
Cisco Annual Security Report Reveals Widening Gulf Between Perception and Reality of Cybersecurity Readiness 60% of Cisco Security Capabilities Benchmark Survey Respondents Are Not Patching and Only 10% of Internet Explorer Users Run Latest Version; Still 90% of Respondents Are Confident in Their Cybersecurity Capabilities
John N. Stewart, Chief Security Officer at Cisco, highlights the findings of Ciscos 2015 Annual Security Report
SAN JOSE, CA, Jan. 20, 2015 - The Cisco 2015 Annual Security Report released today, which examines both threat intelligence and cybersecurity trends, reveals that organizations must adopt an all hands on deck approach to defend against cyber attacks. Attackers have become more proficient at taking advantage of gaps in security to evade detection and conceal malicious activity. Defenders, namely, security teams, must be constantly improving their approach to protect their organization from these increasingly sophisticated cyber attack campaigns. These issues are further complicated by the geopolitical motivations of the attackers and conflicting requirements imposed by local laws with respect to data sovereignty, data localization and encryption.
Attackers
Cyber criminals are expanding their tactics and adapting their techniques to carry out cyber attack campaigns in ways that make it harder to detect and analyze. The top three trends last year that Ciscos threat intelligence has identified are:
Snowshoe Spam: Emerging as a preferred strike method, attackers are sending low volumes of spam from a large set of IP addresses to avoid detection, creating an opportunity to leverage compromised accounts in multiple ways.
Web Exploits Hiding in Plain Sight: Widely used exploit kits are getting dismantled by security companies in short order. As a result, online criminals are using other less common kits to successfully carry out their tactics - a sustainable business model as it does not attract too much attention.
Malicious Combinations: Flash and JavaScript have historically been insecure on their own, but with advances in security detection and defenses, attackers have adapted by deploying exploits which combine their respective weaknesses. Sharing exploits over two different files - one Flash and one JavaScript - can make it more difficult for security devices to identify and block the exploit and to analyze it with reverse engineering tools.
Users
Users are caught in the middle. Not only are they the targets, but end-users are unknowingly aiding cyber attacks. Throughout 2014, Cisco threat intelligence research revealed that attackers have increasingly shifted their focus from seeking to compromise servers and operating systems to seeking to exploit users at the browser and email level. Users downloading from compromised sites contributed to a 228% increase in Silverlight attacks along with a 250% increase in spam and malvertising exploits.
Defenders
Results from the Cisco Security Capabilities Benchmark Study, which surveyed Chief Information Security Officers (CISOs) and Security Operations (SecOps) executives at 1700 companies in nine countries* reveals a widening gap in defender perceptions of their likely security capabilities. Specifically, the study indicates that 75% of CISOs see their security tools as very or extremely effective. However, less than 50% of respondents use standard tools such as patching and configuration to help prevent security breaches and ensure that they are running the latest versions. Heartbleed was the landmark vulnerability last year, yet 56% of all installed OpenSSL versions are over four years old. That is a strong indicator that security teams are not patching.
While many defenders believe their security processes are optimized-and their security tools are effective-in truth, their security readiness likely needs improvement.
The report findings conclude that its time for corporate boards to take a role in setting security priorities and expectations. The Cisco Security Manifesto, a formal set of security principles as a foundation to achieving security, can help corporate boards, security teams and users in an organization better understand and respond to the cybersecurity challenges of todays world. It can serve as a baseline for organizations as they strive to become more dynamic in their approach to security and more adaptive and innovative than adversaries. The principles are:
Security must support the business.
Security must work with existing architecture - and be usable.
Security must be transparent and informative.
Security must enable visibility and appropriate action.
Security must be viewed as a people problem.
For a complete copy of the Cisco Annual Security Research report go to www.cisco.com/go/asr2015
About the Report
The Cisco 2015 Annual Security Report is one of the preeminent security reports that examines the latest threat intelligence gathered by Cisco security experts, providing industry insights, trends and key findings revealing cybersecurity trends for 2015. The report also highlights data results from Ciscos Security Capabilities Benchmark Study which examines the security posture of enterprises and their perceptions of their preparedness to defend themselves against cyber attacks. Geopolitical trends, global developments around data localization and the importance of making cybersecurity a boardroom topic are also discussed.
Supporting Quote
John N. Stewart, senior vice president, chief security and trust officer, Cisco
Security needs an all hands on deck approach, where everybody contributes, from the board room to individual users. We used to worry about DoS, now we also worry about data destruction. We once worried about IP theft, now we worry about critical services failure. Our adversaries are increasingly proficient, exploit our weaknesses and hide their attacks in
Most recent headlines
13/03/2025
(L-R) Stephanie Suganami, Tatanka Means, John Malkovich, Ayo Edebiri, and Juliette Lewis attend the premiere of Opus at Eccles Theatre in Park City. (Photo by...
13/03/2025
Spotify took center stage at the London Book Fair this week, reaffirming our commitment to the audiobook market and showcasing our impact on the publishing indu...
13/03/2025
At Spotify, we work every day to lift up new voices, giving creators the opportunity to live off their art. Through Spotify Audiobooks, our in-house publishing ...
13/03/2025
Every time airborne law enforcement (ALE) teams fly, they expect their equipment to perform. Whether airborne units are conducting support for ground teams, bor...
13/03/2025
Sunday February 9 saw the annual return of the US' biggest television event, the Super Bowl LIX. Jamie McCombs, Fox Sports Audio Consultant / Sr. Audio capt...
13/03/2025
On Sunday March 2, stars across the film industry gathered at the Dolby Theatre in Los Angeles for the 97th Academy Awards. Production Sound Mixer Paul Sandweis...
13/03/2025
WUPPERTAL, Germany Riedel Communications will feature its new StageLink family of smart edge devices, Smart Audio and Mixing Engine (SAME) and Virtual Smart Pan...
13/03/2025
TAG Video Systems and Harmonic Partner to Deliver Enhanced Real-Time Monitoring ...
13/03/2025
DigitalGlue Invites NAB Visitors to Experience New Features in Managed Storage P...
13/03/2025
FOR-A America Theme - Connecting the Present, Building the Future - Comes to Lif...
13/03/2025
CTIA, the wireless industry association, has named former FCC Chairman Aji Pai as its President and Chief Executive Officer, effective April 1. He replaces Mere...
13/03/2025
he National Association of Broadcasters is urging the FCC to end its investigation of that controversial CBS interview with Kamala Harris stating there is no ...
13/03/2025
MIAMI CBS News & Stations continues to expand its use of augmented and virtual reality technologies with the planned launch of an augmented reality/virtual real...
13/03/2025
Srividhya Srinivasan, co-founder and chief customer success & innovation Officer at Amagi, tells TVBEurope how staying ahead of the latest trends is essential f...
13/03/2025
WASHINGTON FCC Chairman Brendan Carr announced that the agency has launched a massive, new deregulatory initiative that could potentially subject virtually all ...
13/03/2025
SUNNYVALE, Calif. SDVI has announced that it has integrated its Rally media supply chain management platform with the Spectra Vail multi-cloud data management s...
13/03/2025
ATLANTA Gray Media has announced that the Federal Communications Commission (FCC) has granted a waiver of its local ownership rules to permit Gray Media to acqu...
13/03/2025
TV Tech: What do you anticipate will be the most significant technology trends at the 2025 NAB Show?...
13/03/2025
Watch Student Naomi Soleils Folk Pop Performance on The Voice The songwriting major sang Stars by Grace Potter and the Nocturnals during the blind auditions.
...
13/03/2025
Roku Debuts NWSL Zone' Within Roku Sports to Spotlight Live Games, Content Feature marks Rokus first women's league-branded zone within service By Bra...
13/03/2025
Pixels, Images, Video, AI - and Us: A Perspective on AI from NDI Inventor Andrew...
13/03/2025
SVG New Sponsor Spotlight: Lighting Design Group's Steve Brill, Dennis Size ...
13/03/2025
IOC, Comcast NBCU Ink $3B Media-Rights Extension for Olympic Games Through 2036;...
13/03/2025
NCAA March Madness Live Returns with Expanded Availability of MultiView Vertical...
13/03/2025
SVG Sit-Down: Cosm's Devin Poolman on What It Takes To Deliver the Immersive...
13/03/2025
Sky Business, Sky's B2B division, providing connectivity and content to busi...
13/03/2025
Rohde & Schwarz launches R&S NRP140TWG(N) thermal power sensor: A new benchmark ...
13/03/2025
We asked the questions, analysed the answers and now we're excited to share the results of the fifth edition of the ICG Marketing Survey.
Our 2025 survey p...
13/03/2025
SAN JOSE, Calif. - March 13, 2025 Harmonic (NASDAQ: HLIT) today announced a breakthrough in video streaming innovation with the launch of new origin capabilitie...
13/03/2025
Haivision Showcases Mission-Critical Video Solutions at SOF Week 2025
Haivision's video wall systems, ISR technology, and DoDIN APL-certified video distri...
13/03/2025
Company Leads the Way with New Software-Based Production Platform, 12G Switcher,...
13/03/2025
A new Apple Immersive concert experience, Metallica, is coming to Apple Vision Pro this Friday, March 14. Filmed in Mexico City during the sold-out second-year ...
13/03/2025
Here is your host, Patrick Kielty!
Shake your Shamrocks, Patrick Kielty will be...
13/03/2025
This St. Patrick's weekend, RT invites you to celebrate all things Irish, showcasing the very best of Irish sport, entertainment and live coverage from the...
13/03/2025
What's next in AI is at GTC 2025. Not only the technology, but the people and ideas that are pushing AI forward - creating new opportunities, novel solution...
13/03/2025
Facebook
Twitter
LinkedIn
By combining T-Mobile's robust network, Thal...
13/03/2025
Bundle up - GeForce NOW is bringing a flurry of Blizzard titles to its ever-expanding library.
Prepare to weather epic gameplay in the cloud, tackling the genr...
13/03/2025
AI is leveling up the world's most beloved games, as the latest advancements...
13/03/2025
PC game modding is massive, with over 5 billion mods downloaded annually. Mods p...
12/03/2025
O Spotify acaba de lan ar o relat rio Loud & Clear deste ano, uma vis o transpar...
12/03/2025
Spotify acaba de presentar el informe Loud & Clear de este a o, una mirada trans...
12/03/2025
Ramadan, a period of profound spiritual significance for Muslims worldwide, is a time for fasting, prayer, reflection, and community. Enrich your experience thi...
12/03/2025
Spotify has just unveiled this year's Loud & Clear report, a transparent loo...
12/03/2025
More than 70% of FAST programming has been produced since 2010, according to new Gracenote report
NEW YORK March 12, 2025 Gracenote, the content data busin...
12/03/2025
GEONA, Nev. Independent digital and linear advertising rep firm Viamedia will adopt cloud-based ShowSeeker Pilot as its primary ad campaign and order management...
12/03/2025
BRUSSELS Mediagenix has announced that Wael Yasin has joined the company as sales director Central Europe....
12/03/2025
LONDON A new study highlights opportunities for shoppable TV and the massive impact online consumer spending is having on the economy, with Omdia predicting tha...
12/03/2025
CUPERTINO, Calif. Interra Systems has announced that Comcast Technology Solutions has integrated recent updates to BATON Version 9 into its operations....
12/03/2025
Nevion announces new 400G addition to its eMerge SDN media fabric offering
Brie Clayton March 12, 2025
0 Comments
High-capacity switch enhances existi...
12/03/2025
DaVinci Resolve Studio Delivers Cinematic Sound for Adam Bol
Brie Clayton March 12, 2025
0 Comments
Feature film relies on DaVinci Resolve Studio for ...