Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Four Ways To Deal With Cybersecurity Risks
Articles

Four Ways To Deal With Cybersecurity Risks

ISBuzz TeamBy ISBuzz TeamJune 20, 2016Updated:July 4, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Web application security is a very hot topic these days, as shown by the variety of websites falling victim to hacking.

One financial organisation fell foul to a data breach exposing over 1.4GB of customers’ data, including full personal data and credit card information. It was suspected that this bank was compromised via an SQL injection vulnerability.

In such an inhospitable climate, how can CISOs and their security teams respond to the growing cybersecurity risks that threaten insecure web applications?

Risk Acceptance

Data breaches are just the tip of the iceberg and there are many more successful attacks that simply remain undetected or unreported, so acceptance is not a viable option – especially when one considers that nowadays risks such as Advanced Persistent Threats (APT) can start at your own website regardless of how big or protected you think your company is.

Risk Avoidance

With various websites and web applications integrated into each company’s core business processes, avoidance is also no longer feasible. ERPs, CRMs, HRMs and many more vital systems are either web-based or at least provide a web interface, so even if the only web application you have is a static website, attackers will still seek to hack into your website to try and get at your most sensitive and confidential information.

Risk Mitigation

Involves three key aspects:

  1. Produce a complete and up-to-date digital asset inventory of all your web applications – companies are often hacked via abandoned subdomains or web applications that are no longer maintained.
  2. Minimise your company’s attack surface – the simplest way – and perhaps the most reliable – is to restrict access to your web applications. If a web application is designed for internal usage only, make sure it’s only available to internal and is not accessible from outside your company. If ypu have employees that work from home or are on the road travelling and need access, you can whitelist VPN IPs, or add a client SSL certificate and 2FA authentication mechanisms. The less web applications that you have which are publicly exposed, the more reliable your protection against potential problems.
  3. Ensure that you maintain all web application software regularly – a continuous monitoring and patch management system in place is essential as, with zero-days for even the most popular web applications appearing in public on a daily basis, you cannot rely on quarter vulnerability scanning anymore. Instead, set up a 24/7 automated vulnerability monitoring and support that with manual or hybrid security testing to identify complicated security flaws that vulnerability scanners cannot before they cause a problem.

Setting up a Web Application Firewall is a good idea, but bear in mind that WAFs are designed to block simple and automated attacks, so are unlikely to save you from professional Black Hat hackers.

Security training for your web developers is also a good idea, but if you outsource software development, make sure that you introduce obligatory secure software development qualification prerequisites whenever you are conducting RFPs.

Implementing a Secure Software Development Life Cycle (S-SDLC) is another good idea but only if you have an opportunity to deploy and properly maintain it afterwards. Otherwise, in the era of agile development and outsourcing, S-SDLC will not always solve the problems it is supposed to.

Risk Transfer

The global cyber insurance market is anticipated to reach $7.5 billion by 2020 – a staggering 300 percent increase on this year’s $2.5 billion this year. Cybersecurity insurance may be a good idea, however you should bear in mind that the cybersecurity insurance market is still in its infancy.

Pavel Sotnikov, managing director for Eastern Europe, Caucasus and Central Asia at Qualys, CISSP, MSs, comments: “In today’s world there is no space anymore for single-factor protection. Companies should definitely adopt Defence-in-Depth methodology for layered robust security measures. If we take website security as an example, there definitely should be continuous automated vulnerability testing both for the website and the infrastructure that supports it, moreover there should be security testing during all stages of the SDLC in addition to the secure coding practices. Additionally, there should be Web Application Firewall for proactive protection. Ideally, all this should be complemented through regular manual penetration testing by qualified professionals.”

The advice is to concentrate all of your efforts on appropriate risk mitigation, complemented by risk transfer activities to prevent incidents before they even occur.

[su_box title=”About Ilia Kolochenko” style=”noise” box_color=”#336588″][short_info id=’60198′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

AppSec is dead, long live AI security

April 29, 20265 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}