share_log

ESG Research Reveals Attack Surface Is Outgrowing Traditional Pentesting Capabilities

ESG Research Reveals Attack Surface Is Outgrowing Traditional Pentesting Capabilities

esg研究显示攻击面正在超越传统渗透测试能力。
PR Newswire ·  06/10 08:00

Survey highlights the need for many organizations to rethink point-in-time pentesting and shift to a platform-based, continuous approach.

调查显示,许多组织需要重新考虑时点渗透测试,并转向基于平台的持续方法。

REDWOOD CITY, Calif., June 10, 2024 /PRNewswire/ -- Synack, the premier security testing platform, today announced the results of a survey led by TechTarget's Enterprise Strategy Group (ESG) that shows challenges in scaling penetration testing to meet the needs of large enterprises.

加州红木城,2024年6月10日 /PRNewswire/ -- Synack是首个安全测试平台,今天宣布了由TechTarget的企业策略小组(ESG)主导的一项调查结果,该调查显示大型企业扩展渗透测试以满足需求存在挑战,该报告由Synack委托,结合了至少拥有1,000名员工的美国组织200名技术决策者的见解。

The report commissioned by Synack leverages insights from 200 technical decision-makers at U.S. organizations with at least 1,000 employees. Half of the survey respondents reported it was more difficult to manage their attack surface today than it was a year ago, whether because of third-party risk, data complexity or increasing attacker sophistication.

一半的调查受访者报告称,与一年前相比,他们今天更难管理攻击面,无论是因为第三方风险、数据复杂性还是攻击者复杂性的增加。

58% of enterprises said detecting vulnerabilities is getting more difficult

58%的企业表示,检测漏洞变得越来越困难

Post this
发帖:

Other highlights of the report include:

报告的其他亮点包括:

  • 58% of enterprises said detecting vulnerabilities is getting more difficult as their attack surface increases in complexity, size and rate of change
  • Organizations reported pentesting currently covers only 47% of business-critical apps
  • 60% of respondents reported finding it difficult to test frequently enough to keep up with the pace of application development, with three in four saying it's likely they will consider platform-based testing solutions like Penetration Testing as a Service (PTaaS)
  • 58%的企业表示,随着他们的攻击面在复杂度、规模和变化率方面的增加,检测漏洞变得越来越困难。
  • 组织报告称,目前渗透测试仅涵盖47%的业务关键应用
  • 60%的受访者报告称,频繁测试以跟上应用程序开发的步伐非常困难,其中三分之二的人表示,很可能考虑使用基于平台的测试解决方案,例如作为服务的渗透测试(PTaaS)。

"Point-in-time pentests have been a staple of security programs for so long, it can be hard to move to a continuous approach," said Dr. Mark Kuhr, Synack CTO and co-founder. "This survey shows security teams are aware of PTaaS's potential to accelerate business transformation and keep pace with modern software development, even though few have made the leap."

"尖峰时段渗透测试一直是安全计划的重要组成部分,转向持续方法可能很困难," Synack的CTO和联合创始人Dr. Mark Kuhr说道。 "这项调查显示,安全团队意识到PTaaS加速业务转型和跟上现代软件开发的步伐的潜力,尽管很少有人迈出这一步。"

Only 32% of respondents said they use pentesting to improve overall security strategies and posture. Most either reported using pentesting for compliance or to achieve tactical objectives like finding and fixing vulnerabilities.

只有32%的受访者表示,他们使用渗透测试来改善整体安全策略和姿态。大多数人报告使用渗透测试以符合法规或实现战术目标,例如查找和修复漏洞。

To read more about Synack's approach to PTaaS, click here. For more data points from the ESG survey, click here.

阅读有关Synack PTaaS方法的更多信息,请参见点击这里。有关ESG调查的更多数据点,请参见点击这里.

ABOUT SYNACK:
Synack's premier security testing platform harnesses a talented, vetted community of security researchers and smart technology to deliver continuous penetration testing and vulnerability management, with actionable results. We are committed to making the world more secure by closing the cybersecurity skills gap, giving organizations on-demand access to the most trusted security researchers in the world. Headquartered in Silicon Valley with regional teams around the world, Synack protects a growing list of Global 2000 customers and U.S. agencies in a FedRAMP Moderate Authorized environment. Synack's comprehensive approach to Pentesting as a Service (PTaaS) uncovered more than 14,000 exploitable vulnerabilities in 2023 alone. For more information, please visit .

关于Synack:
Synack的旅游测试平台利用了一个才华横溢、经过审核的安全研究员社区和智能技术,提供持续渗透测试和漏洞管理,具有实用性结果。我们致力于通过关闭网络安全技能差距,使世界更加安全,为全球2000家客户和美国机构在FedRAMP Moderate授权环境中保护数据安全合规。Synack对作为服务的渗透测试(PTaaS)的全面方法仅在2023年就揭示了14,000多个可利用漏洞。有关更多信息,请访问.

SOURCE Synack

SOURCE Synack

声明:本内容仅用作提供资讯及教育之目的,不构成对任何特定投资或投资策略的推荐或认可。 更多信息
    抢沙发