Newsletters    RSS RSS Feeds


Trusted Strategies: Slow Response Leaves Mobile Users Most Vulnerable to Security Threats

Trusted Strategies and Shavlik Technologies today released findings of a new study aimed at identifying how companies assess, remediate and manage vulnerabilities, and where security policies break down or are under supported by current solutions. The study points to a lack of automated solutions to support security configuration management at the edge of the network as an ongoing and critical flaw in vulnerability management offerings. Plus, less than a third of survey respondents expect Microsoft Vista to solve most or all patch and vulnerability lifecycle management needs.

The Trusted Strategies survey drew responses from more than 150 U.S.-based IT security professionals. The study was sponsored by Shavlik, a leader in security configuration and policy management software.

According to the survey:

  • Nearly two-thirds (60.4 percent) of respondents listed mobile laptops as the greatest threat to maintaining a secure posture.
  • Half of respondents (49.6 percent) said that it takes more than six days to patch critical vulnerabilities on laptop computers.
  • Nearly 80 percent (77.4) of critical server vulnerabilities and 70 percent (67.9) of critical desktop vulnerabilities are patched within six days of discovery.

The survey data suggests that this discrepancy may be explained as a lack of automated assessment, remediation and management tools at the edge of the network (especially on mobile devices). While over 90 percent of respondents believe it is "important" or "very important" to fully automate all of the patch and vulnerability management lifecycle, one in three respondents report that they have only automated "some" or "none" of the patch/vulnerability lifecycle on mobile desktops.

"Over the last six to 12 months, zero-day exploits have risen significantly as hackers grow smarter, better organized, and more financially motivated," said Mark Shavlik, CEO of Shavlik Technologies. "And once a vendor releases its patch, the timeframe to deploy the patch across the network must be extremely short as knowledge of how to exploit the vulnerability rises exponentially once a patch is published. Best practices therefore dictate available patches be deployed within 36 hours or less, to every machine on the network, especially to those distributed and mobile end points that are most vulnerable."

The survey findings also seem to support the belief within the security market that while Microsoft Windows Vista will improve security, it will not completely address customers’ patch and vulnerability lifecycle management needs. Only 30 percent of respondent expect Vista to solve "all" or "most" of those requirements, and nearly another 30 percent “don’t know” how Vista will impact patch and vulnerability management.

"Contrary to speculation by the media and other observers, the survey data suggest that the release of Vista later this month will not signal the death knell of third-party security solution providers," said Bill Bosen, a Partner at Trusted Strategies. "While respondents recognize there will be security benefits with Vista adoption, they see value in an integrated vulnerability management solution that augments Microsoft’s security improvements."

About the market research survey

Contact Trusted Strategies at the link below or Shavlik Technologies for more information on the study.

» Story on Analyst Firm Website

comments powered by Disqus

 

 



 Subscribe to this news feed
 Click this link to view Security news as XML.

Trusted Strategies

Trusted Strategies LLC focuses exclusively on the business of Information Technology Security.

We advise investors, venture capitalists, merger and acquisition specialists, and IT security product companies. Trusted Strategies services include:

SEARCH THE ANALYST BLOGS

Find instant analyst opinions, news analysis and more, at 200+ personal, company and media blogs

 

SEARCH THE ANALYST FIRM WEBSITES

 

CHECK ANALYST CREDENTIALS

Use exact spelling.   Example: Charlene Li