Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

5/22/2018
03:00 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

Las Vegas Most Insecure Cyber City in US; St. Louis Least Vulnerable

Forty-three percent chance of users connecting to high or medium-risk networks in Las Vegas - compared to less than 1% risk in least vulnerable areas, Coronet says.

Turns out that what happens in Las Vegas actually happens in at least a couple of other places as well - from a cybersecurity standpoint.

Residents of the Las Vegas, Memphis, and Charlotte metro areas are at substantially higher risk of data theft and other cybersecurity incidents compared to residents in more than four-dozen other areas in the US.

Cloud security vendor Coronet recently analyzed network connectivity and device related data in the 55 most populated areas in the country and found Wi-Fi and cellular networks — and the devices connecting to them — to be the most insecure in these three areas, the new study shows.

The risk level of a user, expressed in the form of a threat index score, was 10 on a scale of 10 in Las Vegas and 9.8 in both Memphis and Charlotte. People logging into websites or accessing cloud data in these designated market areas (DMAs) were most at risk of experiencing security incidents than anywhere else in the country.

"While in Las Vegas there was a 43% probability of users connecting to medium-risk or high-risk networks, in the least vulnerable cities the average probability was less than one percent," says Dror Liwer, Coronet's founder and CISO. "While in Memphis 7% of devices had no malware protection, the national average was 0.2%," he says.

Other risky cities and areas included Houston (9.2), Providence, RI (9.0), Birmingham, AL (9.0), and Jacksonville, FL (8.9). Rounding off the list of the Top 10 most insecure locations were three market areas in Florida — West Palm Beach-Ft. Pierce (8.9), Orlando-Daytona Beach (8.5), and Tampa–St. Petersburg–Sarasota (8.3).

For purposes of the ranking, Coronet considered any region with a threat index of 6.5 or less to be at an acceptable level of risk. By that metric, the least vulnerable metro in America from a cybersecurity standpoint in Coronet's list was the Richmond-Petersburg area in Virginia with a threat index of just 5.8.

Others in the Top 5 least vulnerable market areas were Greensboro-Winston Salem (6.2); Norfolk-Portsmouth-Newport News (6.2); Seattle-Tacoma (6.3) and St. Louis (6.3).

To arrive at the rankings, Coronet analyzed data collected from more than one million PCs, mobile devices, and tablets running its SecureCloud endpoint software. The collected data included device posture information as well as threat, attack, and vulnerability data gathered from the cellular and Wi-Fi networks to which the devices connected.

Scoring Cities

Coronet scored connectivity infrastructure based on factors like vulnerabilities and misconfigurations that were present on them as well on metrics like wrong routing and spoofing. Among the issues the company looked at were risks posed by captive portals, rogue access points, and honeypots. Devices were scored based on things like the presence or absence of active and updated anti-malware tools, active and updated firewalls, password protection, disk and storage encryption, and operating system integrity.

The company then combined and standardized the infrastructure vulnerability score with the device vulnerability score in each region to arrive at the overall Threat Index Score using a risk score range of 1 to 10,  where 10 represented the highest risk and 1 the lowest.

So why are some regions more risky than others from a security standpoint? It has a lot to do with the presence of more threat actors and activity in certain regions than others, Liwer says. "The main issue is not so much the carriers or network providers that are mostly standardized, but rather, the presence of malicious actors," Liwer says. "While the coffee chain network is configured the same way in [most] of its locations, the fact that three of its locations in Las Vegas are under attack has impact on the probability that users will connect to a malicious node." 

Coronet identified several factors as contributing to heightened threat activity in certain regions of the country. For instance, locations in which there are a lot of defense, financial services companies, manufacturing activity and aerospace firms — like the Tampa-St. Petersburg area and Jacksonville – generally tend to see heightened levels of threat activity.

Fast-growing metro regions and tourist destinations like the Orlando-Daytona DMA tend to be risky as well. For instance, more than 60 million people visited the Central Florida region in a 12-month period flooding the area with unsafe devices from around the world and making them a target for attackers, Coronet said.

Regions with aged or aging populations tend to attract a higher than average amount of threat activity as well. The West Palm Beach-Fort Pierce area with its large population of mostly older, wealthy and likely digitally unsophisticated residents makes for an attractive target for criminals as well.

Mixed Signals

The factors that make a region safer than others are less clear. For instance, the Seattle-Tacoma area, which ranked as the fourth safest in the Coronet report, is one of the most high tech regions in the country. But threat activity here is relatively low compared to areas with a similar high-tech profile. One reason could be because the state of Washington operates one of the most efficient cybersecurity agencies in the country. Similarly, the reason why St. Louis ranked as the fifth least vulnerable region in the country could have to do with presence of Missouri Cybersecurity Center.

Related Content:

 

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
10 Ways to Keep a Rogue RasPi From Wrecking Your Network
Curtis Franklin Jr., Senior Editor at Dark Reading,  7/10/2019
The Security of Cloud Applications
Hillel Solow, CTO and Co-founder, Protego,  7/11/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Planned vacation simulation
Current Issue
Building and Managing an IT Security Operations Program
As cyber threats grow, many organizations are building security operations centers (SOCs) to improve their defenses. In this Tech Digest you will learn tips on how to get the most out of a SOC in your organization - and what to do if you can't afford to build one.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-10100
PUBLISHED: 2019-07-15
couchcms 2 is affected by: Web Site physical path leakage. The impact is: disclosure the full path. The component is: includes/mysql2i/mysql2i.func.php and addons/phpmailer/phpmailer.php. The attack vector is: network connectivity.
CVE-2019-10100
PUBLISHED: 2019-07-15
borg-reducer c6d5240 is affected by: Buffer Overflow. The impact is: Possible code execution and denial of service. The component is: Output parameter within the executable.
CVE-2019-10103
PUBLISHED: 2019-07-15
Saleor Issue was introduced by merge commit: e1b01bad0703afd08d297ed3f1f472248312cc9c. This commit was released as part of 2.0.0 release is affected by: Incorrect Access Control. The impact is: Important. The component is: ProductVariant type in GraphQL API. The attack vector is: Unauthenticated use...
CVE-2019-10103
PUBLISHED: 2019-07-15
libmspack 0.9.1alpha is affected by: Buffer Overflow. The impact is: Information Disclosure. The component is: function chmd_read_headers() in libmspack(file libmspack/mspack/chmd.c). The attack vector is: the victim must open a specially crafted chm file. The fixed version is: after commit 2f084136...
CVE-2019-10103
PUBLISHED: 2019-07-15
Slanger 0.6.0 is affected by: Remote Code Execution (RCE). The impact is: A remote attacker can execute arbitrary commands by sending a crafted request to the server. The component is: Message handler & request validator. The attack vector is: Remote unauthenticated. The fixed version is: after ...