• Tech News
    • Games
    • Pc & Laptop
    • Mobile Tech
    • Ar & Vr
    • Security
  • Startup
    • Fintech
  • Reviews
  • How To
What's Hot

Elementor #32036

January 24, 2025

The Redmi Note 13 is a bigger downgrade compared to the 5G model than you might think

April 18, 2024

Xiaomi Redmi Watch 4 is a budget smartwatch with a premium look and feel

April 16, 2024
Facebook Twitter Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook Twitter Instagram Pinterest VKontakte
Behind The ScreenBehind The Screen
  • Tech News
    1. Games
    2. Pc & Laptop
    3. Mobile Tech
    4. Ar & Vr
    5. Security
    6. View All

    Bring Elden Ring to the table with the upcoming board game adaptation

    September 19, 2022

    ONI: Road to be the Mightiest Oni reveals its opening movie

    September 19, 2022

    GTA 6 images and footage allegedly leak

    September 19, 2022

    Wild west adventure Card Cowboy turns cards into weird and silly stories

    September 18, 2022

    7 Reasons Why You Should Study PHP Programming Language

    October 19, 2022

    Logitech MX Master 3S and MX Keys Combo for Business Gen 2 Review

    October 9, 2022

    Lenovo ThinkPad X1 Carbon Gen10 Review

    September 18, 2022

    Lenovo IdeaPad 5i Chromebook, 16-inch+120Hz

    September 3, 2022

    It’s 2023 and Spotify Still Can’t Say When AirPlay 2 Support Will Arrive

    April 4, 2023

    YouTube adds very convenient iPhone homescreen widgets

    October 15, 2022

    Google finishes iOS 16 Lock Screen widgets rollout w/ Maps

    October 14, 2022

    Is Apple actually turning iMessage into AIM or is this sketchy redesign rumor for laughs?

    October 14, 2022

    MeetKai launches AI-powered metaverse, starting with a billboard in Times Square

    August 10, 2022

    The DeanBeat: RP1 simulates putting 4,000 people together in a single metaverse plaza

    August 10, 2022

    Improving the customer experience with virtual and augmented reality

    August 10, 2022

    Why the metaverse won’t fall to Clubhouse’s fate

    August 10, 2022

    How Apple privacy changes have forced social media marketing to evolve

    October 16, 2022

    Microsoft Patch Tuesday October Fixed 85 Vulnerabilities – Latest Hacking News

    October 16, 2022

    Decentralization and KYC compliance: Critical concepts in sovereign policy

    October 15, 2022

    What Thoma Bravo’s latest acquisition reveals about identity management

    October 14, 2022

    What is a Service Robot? The vision of an intelligent service application is possible.

    November 7, 2022

    Tom Brady just chucked another Microsoft Surface tablet

    September 18, 2022

    The best AIO coolers for your PC in 2022

    September 18, 2022

    YC’s Michael Seibel clarifies some misconceptions about the accelerator • DailyTech

    September 18, 2022
  • Startup
    • Fintech
  • Reviews
  • How To
Behind The ScreenBehind The Screen
Home»Security»Vulnerability management: Most orgs have a backlog of 100K vulnerabilities
Security

Vulnerability management: Most orgs have a backlog of 100K vulnerabilities

September 14, 2022No Comments4 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Ransomware attacks drop 34% in Q2, but experts warn of potential 'uptick'
Share
Facebook Twitter LinkedIn Pinterest Email

Were you unable to attend Transform 2022? Check out all of the summit sessions in our on-demand library now! Watch here.


The threat landscape never stands still. Almost every day there’s a new vulnerability emerging in some form or another. In fact, according to NIST, there were 18,378 vulnerabilities reported in 2021, and most organizations’ vulnerability management programs aren’t fit for purpose.

Each of these vulnerabilities presents a potential entry point for attackers to exploit and gain access to sensitive information. However, many organizations lack the internal expertise or resources to patch these vulnerabilities at the pace required to keep their environments secure. 

New research released by Rezilion and Ponemon Institute today found that 66% of security leaders report a vulnerability backlog of over 100,000 vulnerabilities. It also revealed that 54% say they were able to patch less than 50% of vulnerabilities in the backlog. 

Above all, the data indicates that the way most enterprises approach vulnerability management isn’t scalable or fit for purpose, and it’s providing cybercriminals with ample avenues to gain access to mission-critical data. 

Event

MetaBeat 2022

MetaBeat will bring together thought leaders to give guidance on how metaverse technology will transform the way all industries communicate and do business on October 4 in San Francisco, CA.

Register Here

Why vulnerability management is proving difficult 

The struggles of vulnerability management aren’t necessarily new. According to NTT Application Security, the average time to fix a vulnerability in 2021 was 202 days. Rezilion’s research also highlights that remediation is a problem, with 78% saying that high-risk vulnerabilities take longer than 3 weeks to patch. 

See also  Why the way forward for APIs should embody zero belief

At the heart of this failure to mitigate vulnerabilities effectively, is the lack of necessary tools. 

“What it comes down to is a lack of tools, people and information to properly handle this challenge. Respondents to the survey say there are a number of reasons why this is taking so long, including the long amount of time it takes and the complexity of the task,” said CEO and cofounder of Rezilion, Liran Tancman. 

“Some of the factors they mentioned include an inability to prioritize what needs to be fixed, and a lack of effective tools and a lack of resources. The lack of resources is not surprising as the talent crunch in security is well documented,” Tancman said. 

Tancman also highlights that few organizations have the visibility or context necessary to determine what needs patching, which makes tackling a backlog overwhelming. 

Nowhere is this lack of visibility more clearly demonstrated than with many organizations’ failure to patch Log4j, with a report released earlier this year finding that 70% of firms who previously addressed the vulnerability in their attack surface are still struggling to patch Log4j-vulnerable assets and prevent new instances resurfacing.

Automation is the answer 

Fortunately, automation provides an effective answer to the challenge of vulnerability management by enabling security teams to automate the vulnerability scanning process and continuously identify exploits.  

This not only decreases the time taken to remediate vulnerabilities, but frees up the security team to focus on more-rewarding tasks. Rezilion’s research suggests that automation can be a significant force multiplier for security teams, with 43% saying there was a significantly shorter time to respond.

See also  Unreleased 64-core Threadripper 5990X overclocked to 4.82 GHz, reaches over 100k points in Cinebench R23

It’s worth noting that, for the best results, organizations should look to implement solutions that offer risk-based prioritization if they want to maximize the effectiveness of their vulnerability management program. 

“One of the biggest changes you can make is to focus on the vulnerabilities that are being exploited in the wild. That should be the No.1 goal and will drive down the most risk the fastest,” said Craig Lawson, VP Analyst at Gartner, in a blog post. 

Providers like Tenable, Balbix and Seemplicity are all experimenting with risk-based vulnerability management to help security teams focus on patching high-risk vulnerabilities first, based on current exploitation activity and exposure, so they don’t waste time on lower-value vulnerabilities. 

Source link

100K backlog management orgs vulnerabilities Vulnerability
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Online Reputation Management Is Key To Thriving Post-Google Updates

July 6, 2023

How a 32-Year-Old Couple Makes $100K Per Month In Semi-Passive Income

June 2, 2023

Tempo acquires LiquidPlanner, a project management startup founded in 2006 – Startup

March 16, 2023

Contract lifecycle management startup SirionLabs raises $25M – Startup

January 16, 2023
Add A Comment

Comments are closed.

Editors Picks

A number of Zero-Day Bugs Noticed In Automobile GPS Tracker

July 25, 2022

Abortion Tablet Demand Is Driving an Underground Community

July 18, 2022

There is TSMC and there’s everybody else, can Samsung or Intel catch up?

August 28, 2022

KitchenAid Artisan Espresso Machine review

August 4, 2022

Subscribe to Updates

Get the latest news and Updates from Behind The Scene about Tech, Startup and more.

Top Post

Elementor #32036

The Redmi Note 13 is a bigger downgrade compared to the 5G model than you might think

Xiaomi Redmi Watch 4 is a budget smartwatch with a premium look and feel

Behind The Screen
Facebook Twitter Instagram Pinterest Vimeo YouTube
  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2025 behindthescreen.uk - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.