A third of companies are exposing unsafe network services to the internet
New research finds that 33 percent of companies within the digital supply chain expose common network services such as data storage, remote access and network administration to the internet.
The study from RiskRecon and the Cyentia Institute also finds that organizations that expose unsafe services to the internet exhibit more critical security findings.
The research is based on RiskRecon's assessment of millions of internet-facing systems across approximately 40,000 commercial and public institutions. Cyentia and RiskRecon analyzed the data in two ways, the direct proportion of internet-facing hosts running unsafe services, as well as the percentage of companies that expose unsafe services somewhere across their infrastructure.
Within the top three unsafe network services, datastores, such as S3 buckets and MySQL databases are the most commonly exposed. Remote access is the second most commonly exposed service and the report's authors recommend that admins should consider restricting the accessibility of these services only to authorized and internal users.
Universities are a particular problem with 51.9 percent found to be running unsafe services. With a culture that boasts open access to information and collaboration, the education sector has the greatest tendency to expose unsafe network services on non-student systems,
"Blocking internet access to unsafe network services is one of the most basic security hygiene practices. The fact that one-third of companies in the digital supply chain are failing at one of the most basic cybersecurity practices should serve as a wake up call to executives third-party risk management teams," says Kelly White, CEO and co-founder, RiskRecon. "We have a long way to go in hardening the infrastructure that we all depend on to safely operate our businesses and protect consumer data. Risk managers will be well served to leverage objective data to better understand and act on their third-party risk."
The full report is available from the RiskRecon site.
Image credit: fotogestoeber/Shutterstock