gohiam.com

The Cybersecurity Storm: Non-Human Identities and Manufacturing Vulnerabilities

October 3, 2024, 3:54 pm
Depositphotos
Depositphotos
AgencyCommerceContentMarketplaceMusicOnlinePlatformServiceVideoWeb
Location: United States, New York
Employees: 201-500
Founded date: 2009
Total raised: $5M
In the digital age, shadows lurk where we least expect them. Non-human identities (NHIs) and critical vulnerabilities in manufacturing are two storm clouds gathering on the cybersecurity horizon. As organizations embrace technology, they also invite risks. The latest reports reveal alarming trends that could spell disaster for unprepared enterprises.

A recent study by AppViewX paints a stark picture. It reveals that 66 percent of enterprises have faced successful cyberattacks linked to compromised NHIs. These digital entities, often overlooked, represent a significant attack surface. They are the unseen hands that can unlock doors to sensitive data and disrupt operations. The report surveyed nearly 370 IT, cybersecurity, and DevOps professionals, highlighting a growing concern that cannot be ignored.

The findings are sobering. Organizations now manage 20 times more NHIs than human identities. This number is expected to swell by over 20 percent in the coming year. As NHIs proliferate, so do the risks. Nearly 46 percent of organizations have reported breaches tied to these identities, averaging 2.7 incidents per enterprise in the past year. The stakes are high, and the boardrooms are taking notice. Over 80 percent of organizations plan to ramp up spending on NHI security.

Why the urgency? The complexity of modern cloud environments makes manual management of NHIs a Herculean task. Digital transformation, AI, and cloud-first initiatives are pushing these identities to near-exponential growth. Without proper management, NHIs can lead to costly data breaches and compliance failures. The call for automated solutions is loud and clear. Automated certificate lifecycle management and crypto-agility are essential to avoid security lapses and reduce exposure to cyber threats.

Meanwhile, the manufacturing sector is grappling with its own set of vulnerabilities. A report from Black Kite reveals that 80 percent of manufacturing companies harbor critical vulnerabilities. This sector, vital to the economy, is a prime target for cybercriminals. The study analyzed 5,000 manufacturing companies, uncovering that 69 percent had exposed credentials in the last 90 days. The digital footprint of these organizations is expanding, creating a weak link in their defenses.

Manufacturers have invested heavily in protecting physical and operational technology. Yet, their digital vulnerabilities remain a gaping hole. The report highlights that 67 percent of companies have vulnerabilities listed in the CISA known exploited vulnerabilities (KEV) catalog. Additionally, 62 percent are grappling with broken crypto algorithms. Despite good application security practices, 30 percent of companies still have critical vulnerabilities in web applications, leaving them open to exploitation.

Patch management is another area of concern. A staggering 94 percent of companies in the furniture and related product manufacturing sub-industry received a D or F in patch management. This means that most of their assets are running outdated or vulnerable products. The machines integral to production processes cannot be easily updated without risking operational disruptions. However, this does not excuse exposing these systems to the internet, where they become easy prey for cyberattacks.

The implications are dire. Every sub-industry in manufacturing examined has an average Ransomware Susceptibility Index (RSI) score of 0.4 or greater, placing them in the critical category. This means they are 3.4 times more likely to experience a ransomware attack. The risk is even higher in specific subcategories. Over 60 percent of companies in chemical manufacturing and transportation and equipment manufacturing fall into this critical category.

The cybersecurity landscape is evolving, and organizations must adapt. The convergence of NHIs and manufacturing vulnerabilities creates a perfect storm. As digital identities multiply, so do the attack vectors. The time for complacency is over. Organizations must fortify their defenses and embrace automated solutions to manage NHIs effectively.

The reports from AppViewX and Black Kite serve as wake-up calls. They underscore the urgency of addressing these vulnerabilities before they escalate into full-blown crises. Cybersecurity is not just an IT issue; it’s a business imperative. The boardrooms must prioritize these risks and allocate resources accordingly.

In conclusion, the cybersecurity storm is brewing. Non-human identities and manufacturing vulnerabilities are two sides of the same coin. Organizations must recognize the interconnectedness of these issues and take proactive measures. The future of cybersecurity depends on it. As the digital landscape continues to evolve, so must our strategies to protect it. The time to act is now.