Organizations Take an Average of 60 Days to Patch Critical Risk Vulnerabilities
Edgescan's 2022 Vulnerability Statistics Report Reveals
NEW YORK, March 7, 2022 /PRNewswire/ -- Edgescan, the provider of smart vulnerability management, today announces the findings of its 2022 Vulnerability Statistics Report, which for the 7th year running offers a comprehensive view of the state of vulnerability management globally. This year's report takes a more granular look at the trends by industry, and provides details on which of the known, patchable vulnerabilities are currently being exploited by threat actors.
The report reveals that organizations are still taking nearly two months to remediate critical risk vulnerabilities, with the average mean time to remediate (MTTR) across the full stack set at 60 days.
High rates of "known" (i.e. patchable) vulnerabilities which have working exploits in the wild, used by known nation state and cybercriminal groups are not uncommon.
Remote access exposures across the attack surface are a worrying trend and accounted for 5% of total attack surface exposures in 2021.
Crucially, 57% of all observed vulnerabilities are more than two years old, with as many as 17% being more than five years old. These are all vulnerabilities that have working exploits in the wild, used by known nation state and cybercriminal groups. Edgescan also observed a concerning 1.5% of known, unpatched vulnerabilities that are over 20 years old, dating back to 1999.
While the size of an organization bears little weight on MTTR, Edgescan observed significant differences across industries. Healthcare organizations (NAICS 62) - despite the extreme pressure they endured in the past two years - came out on top, with an MTTR of just 44 days. At the opposite end of the spectrum, the public administration sector (NAICS 92) took an average of 92 days to remediate known vulnerabilities - a month longer than the cross-industry average.
"We are delighted to be able to share our intelligence with the wider security community for the 7th year running", said Eoin Keary, CEO and cofounder of Edgescan. "Patching and maintenance are still a challenge, and so is detection. Attack surface management and visibility is paramount, and with our report we aim inform enterprises of the most common exposures"
The findings in the report Edgescan 2022 Vulnerability Statistics Report are based on the data collected from tens of thousands of individual assets. The analyzed sample included over 40,000 web application and API assessments, 3 million Network Endpoint assessments, and circa 1000 penetration tests delivered in 2021 by the Edgescan team.
Edgescan is an award-winning full-stack Attack Surface Management & Web/API Vulnerability Management Security as a Service (SaaS) solution. Edgescan™ protects & manages thousands of assets across the globe for both Fortune 500 and SME clients helping them to continuously detect, prioritize, monitor, and fix security weaknesses for Internet-facing systems, such as Web Applications, API's, Network/Device systems and IoT services. Due to expert validation of all discovered vulnerabilities, the solution is highly accurate and virtually false positive free.
This press release was issued through 24-7PressRelease.com. For further information, visit http://www.24-7pressrelease.com
SOURCE Edgescan
WANT YOUR COMPANY'S NEWS FEATURED ON PRNEWSWIRE.COM?
Newsrooms &
Influencers
Digital Media
Outlets
Journalists
Opted In
Share this article