Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

6/25/2018
02:30 PM
Connect Directly
Twitter
Twitter
RSS
E-Mail
50%
50%

Midsized Organizations More Secure Than Large Ones

New report offers data and analysis as to why midsized organizations hit a cybersecurity sweet spot in terms of security efficacy.

A new report based on data from an extensive body of penetration tests shows that while prevailing opinion believes big enterprises do the best job at securing their systems and data, it is actually midsized organizations that outperform small and large businesses.

Based on over 300 individual penetration tests conducted over the course of seven months, the Coalfire Labs Penetration Risk Report examines data about vulnerabilities and risks with relation to a number of company factors. 

Most surprising among the findings are those related to company size. For the purpose of this report, small organizations are defined as those with up to $100 million in revenue, medium as those between $100 million and $1 billion in revenue, and large as those with greater than $1 billion in revenue. The study showed that large organizations fared the worst in terms of the overall number of high-risk vulnerabilities exposed to attackers, and medium organizations fared the best. 

The report proposes that midsized organizations occupy a cybersecurity sweet spot because small enterprises may be too unsophisticated or underfunded, while larger ones with a large volume of cybersecurity funds have such diverse IT operations — complex, dynamic and geographically diverse — that security teams struggle to keep up even with deep pockets at their disposal. 

"Our extensive penetration tests flip the thinking that large enterprises are the most secure, even with the largest cybersecurity budgets and investments in staffing and other resources," says Mike Weber, vice president of Coalfire Labs.

Some of the other findings won't surprise most veteran security practitioners. For example, by sector financial services tends to perform best, while healthcare and retail performs the worst. Similarly unsurprising, the study showed that organizations of all sizes still struggle in the basic blocking and tackling efforts of overall security hygiene.

"Too often, companies spend too much time and money trying to identify really complex, sophisticated technical cybersecurity challenges when, if they spent the same time and energy doing the basics, they could reduce their overall corporate risk by literal orders of magnitude," explains Mark Weatherford, chief cybersecurity strategist at vArmour and member of the Coalfire Advisory Board. 

Also not a shocker: companies of all sizes also tend to do a better job protecting themselves from external-based threats, but leave their internal network connections less secured. The report shows that the majority of high-risk vulnerabilities were associated with application and internal attack vectors. In other words, most companies are still caught up in the perimeter-centric mode of protection. 

Why Cybercriminals Attack: A DARK READING VIRTUAL EVENT Wednesday, June 27. Industry experts will offer a range of information and insight on who the bad guys are – and why they might be targeting your enterprise. Go here for more information on this free event.

Consequently, humans tend to be the weakest link when it comes to keeping attackers from reaching organizations' most sensitive assets. Organizations suffer the most significant risk from threats when employees allow attackers to gain an insider position through phishing or other social engineering means. The weaknesses in internal network protections then give those attackers free rein to move at will in pursuit of high value IT assets. 

"Overall, our results conclude that humans — employees, vendors, and customers — still represent the greatest vulnerability as they are prone to social engineering techniques, shortcuts, or inadvertent oversights in the IT/security management process," Weber says.

Interestingly, though midsized organizations perform best when it comes to security operations, they actually did most poorly when it came to social engineering and phishing. This likely comes down to smaller organizations operating in more intimate environments, according to the report, whereas larger organizations tend to operate in more bureaucratic environments that require and audit security awareness training and strictly administer rules and processes that prevent social engineering. 

Related Content:

 

 

 

 

Ericka Chickowski specializes in coverage of information technology and business innovation. She has focused on information security for the better part of a decade and regularly writes about the security industry as a contributor to Dark Reading.  View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Where Businesses Waste Endpoint Security Budgets
Kelly Sheridan, Staff Editor, Dark Reading,  7/15/2019
How Attackers Infiltrate the Supply Chain & What to Do About It
Shay Nahari, Head of Red-Team Services at CyberArk,  7/16/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Building and Managing an IT Security Operations Program
As cyber threats grow, many organizations are building security operations centers (SOCs) to improve their defenses. In this Tech Digest you will learn tips on how to get the most out of a SOC in your organization - and what to do if you can't afford to build one.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-7843
PUBLISHED: 2019-07-18
Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Insufficient input validation vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user.
CVE-2019-7846
PUBLISHED: 2019-07-18
Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Improper error handling vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user.
CVE-2019-7847
PUBLISHED: 2019-07-18
Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Improper Restriction of XML External Entity Reference ('XXE') vulnerability. Successful exploitation could lead to Arbitrary read access to the file system in the context of the current user.
CVE-2019-7848
PUBLISHED: 2019-07-18
Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Inadequate access control vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user.
CVE-2019-7850
PUBLISHED: 2019-07-18
Adobe Campaign Classic version 18.10.5-8984 and earlier versions have a Command injection vulnerability. Successful exploitation could lead to Arbitrary Code Execution in the context of the current user.