly unsurprising, the study showed that organizations of all sizes still struggle in the basic blocking and tackling efforts of overall security hygiene.

"Too often, companies spend too much time and money trying to identify really complex, sophisticated technical cybersecurity challenges when, if they spent the same time and energy doing the basics, they could reduce their overall corporate risk by literal orders of magnitude," explains Mark Weatherford, chief cybersecurity strategist at vArmour and member of the Coalfire Advisory Board. 

Also not a shocker: companies of all sizes also tend to do a better job protecting themselves from external-based threats, but leave their internal network connections less secured. The report shows that the majority of high-risk vulnerabilities were associated with application and internal attack vectors. In other words, most companies are still caught up in the perimeter-centric mode of protection. 

Why Cybercriminals Attack: A DARK READING VIRTUAL EVENT Wednesday, June 27. Industry experts will offer a range of information and insight on who the bad guys are – and why they might be targeting your enterprise. Go here for more information on this free event.

Consequently, humans tend to be the weakest link when it comes to keeping attackers from reaching organizations' most sensitive assets. Organizations suffer the most significant risk from threats when employees allow attackers to gain an insider position through phishing or other social engineering means. The weaknesses in internal network protections then give those attackers free rein to move at will in pursuit of high value IT assets. 

"Overall, our results conclude that humans — employees, vendors, and customers — still represent the greatest vulnerability as they are prone to social engineering techniques, shortcuts, or inadvertent oversights in the IT/security management process," Weber says.

Interestingly, though midsized organizations perform best when it comes to security operations, they actually did most poorly when it came to social engineering and phishing. This likely comes down to smaller organizations operating in more intimate environments, according to the report, whereas larger organizations tend to operate in more bureaucratic environments that require and audit security awareness training and strictly administer rules and processes that prevent social engineering. 

Related Content:

 

 

 

 

Ericka Chickowski specializes in coverage of information technology and business innovation. She has focused on information security for the better part of a decade and regularly writes about the security industry as a contributor to Dark Reading.  View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Mobile Banking Malware Up 50% in First Half of 2019
Kelly Sheridan, Staff Editor, Dark Reading,  1/17/2020
Exploits Released for As-Yet Unpatched Critical Citrix Flaw
Jai Vijayan, Contributing Writer,  1/13/2020
Microsoft to Officially End Support for Windows 7, Server 2008
Kelly Sheridan, Staff Editor, Dark Reading,  1/13/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
The Year in Security: 2019
This Tech Digest provides a wrap up and overview of the year's top cybersecurity news stories. It was a year of new twists on old threats, with fears of another WannaCry-type worm and of a possible botnet army of Wi-Fi routers. But 2019 also underscored the risk of firmware and trusted security tools harboring dangerous holes that cybercriminals and nation-state hackers could readily abuse. Read more.
Flash Poll
[Just Released] How Enterprises are Attacking the Cybersecurity Problem
[Just Released] How Enterprises are Attacking the Cybersecurity Problem
Organizations have invested in a sweeping array of security technologies to address challenges associated with the growing number of cybersecurity attacks. However, the complexity involved in managing these technologies is emerging as a major problem. Read this report to find out what your peers biggest security challenges are and the technologies they are using to address them.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-15625
PUBLISHED: 2020-01-18
A memory usage vulnerability exists in Trend Micro Password Manager 3.8 that could allow an attacker with access and permissions to the victim's memory processes to extract sensitive information.
CVE-2019-19696
PUBLISHED: 2020-01-18
A RootCA vulnerability found in Trend Micro Password Manager for Windows and macOS exists where the localhost.key of RootCA.crt might be improperly accessed by an unauthorized party and could be used to create malicious self-signed SSL certificates, allowing an attacker to misdirect a user to phishi...
CVE-2019-19697
PUBLISHED: 2020-01-18
An arbitrary code execution vulnerability exists in the Trend Micro Security 2019 (v15) consumer family of products which could allow an attacker to gain elevated privileges and tamper with protected services by disabling or otherwise preventing them to start. An attacker must already have administr...
CVE-2019-20357
PUBLISHED: 2020-01-18
A Persistent Arbitrary Code Execution vulnerability exists in the Trend Micro Security 2020 (v160 and 2019 (v15) consumer familiy of products which could potentially allow an attacker the ability to create a malicious program to escalate privileges and attain persistence on a vulnerable system.
CVE-2020-7222
PUBLISHED: 2020-01-18
An issue was discovered in Amcrest Web Server 2.520.AC00.18.R 2017-06-29 WEB 3.2.1.453504. The login page responds with JavaScript when one tries to authenticate. An attacker who changes the result parameter (to true) in this JavaScript code can bypass authentication and achieve limited privileges (...