CIO News Hubb
Advertisement
  • Home
  • News
  • Operations CIO
  • Visionary CIO
  • IT Management
  • Information Security
  • Contact
No Result
View All Result
  • Home
  • News
  • Operations CIO
  • Visionary CIO
  • IT Management
  • Information Security
  • Contact
No Result
View All Result
CIO News Hubb
No Result
View All Result
Home Visionary CIO

Four moves to ‘checkmate’ critical assets thanks to lax cloud security

admin by admin
April 5, 2022
in Visionary CIO
585
SHARES
3.2k
VIEWS
Share on FacebookShare on Twitter


Malicious actors moving laterally through their victim’s network can access and compromise 94% of critical assets within four steps of their initial breach point by chaining vulnerabilities, misconfigurations, privileged credentials and simple human error.

Hybrid cloud architectures are particularly vulnerable to such attacks, as malicious actors are able to exploit security gaps, most commonly misconfigurations or lax access controls, to establish a foothold in the network and then move in-between on-premise and cloud applications as needed.

This is according to a report produced by hybrid cloud security specialist XM Cyber. In the study, Impact report: 2021 year in review, the Israel-based organisation rounded up data gleaned from two million endpoints, files, folders and cloud resources during 2021.

The firm’s analysts wanted to study methods, attack paths and impacts of attack techniques that are used against critical assets across on-premise, multi-cloud, and hybrid computing environments.

“Modern organisations are investing in more and more platforms, apps and other tech tools to accelerate their business, but they too often fail to realise that the interconnection between all these technologies poses a significant risk,” said Zur Ulianitzky, XM Cyber research head.

The resulting report sets out the security gaps and hygiene issues that exist across these environments. XM Cyber said it also demonstrated the importance of risk visibility across the entire network, and across teams, as Ulianitzky explained: “When siloed teams are responsible for different components of security within the network, nobody sees the full picture. One team may ignore a seemingly small risk, not realising that in the big picture, it’s a stepping stone in a hidden attack path to a critical asset.”

In addition to the headline statistic, XM Cyber’s report also found that three quarters of an organisation’s critical assets could have been compromised in their then-current security state, and that 78% of organisations are open to compromise every time a new remote code execution vulnerability is disclosed.

But it was abused credentials, rather than high-profile zero-days, that the report said were the biggest risk, with 73% of the most widely used attack techniques involving mismanaged or stolen credentials as an initial compromise.

The bottom line, said the report, is that understanding attack paths and vectors, visualising and modelling them, and learning about how malicious actors use them to pivot through a hybrid environment, and remediating these issues, should be a priority for security teams.

XM Cyber claimed that if defenders know where and when to disrupt attack paths, they can potentially reduce 80% of issues that would otherwise occupy their security resource.



Source link

Previous Post

Top 9 blockchain platforms to consider in 2022

Next Post

An Overview of Availability Management in ITIL

Related Posts

Visionary CIO

Building a pathway to commercial quantum computing

by admin
May 25, 2022
Visionary CIO

KAC: Creating smarter airports that safeguard passenger journeys

by admin
May 25, 2022
Visionary CIO

MIT Sloan panelists urge cyber resilience focus

by admin
May 24, 2022
Visionary CIO

ICO orders facial recognition firm Clearview AI to delete all data about UK residents

by admin
May 24, 2022
Visionary CIO

Ransomware volumes grew faster than ever in 2021

by admin
May 24, 2022
Next Post

An Overview of Availability Management in ITIL

Leave Comment

Recommended

Building a pathway to commercial quantum computing

May 25, 2022

KAC: Creating smarter airports that safeguard passenger journeys

May 25, 2022

Intro to ITOM & How it Impacts Cost Optimization

May 25, 2022

The Best of SWL 2022 (SupportWorld Live)

May 25, 2022

Conti Ransomware Operation Shut Down After Splitting into Smaller Groups

May 25, 2022

Fronton IOT Botnet Packs Disinformation Punch

May 24, 2022

© 2022 CIO News Hubb All rights reserved.

Use of these names, logos, and brands does not imply endorsement unless specified. By using this site, you agree to the Privacy Policy.

Navigate Site

  • Home
  • News
  • Operations CIO
  • Visionary CIO
  • IT Management
  • Information Security
  • Contact

Newsletter Sign Up

No Result
View All Result
  • Home
  • News
  • Operations CIO
  • Visionary CIO
  • IT Management
  • Information Security
  • Contact

© 2022 JNews - Premium WordPress news & magazine theme by Jegtheme.