Enterprise cyber threat remediation ineffective, study shows

May 15, 2018 / Warwick Ashford

Enterprise cyber threat remediation needs to improve in several key areas, according to an analysis of common remediation strategies. Common enterprise cyber threat remediation strategies are about as effective as random chance, a study has revealed. Some of the simple rule-based strategies do not perform any better than rolling the dice, according to a follow-up report by predictive cyber risk firm Kenna Security and the Cyentia Institute research. Comparing various enterprise cyber risk remediation strategies against a “random” approach, the study found that the efficiency rate remained the same, at around 23%. The study was based on the analysis of five years of historical vulnerability data, comprising millions of data points compiled from more than 15 sources. A total of 94,597 Common Vulnerability Exposures (CVEs) from Mitre were also used in the research. The key areas organisations need to improve, the report said, include reducing the time it takes to assess whethe...