|

Linked – Cybersecurity Report Card for 2016: Overall “C-“ but bad news since the Cloud gets a “D-“ and Mobile gets an “F”!

Fail photo
Image by (e)Spry

“Tenable Network Security surveyed “700 security practitioners across seven key industry verticals and nine countries” that produced “a single report card score that represents overall confidence levels of security practitioners that the world’s cyber defenses are meeting expectations.” The “2017 Global Cybersecurity Assurance Report Card” from Tenable with research partner CyberEdge Group included these comments about the Cloud Darkening:

Cloud software as a service (SaaS) and infrastructure as a service (IaaS) were two of the lowest scoring Risk Assessment areas in the 2016 report. SaaS and IaaS were combined with platform as a service (PaaS) for the 2017 survey and the new “cloud environments” component scored 60% (D-), a seven point drop compared to last year’s average for IaaS and SaaS.

The Report Card included these comments about Mobile Morass:

Identified alongside IaaS and SaaS in last year’s report as one of the biggest enterprise security weaknesses, Risk Assessment for mobile devices once again dropped eight points from 65% (D) to 57% (F).”

I’d like to say the survey is wrong, but let’s face it. We’ve seen multiple hacks against cloud service providers and platforms, and through mobile devices. Why would anyone have a ton of confidence in the security of any online system at this point?

The industry needs to do better.

http://www.vogelitlawblog.com/2016/12/articles/cyber/cybersecurity-report-card-for-2016-overall-c-but-bad-news-since-the-cloud-gets-a-d-and-mobile-get-an-f/

Similar Posts

  • Traffic blocks

    According to Dave this morning: “Can you believe it — there are weblogs that turn away traffic based on referrer. This is bad practice. These people seriously need to take a refresher course in what the Web is about and how important links are and stop screwing around with them. I won’t read sites that…

  • |

    Linked: Data breaches happen constantly and there are very little consequences

    This is the crux of the problem. Personal information is going to be breached, eventually. There is no 100% secure data. None. No business, government entity, non-profit, or any other place that collects and stores data is completely secure. The only true security for personal information is to not have it. To have not collected it or delete it once it’s no longer needed.

    That is the radical re-think that is necessary. It’s also the complete opposite of everything these organizations have been taught and incentivized to do. If we are going to pass federal privacy laws, this should be the central theme.

  • |

    Email Hacked

    Apparently, an old Yahoo! email account that I haven’t used in over a year, was accessed by someone to send out emails to everyone in the contact list. Since I had, at some point, imported my LinkedIn contacts to Yahoo!, that turned out to be quite a few people. My assumption is that my recent…

  • |

    Linked – Productivity is outdated. Here’s why.

    When you have that blurring, though, the idea that you can measure productivity the same way as you did when we spent 8 hours building a widget seems a little overly simplistic, doesn’t it?

    The challenge is finding the thing we can measure to evaluate whether people are accomplishing the goals we set for them, but those goals can’t be the “number of things or hours” when the work is so much more than that.

  • Firefox Hole

    By now I’m sure you’ve all heard about the security hole in Firefox, and the “recommended fixes”. Here’s the thing though, turning off Javascript disables all those cool little Greasemonkey scripts, and turning off “Let website install software” just makes it more difficult for people to get extensions for Firefox. It’s those extensions and add-ons…

  • |

    Friendfeed’s Over-Inflated Sense of Self

    Now that Friendfeed has decided to report the number of people who follow you on their service as “subscribers” when it polls an RSS feed, how over-inflated are your subscriber numbers? A couple of folks in the comments there have already pointed out the obvious, being subscribed to someone on Friendfeed, and maybe seeing just…

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

To respond on your own website, enter the URL of your response which should contain a link to this post's permalink URL. Your response will then appear (possibly after moderation) on this page. Want to update or remove your response? Update or delete your post and re-enter your post's URL again. (Find out more about Webmentions.)