Trending...
- Kevin Francis Design Introduces CHROMA, a Collection of Saturated Solid Color Wool Rugs
- Spokane City Council Passes Aggressive Speeding Ordinance
- City of Tacoma Presents Updated Financial Forecast as Next Step in 'Roadmap to Recovery' to Navigate National Economic Pressures
KIRKLAND, Wash. and TEL AVIV, Israel, Sept. 14, 2021 /PRNewswire/ -- Cyberpion, a cybersecurity pioneer in external attack surface management (EASM), today presented research showing that nearly three quarters of Fortune 500 companies' IT infrastructure exists outside their organization, a quarter of which was found to have a known vulnerability that threat actors could infiltrate to access sensitive employee or customer data.
Key research findings:
Cyberpion collected these results by performing a cursory single-pass scan of the public and internet-facing assets of every Fortune 500 company in the first half of 2021.
More on Washingtoner
According to Gartner1, "EASM is an emerging concept that is growing quickly in terms of awareness within the security vendor community but at a slower pace within end-user organizations...They help security professionals identify exposed vulnerabilities from known and unknown enterprise assets and prioritize the most critical issues to be tackled...EASM should be part of a broader vulnerability and threat management effort aimed at discovering and managing internal- and external-facing assets and their potential vulnerabilities."
Traditional third-party risk management solutions have focused exclusively on the vendors and the IT infrastructures that are directly connected to the enterprise. This approach ignores the true scale of the problem and represents only the tip of the iceberg. Third-party vendors have also adopted a distributed IT infrastructure, and have built their applications and services using their own vendors and third-parties. Those in turn build their solutions upon even more partners. This extensive ecosystem creates an external attack surface that is uniquely appealing to hackers to attack, and extremely complicated for enterprises to manage securely.
Hackers are finding it easier to takeover or exploit the vulnerabilities in the third-party assets within the enterprise's ecosystem in order to carry out attacks such as: malicious code injection (Magecart-style attacks), DNS hijacks, or abusing the branded assets of an enterprise. These breaches ultimately lead to data loss, brand reputation damage, and stolen customer data for the enterprise.
"Security teams often can't effectively defend against attacks stemming from third-parties because they lack visibility into the total inventory and volume of assets they are connected to," said Cyberpion CEO Nethanel Gelertner. "They are unaware of the exposure to these external vulnerabilities, and can't identify and mitigate against these risks. In addition, the growth of these interconnected assets continues to explode due to trends in cloud-first architectures and digital transformation initiatives, meaning that assessing and protecting the attack surface has become even more challenging over time."
More on Washingtoner
About Cyberpion
Cyberpion solves the rising cybersecurity challenge of understanding the risks and vulnerabilities of your connected online assets that form an external attack surface. Knowing how your organization is vulnerable, where those threats come from, and what infrastructures are at risk, is critical to preventing an attack before it happens. Cyberpion helps organizations mitigate these advanced threats by continuously monitoring, discovering, and assessing the threat vectors present throughout online ecosystems that exist outside the traditional security perimeter. With an R&D team based in Israel, the company is funded by leading cybersecurity venture capitalists. To learn more, visit cyberpion.com.
For more information, please contact:
Josh Turner
Si14 Global Communications
josh.[email protected]
1 Gartner, "Emerging Technologies: Critical Insights for External Attack Surface Management" by Ruggero Contu, Elizabeth Kim and Mark Wah, March 19, 2021
SOURCE Cyberpion
Key research findings:
- 73% of Fortune 500 companies' total IT infrastructure is external to the organization, of which 24% is considered at risk or has a known vulnerability
- The total IT infrastructure includes the IT assets that are owned and operated by vendors the Fortune 500 enterprises incorporated into their online footprint
- These IT assets include servers, cloud storage, CDNs, DNS (Domain Name Servers), email servers and other online elements
- 71% of total cloud-based IT assets are external to the organization, of which 25% failed at least one security test
- An example of cloud vulnerability includes cloud storage configured to allow anyone to read or write its contents
- On average, a Fortune 500 company's infrastructure contains 126 different login pages for either customer or employee portals or services - the highest number was over 3,000
- Nearly 10% of these login pages are considered insecure due to the transmission of unencrypted login data, or issues with SSL certificates, which helps ensure that the submission is being sent to the authorized destination
- 30% allow transmission over HTTP
- 12% have invalid certificates/encryption
- Hackers exploiting these logins could access a wealth of sensitive employee or customer data
- Fortune 500 organizations connect to an average of 951 cloud assets, of which nearly 5% are vulnerable to severe abuse
- For example, a misconfigured AWS bucket could allow hackers to read or overwrite the data which could be customer PII or application code
- The largest exposure was well over 30K cloud assets
Cyberpion collected these results by performing a cursory single-pass scan of the public and internet-facing assets of every Fortune 500 company in the first half of 2021.
More on Washingtoner
- purelyIV Expands Mobile IV Therapy to Jackson, MI and Launches PlaqueX® IV Therapy
- Leimert Juneteenth Community Celebration Set for Friday, June 19, in Leimert Park Village
- UK Financial Ltd Publishes Maya Preferred Public Proof Package and CoinMarketCap Supply Verification Evidence
- Haven Treatment Center Launches Community Haircut Drive to Help Local Families
- Advancing High-Potential Nevada Critical Minerals Portfolio as Major Drill Program Nears Assay Results: Glenstar Minerals: Stock Symbol: GSTRF
According to Gartner1, "EASM is an emerging concept that is growing quickly in terms of awareness within the security vendor community but at a slower pace within end-user organizations...They help security professionals identify exposed vulnerabilities from known and unknown enterprise assets and prioritize the most critical issues to be tackled...EASM should be part of a broader vulnerability and threat management effort aimed at discovering and managing internal- and external-facing assets and their potential vulnerabilities."
Traditional third-party risk management solutions have focused exclusively on the vendors and the IT infrastructures that are directly connected to the enterprise. This approach ignores the true scale of the problem and represents only the tip of the iceberg. Third-party vendors have also adopted a distributed IT infrastructure, and have built their applications and services using their own vendors and third-parties. Those in turn build their solutions upon even more partners. This extensive ecosystem creates an external attack surface that is uniquely appealing to hackers to attack, and extremely complicated for enterprises to manage securely.
Hackers are finding it easier to takeover or exploit the vulnerabilities in the third-party assets within the enterprise's ecosystem in order to carry out attacks such as: malicious code injection (Magecart-style attacks), DNS hijacks, or abusing the branded assets of an enterprise. These breaches ultimately lead to data loss, brand reputation damage, and stolen customer data for the enterprise.
"Security teams often can't effectively defend against attacks stemming from third-parties because they lack visibility into the total inventory and volume of assets they are connected to," said Cyberpion CEO Nethanel Gelertner. "They are unaware of the exposure to these external vulnerabilities, and can't identify and mitigate against these risks. In addition, the growth of these interconnected assets continues to explode due to trends in cloud-first architectures and digital transformation initiatives, meaning that assessing and protecting the attack surface has become even more challenging over time."
More on Washingtoner
- Allstream Energy Partners to Host 6th Executive Networking After 2026 Energy Projects Conference
- CAPHRA: Australia and Thailand show nicotine prohibition fuels illicit markets
- Custom Disposables - Wholesale Packaging Solutions for restaurants, food chains, and food distributors
- California Security Glass is an affordable bulletproof glass installation company in LA serving a variety of neighboring cities
- Allstream Energy Partners Announce Media Partnership with the 2026 EPC Show - The Energy Projects Conference
About Cyberpion
Cyberpion solves the rising cybersecurity challenge of understanding the risks and vulnerabilities of your connected online assets that form an external attack surface. Knowing how your organization is vulnerable, where those threats come from, and what infrastructures are at risk, is critical to preventing an attack before it happens. Cyberpion helps organizations mitigate these advanced threats by continuously monitoring, discovering, and assessing the threat vectors present throughout online ecosystems that exist outside the traditional security perimeter. With an R&D team based in Israel, the company is funded by leading cybersecurity venture capitalists. To learn more, visit cyberpion.com.
For more information, please contact:
Josh Turner
Si14 Global Communications
josh.[email protected]
1 Gartner, "Emerging Technologies: Critical Insights for External Attack Surface Management" by Ruggero Contu, Elizabeth Kim and Mark Wah, March 19, 2021
SOURCE Cyberpion
0 Comments
Latest on Washingtoner
- Equipment Leases, Inc. Launches Updated Family Office Equipment Financing Page
- Spokane: Council Members Introduce An Ordinance Imposing Data Center Moratorium
- The $5 Million Man Still Begging: Incumbent Jimmy Panetta Hits Up Voters for More Cash Despite Massive War Chest
- Kevin Francis Design Introduces CHROMA, a Collection of Saturated Solid Color Wool Rugs
- $150+ Million Contracted Backlog, Strategic Acquisitions Adding Millions In Recurring Revenue, Improving Margins & A Clear Path Toward Profitability
- Record Revenue Growth, AI-Driven Healthcare Innovation, Expanding Proprietary Brand and Targeting $200 Million Revenue By 2029: Cosmos Health Inc
- Bergey's Truck Centers Recognized in 2026 MACH Alliance Composable Impact Awards
- Tacoma: City Council Adopts Updated Stormwater Management Manual to Enhance Environmental Health and Regulatory Compliance
- Spokane Police Sergeant Pulls Elderly Female from Burning Home
- What Would you Do with Your Time if it Was Actually Money?
- Mr. Hospital Bed Showcases the Best Hospital Bed and Air Mattress for Bed Sores for 2026
- City of Tacoma Presents Updated Financial Forecast as Next Step in 'Roadmap to Recovery' to Navigate National Economic Pressures
- Tacoma: Full Intersection Closure at E. 11th Street and St. Paul Avenue for One-Day Asphalt Repairs on June 27
- Spokane: Early-Morning House Fire Damages Two Homes on East Sanson Avenue
- Spokane City Council Passes Aggressive Speeding Ordinance
- Traian TKD Tractari Auto Iasi: cum transporti legal la RAR o masina fara numere sau cu ITP expirat
- Republican National Hispanic Assembly & Metropolitan Republican Club Announce Strategic Partnership
- Lake East Landscape Highlights Full-Service Landscaping Solutions Across Seattle and Nearby Areas
- Proactive Tax & Advisory and Accountability Services Merge and Rebrand as Proactive Advisory Group
- Mike Williams Golf Center Now Open at Georgia's Lanier Islands Resort