share_log

ESG Research Reveals Attack Surface Is Outgrowing Traditional Pentesting Capabilities

ESG Research Reveals Attack Surface Is Outgrowing Traditional Pentesting Capabilities

esg研究顯示攻擊面正在超越傳統滲透測試能力。
PR Newswire ·  06/10 08:00

Survey highlights the need for many organizations to rethink point-in-time pentesting and shift to a platform-based, continuous approach.

調查顯示,許多組織需要重新考慮時點滲透測試,並轉向基於平台的持續方法。

REDWOOD CITY, Calif., June 10, 2024 /PRNewswire/ -- Synack, the premier security testing platform, today announced the results of a survey led by TechTarget's Enterprise Strategy Group (ESG) that shows challenges in scaling penetration testing to meet the needs of large enterprises.

加州紅木城,2024年6月10日 /PRNewswire/ -- Synack是首個安全測試平台,今天宣佈了由TechTarget的企業策略小組(ESG)主導的一項調查結果,該調查顯示大型企業擴展滲透測試以滿足需求存在挑戰,該報告由Synack委託,結合了至少擁有1,000名員工的美國組織200名技術決策者的見解。

The report commissioned by Synack leverages insights from 200 technical decision-makers at U.S. organizations with at least 1,000 employees. Half of the survey respondents reported it was more difficult to manage their attack surface today than it was a year ago, whether because of third-party risk, data complexity or increasing attacker sophistication.

一半的調查受訪者報告稱,與一年前相比,他們今天更難管理攻擊面,無論是因爲第三方風險、數據複雜性還是攻擊者複雜性的增加。

58% of enterprises said detecting vulnerabilities is getting more difficult

58%的企業表示,檢測漏洞變得越來越困難

Post this
發帖:

Other highlights of the report include:

報告的其他亮點包括:

  • 58% of enterprises said detecting vulnerabilities is getting more difficult as their attack surface increases in complexity, size and rate of change
  • Organizations reported pentesting currently covers only 47% of business-critical apps
  • 60% of respondents reported finding it difficult to test frequently enough to keep up with the pace of application development, with three in four saying it's likely they will consider platform-based testing solutions like Penetration Testing as a Service (PTaaS)
  • 58%的企業表示,隨着他們的攻擊面在複雜度、規模和變化率方面的增加,檢測漏洞變得越來越困難。
  • 組織報告稱,目前滲透測試僅涵蓋47%的業務關鍵應用
  • 60%的受訪者報告稱,頻繁測試以跟上應用程序開發的步伐非常困難,其中三分之二的人表示,很可能考慮使用基於平台的測試解決方案,例如作爲服務的滲透測試(PTaaS)。

"Point-in-time pentests have been a staple of security programs for so long, it can be hard to move to a continuous approach," said Dr. Mark Kuhr, Synack CTO and co-founder. "This survey shows security teams are aware of PTaaS's potential to accelerate business transformation and keep pace with modern software development, even though few have made the leap."

"尖峯時段滲透測試一直是安全計劃的重要組成部分,轉向持續方法可能很困難," Synack的CTO和聯合創始人Dr. Mark Kuhr說道。 "這項調查顯示,安全團隊意識到PTaaS加速業務轉型和跟上現代軟件開發的步伐的潛力,儘管很少有人邁出這一步。"

Only 32% of respondents said they use pentesting to improve overall security strategies and posture. Most either reported using pentesting for compliance or to achieve tactical objectives like finding and fixing vulnerabilities.

只有32%的受訪者表示,他們使用滲透測試來改善整體安全策略和姿態。大多數人報告使用滲透測試以符合法規或實現戰術目標,例如查找和修復漏洞。

To read more about Synack's approach to PTaaS, click here. For more data points from the ESG survey, click here.

閱讀有關Synack PTaaS方法的更多信息,請參見點擊這裏。有關ESG調查的更多數據點,請參見點擊這裏.

ABOUT SYNACK:
Synack's premier security testing platform harnesses a talented, vetted community of security researchers and smart technology to deliver continuous penetration testing and vulnerability management, with actionable results. We are committed to making the world more secure by closing the cybersecurity skills gap, giving organizations on-demand access to the most trusted security researchers in the world. Headquartered in Silicon Valley with regional teams around the world, Synack protects a growing list of Global 2000 customers and U.S. agencies in a FedRAMP Moderate Authorized environment. Synack's comprehensive approach to Pentesting as a Service (PTaaS) uncovered more than 14,000 exploitable vulnerabilities in 2023 alone. For more information, please visit .

關於Synack:
Synack的旅遊測試平台利用了一個才華橫溢、經過審核的安全研究員社區和智能技術,提供持續滲透測試和漏洞管理,具有實用性結果。我們致力於通過關閉網絡安全技能差距,使世界更加安全,爲全球2000家客戶和美國機構在FedRAMP Moderate授權環境中保護數據安全合規。Synack對作爲服務的滲透測試(PTaaS)的全面方法僅在2023年就揭示了14,000多個可利用漏洞。有關更多信息,請訪問.

SOURCE Synack

SOURCE Synack

声明:本內容僅用作提供資訊及教育之目的,不構成對任何特定投資或投資策略的推薦或認可。 更多信息
    搶先評論