A recent industry study conducted by Spur Intelligence, surveying over 200 security practitioners, reveals that anonymizing infrastructure—including VPNs and residential proxy networks—now appears in nearly every security incident. Despite the abundance of IP data available, many organizations struggle to sift through noise and lack the visibility, context, and operational workflows needed for effective decision-making.
The study highlights that traditional approaches based solely on reputation or static blocklists are becoming less effective as cybercriminals leverage residential proxies and VPNs to blend malicious activity with normal user behavior. Nearly half of companies reported significant operational or financial impact from account takeover attempts and credential abuse via these anonymization tools.
A major obstacle is the lack of contextual information to determine who is behind a connection. Basic IP attributes like geolocation and network ownership often fail to explain intent. Security teams need additional layers of context, including infrastructure classification, VPN and proxy attribution, behavioral indicators, historical usage patterns, device and session correlations, and automation signals.
Reactive security remains the norm, with IP intelligence primarily used during investigations after alerts are generated. However, a growing number of teams are exploring proactive approaches, such as adaptive authentication, risk-based access controls, fraud prevention, automated policy enforcement, and session risk scoring.
The study also underscores overlooked internal risks from bring-your-own-device policies, consumer apps, and personal VPN usage, which create blind spots. 61% of respondents reported being moderately, slightly, or not at all concerned about internal network exposure via residential proxies on employee devices. As zero-trust architectures mature, internal proxy activity must be treated as a potential risk signal.
Quantifying the effectiveness of IP intelligence remains a challenge, with a third of companies not measuring it at all. Security leaders are increasingly focusing on outcomes like investigation time, false positives, and costs. The future of IP intelligence will demand richer context, automation, and tighter integration with decision-making workflows to move from detection to decision.
CVEs: CVE-2026-11645
Companies: Spur Intelligence
Original source: thehackernews.com