This is according to the new State of External Exposure Management report by CyCognito, which analysed 3.5 million assets across its customer base, including Fortune 500 entities, between June 2022 and May 2023.
It found that in addition to being susceptible to significant exploits, 11% of assets with PII contain an “easily” exploitable weakness. “These vulnerable high value assets create windows of opportunity for attackers looking to exfiltrate and sell data or leverage access,” says the report.
Exploits identified by this report as being vulnerable are based on known exploits, meaning there could be unknown exploits these assets are vulnerable to. These assets can be found across public cloud, mobile and web platforms, raising concerns about data safeguarding and privacy.
In the UK, 32% of businesses reported suffering a breach between 2022-2023, which rises to 59% for medium sized businesses and 69% for large businesses. Recently, a MOVEit file-transfer vulnerability exploited information from hundreds of organisations, including Boots, British Airways, and the BBC.
Other concerning findings in the report was the revelation that the average global enterprise manages 12,000 applications, and of those, over 30% are susceptible to a vulnerability, even though half of them are hosted in cloud environments.
Recommended
- How Cybercriminals Exploit Trust Between Organisations
- New Emergency Alert System Ripe for Potential Scams
- UK Intelligence Agency Warns of Criminals Exploiting Coronavirus
The report also looked into GDPR compliance, and found that 98% of web applications are potentially not compliant, for lack of opportunity in allowing users to opt out of cookies.
To rectify the situation, experts suggest measures to safeguard the identified vulnerability crisis going forward. Regular scans for vulnerabilities, multi-factor authentication, and the encryption of data in transit and rest were the top suggestions.
“Organisations must go beyond simply indexing their assets and engage in true exposure management practices by identifying, testing, and prioritising the remediation of high value assets,” says the report.





