Seguridad Mania.com - España y América Latina
Portal sobre tecnologías para la seguridad física
- Destacamos »
- software Anti Blanqueo
PR Newswire
MCLEAN, Va. and BEDFORD, Mass., Dec. 16, 2021
MCLEAN, Va. and BEDFORD, Mass., Dec. 16, 2021 /PRNewswire/ -- MITRE Engenuity™, MITRE's tech foundation for public good, today announced the results of the "2021 Managed Services Report: No Rest for the Wary". The research was conducted in collaboration with Cybersecurity Insiders, an online community of 400,000 information security professionals worldwide, to understand the state of affairs in managed services security. The survey of IT security professionals representing organizations of all sizes from industries such as Technology, Healthcare, Retail, Government, Financial, and others set out to discover if organizations are adopting a threat-informed approach to cybersecurity, how they are adopting threat-informed approaches, and what organizations and IT security professionals are doing to improve their confidence in their ability to defend against cyber intrusions.
Are organizations adopting threat-informed defense?
The survey, which polled individuals in IT security and operations across a wide range of industries, found that organizations largely conduct various offensive tests on products and services before and after purchasing them, and actively seek to become threat-informed by utilizing ATT&CK® Evaluation's data. Key findings include:
How are organizations actually doing?
While there appears to be positive results in recognizing the importance of being threat-informed, as well as testing and evaluating products and services before and after investment, the survey found concerning factors relating to utilization of the tools, and challenges hiring and training staff that leads to low confidence in security:
"While many organizations have the intent to operate as threat-informed and do the right things, such as conducting offensive testing, there are still a significant number of organizations that aren't leveraging the data ATT&CK tells us we should look at," said Frank Duff, MITRE Engenuity's general manager, ATT&CK Evaluations. "We have an over-reliance on keeping the adversary out, and we also are limited by hiring and training."
What are organizations doing to improve?
Perhaps recognizing their own limitations in their tools and people, the survey found that there is a commitment to improving who watches the environment. In fact, 68% of respondents report using MSSP/MDR to fill security gaps, however there is still a substantial need for improvement in the trust of MSSP/MDR technology, people, and processes.
"Based on the results of this survey, it is clear that the participants' level of confidence in their managed services is much lower compared to their in-house security people and technology, in which 78% reported feeling confident," added Holger Schulze, CEO, Cybersecurity Insiders.
Something needs to be done to allow organizations to have similar confidence levels in their managed services as they have with their in-house security operations. The need for open, transparent, and threat-informed evaluations for managed services is clear and evident. The MITRE ATT&CK Evaluations for managed services extend the ATT&CK Evaluation program from the technology that enables us to be secure, to the people who are responsible for keeping us secure. The execution of the managed services evaluations will take place in Q2 2022 with the results expected to be released in Q3 2022. The call for participation closing date has been extended to February 25th, 2022.
For a complete overview of the evaluation process, to learn more, or to contact the ATT&CK Evaluations team, visit https://attackevals.mitre-engenuity.org/.
About MITRE Engenuity
MITRE Engenuity, a subsidiary of MITRE, is a tech foundation for the public good. MITRE's mission-driven teams are dedicated to solving problems for a safer world. Through our public-private partnerships and federally funded R&D centers, we work across government and in partnership with industry to tackle challenges to the safety, stability, and well-being of our nation.
MITRE Engenuity brings MITRE's deep technical know-how and systems thinking to the private sector to solve complex challenges that government alone cannot solve. MITRE Engenuity catalyzes the collective R&D strength of the broader U.S. federal government, academia, and private sector to tackle national and global challenges, such as protecting critical infrastructure, creating a resilient semiconductor ecosystem, building a genomics center for public good, accelerating use case innovation in 5G, and democratizing threat-informed cyber defense.
View original content:https://www.prnewswire.com/news-releases/new-research-from-mitre-engenuity-and-cybersecurity-insiders-finds-low-confidence-in-managed-services-security-solutions-301446366.html
SOURCE MITRE Engenuity
Publicamos interesante Informe de más de 48 págs y varios videos demostrativos sobre los posibles ataques a los robots de montaje de las fábricas. ... Leer más ►
Publicado el 22-Jun-2017 • 10.48hs
Publicado el 20-Jun-2017 • 20.22hs
Dirigido tanto a los principiantes, como a los expertos en seguridad informática y sistemas de control industrial (ICS), este libro ayudará a los lectores a comprender mejor la protección de normas de control interno de las amenazas electrónicas. ... Leer más ►
Publicado el 3-Ene-2012 • 20.16hs
Publicado el 25-Set-2009 • 01.26hs
Publicado el 17-Dic-2008 • 08.32hs