{"id":18329,"date":"2021-12-15T16:08:38","date_gmt":"2021-12-15T15:08:38","guid":{"rendered":"https:\/\/www.proactivanet.com\/blog\/sin-categorizar\/reduce-the-risk-of-cyberattacks-by-30-by-simply-applying-patches\/"},"modified":"2023-02-21T20:05:35","modified_gmt":"2023-02-21T19:05:35","slug":"reduce-the-risk-of-cyberattacks-by-30-by-simply-applying-patches","status":"publish","type":"post","link":"https:\/\/www.proactivanet.com\/en\/blog\/safety-management\/reduce-the-risk-of-cyberattacks-by-30-by-simply-applying-patches\/","title":{"rendered":"Reduce the risk of cyberattacks by 30% by simply applying patches"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">Some time ago, in one of by presentations, I shared with you some figures from a study of cybersecurity regarding the GAP that exists between detection of a vulnerability (or risk of cyberattacks) and the moment when the organizations apply a \u201cpatch.\u201d At the time, the figure seemed to me very concerning, because it mentioned almost 2 months for simply applying a patch to a known vulnerability with an available solution (a \u201cknown error\u201d, in terms of ITIL.:-))<\/span><\/p>\n<p><!--more--><\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-6961 size-full\" src=\"https:\/\/www.proactivanet.com\/wp-content\/uploads\/2021\/03\/Verizon-Data-Breach-Investigation-Report-2016.png\" alt=\"Verizon Data Breach Investigation Report 2016\" width=\"625\" height=\"452\" srcset=\"https:\/\/www.proactivanet.com\/wp-content\/uploads\/2021\/03\/Verizon-Data-Breach-Investigation-Report-2016.png 625w, https:\/\/www.proactivanet.com\/wp-content\/uploads\/2021\/03\/Verizon-Data-Breach-Investigation-Report-2016-300x217.png 300w\" sizes=\"(max-width: 625px) 100vw, 625px\" \/><\/p>\n<p><span style=\"font-weight: 400;\">I didn\u2019t want to give much credit to this figure, because it seemed very high, but in light of a new study by Kaspersky, I am starting to think that it is true. According to this study, more than 30% of cyberattacks take advantage of vulnerabilities that have not been patched, which seems to lend credibility to the previous figures...(and if we also add the \u201cnon-policy\u201d of secure passwords, then we arrive at figures that are dizzying...).<\/span><\/p>\n<p style=\"padding-left: 40px;\"><a href=\"https:\/\/www.computing.es\/seguridad\/informes\/1128523002501\/gestion-de-parches-y-contrasenas-sofisticadas-reducen-riesgo-de-ciberataques-60.1.html\" target=\"_blank\" rel=\"noopener\"><i><span style=\"font-weight: 400;\">Management of patches and sophisticated passwords reduce the risk of cyberattacks by 60%.<\/span><\/i><\/a><\/p>\n<p><span style=\"font-weight: 400;\">I encourage you to read the previous article so that you can see some of the figures in more detail, but if you don\u2019t feel like it, then I will give you a <\/span><i><span style=\"font-weight: 400;\">spoiler<\/span><\/i><span style=\"font-weight: 400;\">: the majority of vulnerabilities that are exploited in a cyberattack are not even from this year!! The majority of these vulnerabilities are many months (or even years) old, and therefore the figure for days of vulnerability could really be much worse.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">With technology from 20 years ago, maintaining a minimally patched infrastructure could be a very complicated task, but today\u2019s technology makes it easy thanks to automation! Find out what you have, in what condition you have it, where you have it, obtaining detailed and absolute knowledge of the patches yet to be deployed in each device, and being able to deploy them \u201cwith a single click,\u201d would be a <\/span><i><span style=\"font-weight: 400;\">must have<\/span><\/i><span style=\"font-weight: 400;\"> in the agenda of any systems manager.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Remember: Don\u2019t let this happen - adopt measures from the first day!<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><em>I hope that you enjoy it, and farewell<\/em><\/p>\n<p><em><a href=\"https:\/\/www.linkedin.com\/in\/proactivajandro\/\" target=\"_blank\" rel=\"noopener noreferrer\">Alejandro Castro<\/a>, <a href=\"https:\/\/www.proactivanet.com\/en\/\" target=\"_blank\" rel=\"noopener noreferrer\">Proactivanet\u2019s<\/a> Technical Director<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Some time ago, in one of by presentations, I shared with...  <\/p>\n<div class=\"read-more mt-4 text-blue text-xs\"><\/div>\n","protected":false},"author":7,"featured_media":16613,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1464],"tags":[1496,1482,1466],"class_list":["post-18329","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-safety-management","tag-ransomware-en","tag-itam-en","tag-cybersecurity"],"acf":{"is_icon":[]},"post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/www.proactivanet.com\/en\/wp-json\/wp\/v2\/posts\/18329","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.proactivanet.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.proactivanet.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.proactivanet.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/www.proactivanet.com\/en\/wp-json\/wp\/v2\/comments?post=18329"}],"version-history":[{"count":0,"href":"https:\/\/www.proactivanet.com\/en\/wp-json\/wp\/v2\/posts\/18329\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.proactivanet.com\/en\/wp-json\/wp\/v2\/media\/16613"}],"wp:attachment":[{"href":"https:\/\/www.proactivanet.com\/en\/wp-json\/wp\/v2\/media?parent=18329"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.proactivanet.com\/en\/wp-json\/wp\/v2\/categories?post=18329"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.proactivanet.com\/en\/wp-json\/wp\/v2\/tags?post=18329"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}