Site navigation

High Risk Sectors Have the Most Critical Vulnerabilities

Elizabeth Greenberg

,

critical vulnerabilities
Critical sectors like finance and health tend to have the most high-risk vulnerabilities, new research reveals. 

Organisations are continually underestimating the security needs of sites containing fewer complex applications, new research from Black Duck reveals.

The report, 2024 Software Vulnerability Snapshot, offers insights from over 200,000 dynamic application security testing (DAST) scans across around 13,000 applications in 19 industries.

The report revealed the top three sectors with critical vulnerabilities, which include finance and insurance, healthcare and social assistance, and information services.

Top Sectors

Small and medium-complexity sites tend to have more critical vulnerabilities than those with larger complexity, particularly in finance and insurance, which had the highest number of critical vulnerabilities (1,299). The sector, which is highly regulated, therefore still faces substantial risk, despite threat actors continually targeting this industry for maximum financial gain.

The healthcare and social assistance sector was closely behind with 992 critical vulnerabilities, which raises concerns about patient data protection and compliance with regulation.

In the UK, the NHS has been continually targeted, either directly through NHS councils, or through high-profile breaches of affiliate labs such as Synnovis.

Data-centric industries are also in danger, as information services was the third highest sector in terms of critical vulnerabilities, with 446.

Top Vulnerabilities

In terms of what these vulnerabilities looked like, Black Duck rounded the 96,917 vulnerabilities it identified into three critical categories.

Cryptographic failures, or sensitive data exposure, accounted for 30,726 vulnerabilities, including nearly 5,000 critical risk instances.

These affected 86% of clients, representing one of the most common and serious security issues across industries.

4,814 were identified as injection vulnerabilities, with over half of those classified as critical instances. These vulnerabilities, which include SQL Injection and Cross-Site Scripting (XSS), allow for the potential for data theft and compromised systems, posing a significant threat to security.

Misconfigurations to security systems affected nearly all (98%) of clients Black Duck scanned, with over 36,000 identified vulnerabilities. However, while many of these were deemed information by Black Duck, as in, no immediate action was indicated, they still represent significant potential for security risks.


Recommended reading


Remediation Variation

Black Duck also found variations in the remediation times for security incidents across various sectors.

Despite having the highest amount of vulnerabilities, the finance and insurance sector demonstrated the fastest response times, which varied based the complexity of the sites. with 28, 23, and 78 day response times for small, medium, and large complexity sites respectively.

Utilities, on the other hand, had the longest remediation time, with small sites taking 107 days, and medium complexity sites taking 876 days on average

Recommendations

The report highlighted the mounting challenges faced in application security across various industries, and recommends that organisations prioritise sensitive data exposure and injection vulnerabilities, particularly in high-risk sectors like finance and health.

Further, they recommend reducing time-to-close for critical vulnerabilities to mitigate the long-term effect any breaches may have.

Addressing misconfigurations and implementing a multifaceted security approach centered around testing and comprehensive coverage is also vital.

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data