Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Over Half Of Organizations Struggle To Avoid Major Incidents And Losses
Articles

Over Half Of Organizations Struggle To Avoid Major Incidents And Losses

Gedeon HombrebuenoBy Gedeon HombrebuenoJanuary 13, 2022Updated:January 6, 20234 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Fortinet Issues A New Critical RCE Vulnerability Alert in FortiOS & FortiProxy
Fortinet Issues A New Critical RCE Vulnerability Alert in FortiOS & FortiProxy
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

In the first half of 2021, we released our Security Outcomes Study: Endpoint Edition. We worked with an independent research firm to conduct a double-blind survey of 4,800 IT and security professionals for our study. Those individuals’ responses demonstrate the value of endpoint security solutions including best practices and program-level outcomes that organizations can use to shape their endpoint security initiatives going forward.

Let’s examine some of the study’s major findings below.

Less Than Half Were Successful in Avoiding a Major Incident

In our survey, 43% of respondents said that their organization had succeeded in avoiding major security incidents and losses over the past couple of years. That’s not to say they didn’t struggle to some degree along the way. That’s also not to say that they didn’t suffer minor or even moderate security incidents in that period. Rather, it means that their security controls helped to preserve their reputation, advance their security goals, and keep them out of the headlines.

We wanted to know how many organizations had experienced a major incident or loss. To find that out, we posed a follow-up question: “Has your organization actually had a major security incident or loss in the last two years?” Approximately two in five survey participants responded in the affirmative, while another 5% said they weren’t sure.

These findings raised the following question. “What threats are helping to drive these major security incidents and losses?”

We examined critical-severity Indicators of Compromise (IOCs) observed on our customers’ networks to find out. Overall, we found that dual-use tools came in first place at 23% of those significant events. Malicious actors specifically leveraged PowerShell Empire, Cobalt Strike, PowerSploit, Metasploit, and other utilities for both exploitation and post-exploitation tasks, as doing so helped them to reduce the noise surrounding their attacks. This is the logic behind using “living off the land” techniques. By abusing legitimate tools for malicious purposes, attackers increase their chances of avoiding detection by not deploying foreign tools that could otherwise raise a red flag with AV tools, a behavior analytics engine, and/or other security capabilities.

As you can see from the screenshot above, ransomware came in second just behind dual-use tools at 22.5% of critical-severity IOCs. Those attacks highlight the extent to which malicious actors now use email, Remote Desktop Protocol (RDP) weaknesses, and other vectors to compromise an endpoint with ransomware. From there, they eventually attempt to spread to other endpoints containing sensitive information as a means of facilitating double extortion.

Fileless malware came in third at 19.9% of critical-severity IOCs. The important thing to note about fileless malware is that signature-based AV solutions can’t detect it because it doesn’t have a signature or executable files. Instead, it deliberately injects itself into processes and uses registry activity to avoid detection.

No wonder then that “Defense Evasion,” one of the Tactics discussed in the MITRE ATT&CK Framework, appeared in 50% of critical IOCs we detected on the endpoint level.

Execution came in second place at 42% of critical IOCs. This was followed by Persistence, Impact, and Lateral Movement at 31%, 22%, and 17%, respectively. Credential Access was least prevalent in critical IOCs we observed at just 16%.

How Organizations Can Avoid Falling Victim to These Threats

In response to the threats identified above, we conducted a multivariate analysis of our survey data to pull out some practices that explain why some organizations’ endpoint security efforts tend to succeed over others. We found that a proactive tech fresh strategy had the greatest impact. Indeed, we found that this exercise helped organizations to increase their chances of avoiding major incidents and losses by 5%-9%, with an average of 7.2%.

Learning from previous incidents increased organizations’ probability of success by 5.5%, while executing prompt disaster recovery and having sufficient security tech had a similar impact at 4.3% and 4.2%, respectively.

For more insights, check out Cisco’s Security Outcomes Study: Endpoint Edition here.

Gedeon Hombrebueno

Gedeon Hombrebueno, Manager, Product Marketing at Cisco

    The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

    Share. Facebook Twitter LinkedIn Email Copy Link

    Related Posts

    Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

    May 20, 20265 Mins Read

    Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

    May 6, 20265 Mins Read

    Why OSINT deserves the same status as other intelligence disciplines

    March 17, 20266 Mins Read
    ISB-Bora-Side-Bar

    No se ha podido establecer conexión. Error 429

     
    ISB-Bora-Side-Bar
    Black ISB Logo

    Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

    X (Twitter) LinkedIn Facebook RSS

    Working With Us

    • About Us
    • Advertise With Us
    • Contact Us

    Write For Us

    • How To Contribute

    The Pages

    • Privacy Policy
    • Cookie Policy
    • AI Policy
    • Terms & Conditions
    • Copyright Notice

    Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

    Type above and press Enter to search. Press Esc to cancel.

    Manage Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}