Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

6/25/2018
02:30 PM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

Midsized Organizations More Secure Than Large Ones

New report offers data and analysis as to why midsized organizations hit a cybersecurity sweet spot in terms of security efficacy.

A new report based on data from an extensive body of penetration tests shows that while prevailing opinion believes big enterprises do the best job at securing their systems and data, it is actually midsized organizations that outperform small and large businesses.

Based on over 300 individual penetration tests conducted over the course of seven months, the Coalfire Labs Penetration Risk Report examines data about vulnerabilities and risks with relation to a number of company factors. 

Most surprising among the findings are those related to company size. For the purpose of this report, small organizations are defined as those with up to $100 million in revenue, medium as those between $100 million and $1 billion in revenue, and large as those with greater than $1 billion in revenue. The study showed that large organizations fared the worst in terms of the overall number of high-risk vulnerabilities exposed to attackers, and medium organizations fared the best. 

The report proposes that midsized organizations occupy a cybersecurity sweet spot because small enterprises may be too unsophisticated or underfunded, while larger ones with a large volume of cybersecurity funds have such diverse IT operations — complex, dynamic and geographically diverse — that security teams struggle to keep up even with deep pockets at their disposal. 

"Our extensive penetration tests flip the thinking that large enterprises are the most secure, even with the largest cybersecurity budgets and investments in staffing and other resources," says Mike Weber, vice president of Coalfire Labs.

Some of the other findings won't surprise most veteran security practitioners. For example, by sector financial services tends to perform best, while healthcare and retail performs the worst. Similarly unsurprising, the study showed that organizations of all sizes still struggle in the basic blocking and tackling efforts of overall security hygiene.

"Too often, companies spend too much time and money trying to identify really complex, sophisticated technical cybersecurity challenges when, if they spent the same time and energy doing the basics, they could reduce their overall corporate risk by literal orders of magnitude," explains Mark Weatherford, chief cybersecurity strategist at vArmour and member of the Coalfire Advisory Board. 

Also not a shocker: companies of all sizes also tend to do a better job protecting themselves from external-based threats, but leave their internal network connections less secured. The report shows that the majority of high-risk vulnerabilities were associated with application and internal attack vectors. In other words, most companies are still caught up in the perimeter-centric mode of protection. 

Why Cybercriminals Attack: A DARK READING VIRTUAL EVENT Wednesday, June 27. Industry experts will offer a range of information and insight on who the bad guys are – and why they might be targeting your enterprise. Go here for more information on this free event.

Consequently, humans tend to be the weakest link when it comes to keeping attackers from reaching organizations' most sensitive assets. Organizations suffer the most significant risk from threats when employees allow attackers to gain an insider position through phishing or other social engineering means. The weaknesses in internal network protections then give those attackers free rein to move at will in pursuit of high value IT assets. 

"Overall, our results conclude that humans — employees, vendors, and customers — still represent the greatest vulnerability as they are prone to social engineering techniques, shortcuts, or inadvertent oversights in the IT/security management process," Weber says.

Interestingly, though midsized organizations perform best when it comes to security operations, they actually did most poorly when it came to social engineering and phishing. This likely comes down to smaller organizations operating in more intimate environments, according to the report, whereas larger organizations tend to operate in more bureaucratic environments that require and audit security awareness training and strictly administer rules and processes that prevent social engineering. 

Related Content:

 

 

 

 

Ericka Chickowski specializes in coverage of information technology and business innovation. She has focused on information security for the better part of a decade and regularly writes about the security industry as a contributor to Dark Reading.  View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Commentary
Ransomware Is Not the Problem
Adam Shostack, Consultant, Entrepreneur, Technologist, Game Designer,  6/9/2021
Edge-DRsplash-11-edge-ask-the-experts
How Can I Test the Security of My Home-Office Employees' Routers?
John Bock, Senior Research Scientist,  6/7/2021
News
New Ransomware Group Claiming Connection to REvil Gang Surfaces
Jai Vijayan, Contributing Writer,  6/10/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
The State of Cybersecurity Incident Response
In this report learn how enterprises are building their incident response teams and processes, how they research potential compromises, how they respond to new breaches, and what tools and processes they use to remediate problems and improve their cyber defenses for the future.
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2010-2486
PUBLISHED: 2021-06-22
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none.
CVE-2021-0534
PUBLISHED: 2021-06-22
In permission declarations of DeviceAdminReceiver.java, there is a possible lack of broadcast protection due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Android...
CVE-2021-0535
PUBLISHED: 2021-06-22
In wpas_ctrl_msg_queue_timeout of ctrl_iface_unix.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID...
CVE-2021-0554
PUBLISHED: 2021-06-22
In isBackupServiceActive of BackupManagerService.java, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-158482162
CVE-2021-0555
PUBLISHED: 2021-06-22
In RenderStruct of protostream_objectsource.cc, there is a possible crash due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-1791617...