Many organizations prioritize external cyber threats and use various tools and technologies to protect against such issues. However, these organizations may also be more likely than others to overlook internal cyber threats that lead to security vulnerabilities and data breaches, according to the fourth annual Securealities Penetration Risk Report from cybersecurity and cloud services provider (CSP) Coalfire.
Security Misconfiguration is an Ongoing Vulnerability
High-risk internal attack vectors are more than three times higher than external ones and nearly four times higher than app-related vectors, Coalfire's report shows. In addition, large cloud services providers hold 55% of high risks, small CSPs account for 37% and midsize CSPs account for 8%.
More than 3,100 penetration tests and four research reports indicate that the top vulnerabilities fluctuate over time, but security misconfiguration is "always at the top," Coalfire's report indicated.
This is likely due to the fact that many organizations:
Technology Sector Leads Penetration Testing
Other notable findings from Coalfire's report include:
Organizations can use multilayered cybersecurity strategies to detect, limit and prevent cyberattacks and data breaches, Coalfire stated. These strategies can include automated security testing throughout the web and application lifecycle and regular pentests. That way, organizations can establish risk management priorities, mitigate security weaknesses and keep pace with current and emerging cyber threats.