Le Lézard
Classified in: Science and technology, Covid-19 virus
Subject: Survey

VMware Releases Cybersecurity Threat Survey Report Detailing Increased Attack Volume and Breach Levels in the United States


VMware, Inc. (NYSE: VMW), a leading innovator in enterprise software, today released the results of its first U.S.-focused cybersecurity threat report, entitled: "Extended Enterprise Under Threat," based on a survey of 250 U.S. CIOs, CTOs and CISOs.

The research found an increase in both cyberattack volume and breaches during the past 12 months in the U.S. This has prompted increased investment in cyber defense, with U.S. businesses already using an average of more than nine different cybersecurity tools, the survey found.

Data for the report was compiled in March and April 2020 by an independent research company, Opinion Matters, on behalf of VMware Carbon Black.

Key survey findings from U.S. respondents:

Common breach causes in U.S.

The most common cause of breaches in the U.S. was OS vulnerabilities (27%). This was jointly followed by web application attacks with 13.5% and ransomware with 13%. Island-hopping was the cause of 5% of breaches.

Rick McElroy, Cyber Security Strategist at VMware Carbon Black, said: "Island-hopping is having an increasing breach impact with 11% of survey respondents citing it as the main cause. In combination with other third-party risks such as third-party apps and the supply chain, it's clear the extended enterprise is under pressure."

Complex multi-technology environments

US cybersecurity professionals said they are using an average of more than nine different tools or consoles to manage their cyber defense program, the survey found. This indicates a security environment that has evolved reactively as security tools have been adopted to tackle emerging threats.

Said McElroy: "Siloed, hard-to-manage environments hand the advantage to attackers from the start. Evidence shows that attackers have the upper hand when security is not an intrinsic feature of the environment. As the cyber threat landscape reaches saturation, it is time for rationalization, strategic thinking and clarity over security deployment."

Supplemental COVID-19 survey in U.S.

The latest research was supplemented with a survey on the impact COVID-19 has had on the attack landscape1. According to the supplemental survey of more than 1,000 respondents from the U.S., UK, Singapore and Italy, 88% of U.S. cybersecurity professionals said attack volumes have increased as more employees work from home. 89% said their organizations have experienced cyberattacks linked to COVID-19 malware.

Key findings from the supplemental U.S. COVID-19-focused survey:

Said McElroy: "The global situation with COVID-19 has put the spotlight on business resilience and disaster recovery planning. Those organizations that have delayed implementing multi-factor authentication appear to be facing challenges, as 32% of U.S. respondents say the inability to implement MFA is the biggest threat to business resilience they are facing right now."

U.S. survey respondents were asked whether COVID-19 had exposed gaps in their disaster recovery plans, and to indicate the severity of those gaps. Their responses showed that:

Said McElroy: "These figures indicate that the surveyed CISOs may be facing difficulty in a number of areas when answering the demands placed on them by the COVID-19 situation."

Risks directly related to COVID-19 have also quickly emerged, the survey found. This includes rises in COVID-19 malware which was seen by 89% of U.S. respondents.

Said McElroy: "The 2020 survey results suggest that security teams must be working in tandem with business leaders to shift the balance of power from attackers to defenders. We must also collaborate with IT teams and work to remove the complexity that's weighing down the current model. By building security intrinsically into the fabric of the enterprise ? across applications, clouds and devices ? teams can significantly reduce the attack surface, gain greater visibility into threats, and understand where security vulnerabilities exist."

Read the full executive summary here.

About VMware's Intrinsic Security Strategy

Security sprawl ? too many products, agents, and interfaces deployed across an organization ? has created complexity for security management, opening organizations to significant risk. Most security innovation over the past decade has focused on identifying and reacting to individual attacks. Little innovation has focused on hardening infrastructure itself to make it more secure or using the infrastructure to better protect an organization.

The way forward is an intrinsic security approach that combines detecting and responding to threats, in addition to hardening infrastructure. VMware makes security intrinsic from endpoint to cloud, leveraging the infrastructure to provide visibility for apps, users and devices, and combining that with leading threat detection and response capabilities to deliver a unique (and better) approach to security.

About VMware

VMware software powers the world's complex digital infrastructure. The company's cloud, app modernization, networking, security, and digital workspace offerings help customers deliver any application on any cloud across any device. Headquartered in Palo Alto, California, VMware is committed to being a force for good, from its breakthrough technology innovations to its global impact. For more information, please visit https://www.vmware.com/company.html

VMware and Carbon Black are registered trademarks or trademarks of VMware, Inc. or its subsidiaries in the United States and other jurisdictions.

Main Survey Methodology

Carbon Black commissioned a survey, undertaken by an independent research organization, Opinion Matters, in March 2020. 3,012 CIOs, CTOs and CISOs, including 250 from the U.S., were surveyed for this global research project across multiple countries including: Australia, Canada, France, Germany, Italy, Japan, The Netherlands, The Nordics, Singapore, Spain, the US and the UK. Companies were from a range of industries including: financial, healthcare, government, retail, manufacturing, food and beverage, oil and gas, professional services, and media and entertainment.

COVID-19 Survey Methodology

1 COVID-19 survey methodology: The COVID-19 survey was conducted by Opinion Matters in March and April 2020. 1002 CIOs, CTOs or CISOs from Italy, Singapore, the UK and the US were asked for their views on the security and operational challenges of COVID-19.


These press releases may also interest you

at 20:40
Rakovina Therapeutics Inc. a biopharmaceutical company committed to advancing new cancer therapies based on novel DNA-damage response technologies announced the financial results for its fourth quarter and fiscal year ending December 31, 2023 and...

at 20:15
The partnership was unveiled internally at the Franchisor's annual convention in Las Vegas, NV in December 2023, eliciting...

at 19:40
ReNAgade Therapeutics, a company unlocking the limitless potential for RNA medicines, today announced its ongoing commitment to exploring the therapeutic opportunity of glycobiology through support for ongoing research at GanNA Bio, and the...

at 18:57
Tribe Property Technologies Inc. (the "Issuer" or the "Company") , a leading provider of technology-elevated property management solutions, today announced that it expects to complete and file its 2023 Annual Filings (as defined below) on or before...

at 18:47
The Korean Cultural Center New York (KCCNY), a branch of the Ministry of Culture, Sports and Tourism of the Republic of Korea, is proud to present a special exhibition "Whanki in New York," from May 2 to June 13, 2024. This exhibition commemorates...

at 18:30
Aspire Health Alliance ("Aspire Health") is a company headquartered in Braintree, Massachusetts, that provides behavioral health services in the community.  Aspire Health experienced a data security incident that may have involved personal and...



News published on and distributed by: