report – Digital IT News https://digitalitnews.com IT news, trends and viewpoints for a digital world Fri, 24 Sep 2021 21:49:55 +0000 en-US hourly 1 https://wordpress.org/?v=5.4.15 PC Matic Survey: 20% of Employers Never Require Employees to Change Passwords https://digitalitnews.com/pc-matic-survey-20-of-employers-never-require-employees-to-change-passwords/ Tue, 08 Jun 2021 20:52:45 +0000 https://digitalitnews.com/?p=4213 PC Matic, announced the release of its third annual report analyzing users and their password habits and hygiene. The report found that nearly 30% of Americans aren’t sure when they last changed their passwords, or never have at all. The survey also revealed lax corporate passwords, finding that nearly a fifth of employers nationwide never [...]

The post PC Matic Survey: 20% of Employers Never Require Employees to Change Passwords appeared first on Digital IT News.

]]>
PC Matic, announced the release of its third annual report analyzing users and their password habits and hygiene. The report found that nearly 30% of Americans aren’t sure when they last changed their passwords, or never have at all. The survey also revealed lax corporate passwords, finding that nearly a fifth of employers nationwide never require their employees to change their passwords.

The sixteen-page report presents the results of a nationally distributed survey by which 2,500 Americans were asked about their password behaviors and tendencies. The findings, fielded in May 2021, found that nearly 30% of Americans aren’t sure when they last changed their passwords, or never have at all. The survey also revealed lax corporate password policies, finding that nearly a fifth of employers nationwide never require their employees to change their passwords.

More key findings from the report are as follows:

  • Nearly 60% of those surveys responded that they have never changed their home Wi-Fi password, or that it hasn’t been changed since setup. In 2020, 50% of those surveys responded in this same manner.

  • 40% of respondents indicated that they are using the password lockout feature on both their work and home computers. This number is up from 25% responding that they used this feature in 2020’s survey results.

  • Just shy of 45% of employers don’t require their employees to utilize a Virtual Private Network (VPN). 2020’s survey results showed just a slightly higher number of respondent’s employers requiring a VPN, with 46% affirming they were required to use the security tool.

  • More than 50% of respondents admit to checking personal e-mail accounts at work. This number remains virtually unchanged from 2020’s survey results, and still presents an imminent threat to corporate networks.

 

“As employees’ transition from work-from-home to in-office work environments again, it is the perfect time implement password policies and procedures that can keep employees and corporate networks safe,” said Rob Cheng, CEO and Founder of PC Matic. “The 2021 Password Habits and Hygiene Report aimed to understand the policies and procedures being implemented and abided by users across the nation and provides further insight into how corporate IT professionals can protect networks from cybercriminals.”

More findings and the complete report may be found here.

Image licensed by: Pixabay.com

Related News:

Cisco Flexes Its Muscle in Cloud: Helping Customers Be Cloud Smart to Deliver Exceptional Digital Experiences

New Mandiant Services Help Organizations Balance Effective Cyber Security and Business Risk

The post PC Matic Survey: 20% of Employers Never Require Employees to Change Passwords appeared first on Digital IT News.

]]>
BlueVoyant Report Reveals Ransomware is the Number One Cyber Threat facing Higher Education https://digitalitnews.com/bluevoyant-report-reveals-ransomware-is-the-number-one-cyber-threat-facing-higher-education/ Tue, 23 Feb 2021 19:08:34 +0000 https://digitalitnews.com/?p=3669 COVID-19 has forced the higher education sector to rapidly transition to remote learning. This report delivers insights into the growing threat landscape of ransomware, credential breaches and other online threats facing universities and colleges. BlueVoyant, a cybersecurity services company, today announced the findings from its Cybersecurity in Higher Education report. Using open source data and proprietary [...]

The post BlueVoyant Report Reveals Ransomware is the Number One Cyber Threat facing Higher Education appeared first on Digital IT News.

]]>
COVID-19 has forced the higher education sector to rapidly transition to remote learning. This report delivers insights into the growing threat landscape of ransomware, credential breaches and other online threats facing universities and colleges.

BlueVoyant, a cybersecurity services company, today announced the findings from its Cybersecurity in Higher Education report. Using open source data and proprietary research, BlueVoyant analyzed 2702 universities across 43 countries, revealing that ransomware attacks against universities increased by 100% between 2019 and 2020, and are the number one cyber threat—with the average cost of a ransomware attack totaling $447,000. Additionally, tactics seen in other industries—such as holding organizations to ransom for larger sums of money—were also observed amongst attacks on higher education institutions.

In the wake of COVID-19, the higher education sector is experiencing unprecedented change. Not only are universities embracing, or wrestling with, a host of new technologies and teaching methods—they’re also using a variety of apps, portals, and remote teaching technologies to support online or blended learning environments, which exponentially increase their vulnerability to a cybersecurity breach. As the nature of the classroom and the student experience evolves, universities face new challenges, new demands, and new risks which underscore the critical need to secure their proprietary data sources and to be properly positioned to withstand the growing threat landscape of cybersecurity breaches.

The report outlines the current threat landscape for the higher education sector and, delivers insights about the growing threat of ransomware attacks, the outsized impact of credential breaches, and the broader consequences for schools in the form of credential stuffing attacks. The research also outlines a concerning prevalence of high-risk vulnerabilities in the sector, which require remediation, including using multi-factor authentication, password policy mandates, monitoring anomalies and password screening.  

Key findings from the report include:

  • Ransomware is the number one threat facing universities—ransomware events doubled from 2019 to 2020.
  • The average cost of a ransomware attack in higher education in 2020 was $447,000.
  • Data breaches were the number two threat facing universities, making up half of all events in 2019.
  • Data theft by nation states is a regular occurrence, affecting over 200 universities in the past two years.
  • University credential lists are massive and heavily trafficked in dark web markets, underpinning a huge volume of threats targeting accounts and vulnerable websites.
  • Passwords are easily compromised due to the prevalence of simple passwords and password reuse.
  • Threats have magnified, due to increasing reliance on mobile devices, the move to remote learning, and third-party education partners—expanding the higher education attack surface.

Common vulnerabilities identified in the sector are:

  • Two thirds (66%) of all analyzed universities and colleges lacked all basic email security configurations, which left these institutions exposed to phishing attacks.
  • Over three quarters of all analyzed universities and colleges had open or unsecured remote desktop ports. Open remote desktop protocol (RDP) ports are the number two threat vector—behind phishing—or ransomware gangs.
  • 86% of all observed universities and colleges showed evidence of inbound botnet targeting. The rise of botnet activity over the past year has prominently featured in the news.

Key adversary tactics commonly deployed against education sector targets included:

Credential stuffing: whereby account credentials, typically consisting of lists of usernames and/or email addresses and the corresponding passwords, are used to gain unauthorized access to user accounts through large-scale automated login attempts.

Brute-Forcing: when an attacker systematically submits many passwords or passphrases with the hope of eventually guessing correctly. The attacker checks all possible passwords and passphrases until the correct one is found.

Dehashing/Cracking: the process of recovering passwords from data that has been stored in an unsalted hashed form. Hashes are scrambled versions of passwords that services use to enhance security practices, however, hashing is not equivalent to cryptography and many hashes can be ‘cracked’ or guessed.

Commenting on the research, Jim Penrose, COO, BlueVoyant said: “As the nature of teaching and the student experience changes in response to COVID-19, universities and higher education establishments face new challenges, demands and risks. The attack surface has exponentially increased as organizations in this sector move to remote learning and face unique privacy and cyber risks. This is due to the combination of the sensitive data they manage and the nature of how technology is deployed, combined with growing regulations facing this sector.”

“The good news is that many of these issues can be easily rectified with the introduction of cybersecurity technologies, policies and user education. This includes multi-factor authentication (MFA) and long password policies, combined with the ability to block password reuse and simple passwords, and password screening. By combining long passwords with MFA and screening, the chance of being breached through brute force or credential stuffing attacks is considerably reduced.”

In addition to the broad scope analysis, BlueVoyant has also provided insights on a smaller pool of 30 universities. This in-depth analysis looked for distinct patterns and trends to identify vulnerabilities that matched the known threat vectors and risks. Analysis showed that torrenting (a popular method of sharing large files online) and gaming were being widely used, and highlighted the scale of credentials data commonly available.


Jim Rosenthal, co-founder and CEO, BlueVoyant, concludes: “This is an industry that has had to rapidly pivot to online learning, changing their standard methods of learning, practically overnight. The education sector is also under huge financial and regulatory pressure. Threat actors know that there are vulnerabilities to be exploited and they are taking advantage of these vulnerabilities at every opportunity—making it an imperative for universities to adopt a solid cybersecurity threat posture to ensure that the wealth of sensitive data is properly defended against adversaries.”

Image Licensed by Pixabay.com

Related News: 

Veristor Builds on Cloudian Partnership to Power Storage Managed Services with Greater Efficiency and Scale

IGEL Brings EUC Professionals Together for the Digital DISRUPT Unite Cloud Workspaces Experience, February 25, 2021

The post BlueVoyant Report Reveals Ransomware is the Number One Cyber Threat facing Higher Education appeared first on Digital IT News.

]]>