The majority (82%) of companies say that there’s an expanding gap between the number of security exposures and their ability to manage them.
This is according to new research from XM Cyber, the hybrid cloud security company, which has published its 2024 State of Security Posture Survey. The report, based on a survey of 300 cybersecurity decision-makers from large orgs in the UK and US, looked at how exposures are being remediated and the level of effort invested into doing so.
Alongside the headline statistic, it discovered that 87% of organisations indicated plans to enhance vulnerability and exposure remediation efforts within the next year. This decision comes despite challenges such as a shortage of skilled personnel and the continued burden on existing security teams.
According to the findings, 62% of IT and security teams are actively engaged in remediating exposures, handling an average of 12 per week. This indicates a significant but insufficient effort given the ever-growing number of exposures.
The research also found that there’s to be a particular focus on cloud and integrated cybersecurity strategies going forward. Around 45% of firms identified the cloud as a primary area for enhancing security posture amid growing concern. However, nearly half of the companies surveyed manage exposures separately for on-prem and hybrid cloud environments.
Challenges in communication and organisation alignment were also evident. Approximately 68% of companies emphasised the importance of effectively conveying security posture to leadership.
Recommended reading
- 22% of Phishing Attacks Utilised QR Codes, New Insights Reveal
- NCSC Warns of “Significant” Threat to UK’s Critical Infrastructure
- Which Data Breaches Had Everyone Talking This Year?
“The data highlights two crucial gaps that need to be bridged: the expanding gap between exposures and remediations, and the communications gap between security operators and leadership,” said Boaz Gorodissky, CTO and co-founder of XM Cyber.
“It’s a call to action for organizations to not only invest in advanced solutions but also to foster a culture of cybersecurity awareness and collaboration.”





