Failure to patch is leaving companies open to attack

Image credit: Pixabay (Image credit: Image Credit: Geralt / Pixabay)

One in four organizations have been breached because of unpatched vulnerabilities according to a new report from Tripwire on vulnerability management trends.

The firm surveyed 340 infosecurity professionals to reveal that 24 percent  of global organizations have been breached as a result of unpatched vulnerabilities with an even higher rate in Europe of 34 percent.

Vulnerability management begins with visibility of the attack surface and Tripwire's report found that 59 percent of global organizations are able to detect when new hardware and software are on their networks within minutes or hours.

However, this manual effort has proved difficult for many organizations and almost half (47%) report that less than half of their assets are discovered automatically including 13 percent who don't even use automatic discovery solutions.

Unpatched vulnerabilities

In order to assess the attack surface for vulnerabilities, 88 percent of those surveyed said they run vulnerability scans but Tripwire's research found that organizations address vulnerabilities with varying degrees of effectiveness.

The use of authenticated scans has improved compared with a past report and 63 percent now say they conduct authenticated scans as part of their vulnerability assessment. However, more than one third (39%) are still not scanning for the weekly as recommended by industry standards.

According to Tripwire's report, 16 percent of US organizations say they conduct vulnerability scans to meet compliance or other requirements though this rate was higher for European organizations at 21 percent.

Vice president of product management and strategy at Tripwire, Tim Erlin explained why organizations should be scanning for vulnerabilities more often, saying:

“How you assess your environment for vulnerabilities is important if you want to effectively reduce your risk. If you are not doing authenticated vulnerability scans, or not using an agent, then you are only giving yourself a partial picture of the vulnerability risk in your environment. And if you’re not scanning for vulnerabilities frequently enough, you’re missing new vulnerabilities that have been discovered, and you may miss assets that tend to go on and off the network, like traveling laptops.” 

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Security
A close-up of a phone screen showing the Telegram, Signal and WhatsApp apps
Agentic AI has “profound” issues with security and privacy, Signal President says
Bluetooth
Top Bluetooth chip security flaw could put a billion devices at risk worldwide
How to prevent cyberattacks
NTT admits hackers accessed details of almost 18,000 corporate customers in cyberattack
Woman shocked by online scam, holding her credit card outside
Cybercriminals used vendor backdoor to steal almost $600,000 of Taylor Swift tickets
Woman using iMessage on iPhone
UK government guidelines remove encryption advice following Apple backdoor spat
Cryptocurrencies
Ransomware’s favorite Russian crypto exchange seized by law enforcement
Latest in News
Q Acoustics Q SUB80, QSUB100 and QSUB120 subwoofers
Q Acoustics wants to bring the bass to your post-Oscars movie catch-up
Hospital
Major Oracle outage hits US Federal health record systems
Samsung Galaxy A56 display
Samsung’s new budget handsets are getting One UI 7 before the Galaxy S24 Ultra, and I’m as confused as you are
iPad Pro 13-inch 2024 on a table
The OLED iPad Pro is reportedly less popular than expected – and that could mean these changes to Apple's OLED iPad plans
Sam Porter cradles a baby
Death Stranding 2: On the Beach trailer confirms June release date and an even more harrowing post-apocalyptic world
The Ray-Ban Meta Coperni smart glasses
The new Ray-Ban Meta smart glasses design is an expensive disappointment