The Threat is Real • 15% of all Hosting and web application environments combined have a high or critical risk • 95% of Critical risks are in the web application layer • 82% of High Risks are in the web application layer • 65% of all vulnerabilities discovered are in the Hosting Layer 15.1% of Assets have high or critical risk vulnerabilities Critical Risk: 1% Overall vulnerability Breakdown across both web application and hosting environments: High Risk: 14% Medium Risk: 17% 2016 Risk Rating Minimal Risk: 44% Low Risk: 24% High or critical vulnerabilities are defined as: • Easily exploitable • Usually remote from the public Internet • Application and Network layers combined • Root Cause: Coding errors, configuration flaws and out-of-date or no patching applied Remediation: Even though patch management is less than glamorous it still needs to be consistently performed. Security patches are a result of security bugs being discovered in application component and server systems provided by third parties. In relation to web application security we still talk about Secure Application Development. It’s our view that security touch points and developer education is a good starting place to correct the problem.
5 Publizr Home