The study analyzed the cybersecurity performance of nearly 100,000 organizations around the world across nine industries.
Bitsight mapped its risk vectors to 16 of the MVSP controls and reported performance in 2023 and over time.
Google validated the statistical approach employed in this analysis.
The study found that while every industry in 2023 has a high Pass rate for 10 of the 16 MVSP controls studied, many organizations are still failing on controls critical to protecting themselves against cyber incidents.
The findings indicate that organizations across all industries have several areas in which they must improve their vulnerability management program to reduce exposure to potential breaches.
Notably, 2023 Computer Software industry Fail rates for Dependency Patching and Time to Fix Vulnerabilities - which map to Bitsight analytics correlating to the likelihood of a breach - did not improve from 2020 rates as much as the macro average, leaving other industries vulnerable to third-party risk given their reliance on computer software.
They also had high Pass rates for Customer training and Training.
Organizations across all industries are struggling with controls critical to the health of an organization's vulnerability management program, Bitsight found.
Eight MVSP controls that are important for vulnerability management - External Testing, Self-assessment, Vulnerability Prevention, Encryption, HTTPS-only, Security Headers, Dependency Patching, Time to Fix Vulnerabilities - have either high 2023 Fail rates, low Pass rates, or both, across all industries.
Finally, there has been a decline in use of security headers, including in the computer software industry.
Business leaders around the world need to understand where their companies' vulnerabilities lie and how they match up with others to better manage increasingly complex cyber risks and stakeholder demands.
By understanding the pass and fail rates of MVSP controls organizations will be better armed with the knowledge to benchmark their security performance and improve their cybersecurity strategies to mitigate and reduce vulnerability.
This Cyber News was published on www.helpnetsecurity.com. Publication date: Wed, 13 Dec 2023 10:13:04 +0000