Select your language

'Companies do not plan their Digital Protection strategies thinking about risks'

Mexico. Westcon-Comstor's business unit and one of the leading Cisco technology wholesalers, says companies are not yet planning their Digital Protection strategies with risks in mind.

Security is one of the most discussed and discussed topics in the area of IT. However, each new study of the sector reveals an intriguing reality: despite the high information on alerts and vulnerability, companies still do not plan their Digital Protection strategies thinking about the risks. 

A recent study by White Hat, a Web security company, revealed that, although after countless warnings about application vulnerability dangers, for example, companies still do not have a systemic work that prioritizes the containment of security risks in this item.

The report, which concentrates annual data on Web security, showed that, in addition to the lack of plans for the containment of risks in terms of applications, companies can take months or even years for most vulnerabilities to be communicated in all sectors of the organization. Likewise, it would also take a long time to establish measures to prevent further similar attacks or to open the way to a number of other security problems.

- Publicidad -

To get an idea of the risk, the White Hat paper shows that about a third of insurance orders, nearly 40% of banking or financial services applications, and half of retail applications, for example, are always vulnerable and that the number of breaches in those applications has grown significantly. On the other hand, application security does not improve at the same rate as attacks. 

Companies have taken, on average, 150 days to fix vulnerabilities, but only a significant portion of them are corrected. In addition, the average time to fix a vulnerability after a breach reaches systems can take 2 to 5 years.

What does this mean?
Specialists translate that data with concern, because if critical and high-risk vulnerabilities known to companies are not corrected quickly, what can be expected from new threats? And the delayed response time in detecting and containing breaches means that companies are increasingly exposed and that there is not yet, on the part of companies, a plan that defines priorities in terms of Web security focused on the systematic risk of those vulnerabilities.

The recommendation is that organizations make a better security assessment with a focus on building strategies and remediation, considering the software lifecycle.

Another statistical study, conducted by Akamai, a U.S. Internet company, showed a more than 20% increase in attacks on Web applications, especially attacks on HTTPS Web applications, which rose almost 234%. Interestingly, there was also a huge increase in SQL injection attacks, with an 87.3% jump in that area.

Since the environment in companies is more oriented to the increase of connectivity, there is a clear need to adapt to the security infrastructure, which includes attention to the increase and diversity of different devices that will be connected, as well as applications and integration points in those networks.

In this way, companies need a focus on the definition of protection policies and use of monitoring, grouping the infinity of types of products available for the construction of a security architecture. Without that, criminals will have an open field to commit crimes, without any kind of security plan and containment of those threats.

Santiago Jaramillo
Santiago JaramilloEmail: [email protected]
Editor
Comunicador social y periodista con más de 15 años de trayectoria en medios digitales e impresos especializados para América Latina. Actualmente Editor de las revistas Ventas de Seguridad, Gerencia de Edificios y Coordinador académico del Congreso TecnoEdificios.

No comments

• If you're already registered, please log in first. Your email will not be published.

Leave your comment

In reply to Some User
Investing in Access Controllers: Why Eliminating Them Can Be a Strategic Mistake

Investing in Access Controllers: Why Eliminating Them Can Be a Strategic Mistake

Thanks to technological evolution, today there are smart readers with the capacity to process credentials, store information and even operate locks autonomously. This has led many organizations to...

Case study: How did a retail chain in Costa Rica reduce fraud by 18%?

Case study: How did a retail chain in Costa Rica reduce fraud by 18%?

Almacenes El Rey is a rapidly expanding department store, with 18 branches nationwide and more than one million customers each year. Thanks to the Avigilon Unity Video solution, the retail chain...

Is storing video no longer enough? Milestone's Sales Director for Latam speaks

Is storing video no longer enough? Milestone's Sales Director for Latam speaks

Latin America. Johana Arias, an executive at Milestone Systems, discusses how the integration of AI, natural language, and open platforms are transforming video into actionable insights for...

Anti-intrusion system described as one of Ajax's largest in South America

Anti-intrusion system described as one of Ajax's largest in South America

Argentina. The Bayron company installed a protection system with more than 85 Ajax wireless devices in the new branch of Autos del Sur S.A., Toyota's official dealership in the country.

Interview with Manuel Carlos, Senior Sales Director for Mexico at Hanwha Vision

Interview with Manuel Carlos, Senior Sales Director for Mexico at Hanwha Vision

Mexico. Manuel Carlos, an executive at Hanwha Vision, details how the company is revolutionizing electronic security by consolidating generative artificial intelligence and processing at the edge.

Prosegur presents new capabilities in cybersecurity and automation

Prosegur presents new capabilities in cybersecurity and automation

International. Prosegur Security has created two new modules, xCope and xEcute, which aim to provide companies and organizations with a new corporate digital surveillance service and another for...

Access and video platform

Access and video platform

Johnson Controls Designed to take the complexity out of legacy systems, the latest version of C•CURE IQ helps organizations achieve faster response, simplify workflows, and turn safety data into...

SIA presents the new directives of its International Relations Committee

SIA presents the new directives of its International Relations Committee

Latin America. Mariana Ramírez is the new president of the International Relations Committee of the Security Industry Association (SIA), while Vanesa Cabral assumed the role of vice president.

Access management and security in stadiums during the World Cup

Access management and security in stadiums during the World Cup

International. With the World Cup underway, stadium operation and the management of credentials and critical assets become key factors in ensuring security in high-demand environments.

Jovicard modernizes its headquarters with HID access control technology

Jovicard modernizes its headquarters with HID access control technology

Brazil. Jovicard, which specializes in physical access control, secure identity, biometrics and integrated electronic security, completed the modernization of its corporate headquarters with trusted...

Suscribase Gratis
Remember Me
SUBSCRIBE TO OUR ENGLISH NEWSLETTER
DO YOU NEED A SERVICE OR PRODUCT QUOTE?
LATEST INTERVIEWS
SITE SPONSORS










LATEST NEWSLETTER
Latest Newsletter