Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity

    Software Patches Could Prevent Most Breaches, Study Finds

    Written by

    Rob Lemos
    Published March 14, 2017
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Approximately 80 percent of companies that had either a breach or a failed audit could have prevented the issue with a software patch or a configuration change, according to a security-automation survey of 318 firms.

      The survey, conducted by research firm Voke Media in late 2016, found that 27 percent of companies reported a failed audit in the prior 18 months, of which 81 percent could have been prevented with a patch or configuration change. Similarly, 26 percent reported a breach, of which 79 percent could have been prevented with those two measures.

      Nearly half—46 percent—of companies took longer than 10 days to remediate vulnerabilities and apply patches. Those patch or configuration-change backlogs are a critical issue for businesses, said Theresa Lanowitz, the founder and CEO of Voke.

      “These companies could prevent these breaches from happening, especially due to vulnerabilities that have patches that have been sitting in the backlog,” she said. “There has to be an effective management of the patch backlog—if there is, you can improve your audit readiness, you can reduce that window of risk, and you can reduce those vulnerabilities.”

      The problem underscores the workload issues posed by operational security, Lanowitz said. Companies are increasingly looking to automation and machine learning to help reduce the workload of keeping their business secure.

      A significant problem is that most companies have conflicting priorities between the two groups responsible for securing their information technology and data. The IT operations team is usually focused on enabling business users to be productive and only considers security when there is an incident. Meanwhile, the IT security team focuses on finding vulnerabilities and signs of breaches, but does not give much thought to how those issues impact operations, Lanowitz said.

      “You have two disparate teams—the IT ops team and the IT security team—and they have conflicting priorities, but they are both responsible for protecting the IT infrastructure,” she said. “If you had these two teams working together, using some of the newer tools in the market and focused on security-operations automation, you can have much better outcomes.”

      The survey found that many, but not the majority, of companies used a variety of automation to secure their products and infrastructure. Nearly half of all companies had used security architects to ensure that security was designed into their IT infrastructure. Forty-two percent used a production-equivalent environment to test and verify patches. And, more than a third of companies took four other measures: designing products with security in mind, automating patch deployment, focusing on security requirements for applications, and using source-code analysis tools to scan products.

      Focusing more on automation is critical to keep ahead of the risks facing companies, Lanowitz said.

      “Invest in the tools and training needed to operationalize security,” she said. “Getting the teams to work together in operationalizing security and having an executive mandate is critical.”

      Rob Lemos
      Rob Lemos

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×