Site navigation

Report: FTSE 350 Cybersecurity Posture Has Improved

Michael Edgar

,

FTSE 350 cybersecurity posture
On nearly every metric in a report on the cybersecurity posture of UK-based organisations on the FTSE 350, there has been significant improvement since 2021.

The report is by cybersecurity firm Rapid7, which examines the attack surface of the UK as represented by the Financial FTSE 350 – the 350 largest publicly traded companies in the Financial Times Stock Exchange.

According to the report, financial and technology companies dominate the average number of exposed ports and “high-risk” ports (commonly associated with FTP, SSH, Telnet, SMB and RDP). 

While this is commonplace across the globe as both sectors are reliant on the internet, where tech companies dominate in exposed ports and fall in the middle of the pack in high-risk ports, financial companies continue to expose a number of concerning ports. According to the report, the average financial services company is exposing two telnet ports, a notoriously insecure protocol . The report implores financial services organisations to re-evaluate their external attack surface. 

However, compared to 2021, the numbers have greatly improved across the board. “This is a positive trend that we are seeing across the UK,” said Erick Galinkin, Principal Researcher at Rapid7. “As organisations become more aware of the importance of cybersecurity, they are taking steps to improve their overall security posture. This is an encouraging sign for the industry as a whole.”

Another area of improvement from 2021 were the email security standards. According to the report, 247 companies in the FTSE 350 had a valid domain-based message authentication, reporting & conformance (DMARC) policy. This policy protects email channels from spoofing techniques used in phishing and other email based attacks. 

However, the report finds that the number of companies using the DNS security extensions (DNSSEC), which strengthens authentication in the domain name system using digital signatures on public key cryptography, this year were “bleak”. 

The company found that just 4% of the FTSE 350 companies implemented DNSSEC, which is another area in need of improvement. However, the percentage is on par with other major stock indices such as the Fortune 500 and the ASX 200. 


Recommended


Finally, the report points out the need to patch web server vulnerabilities as they are the favoured access points for attackers. The report found that the total number of web services are dominated by the financial services sector once again, with companies appearing to favour Apache. In contrast with the ASX 200 where Nginx is more commonplace. 

The report finds that only roughly 30% of Nginx servers are running a supported version. Unsupported versions of web servers will not receive patches necessary to improve the vulnerabilities and will remain vulnerable until the underlying software is upgraded. 

Luckily, in the FTSE 350 where Apache is favoured, almost 89% of servers are running on a supported version. Additionally, the report found no new critical vulnerabilities in Apache or Nginx in the last 12 months.  

“The improvement in cybersecurity metrics is a clear indication that organisations are taking cybersecurity seriously and making progress in their efforts to protect their networks and data,” said Galinkin. “However, there is still more work to be done, and it is important that companies continue to invest in cybersecurity for ongoing risk management and threat mitigation.”

Michael Edgar

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data