• About
  • Subscribe
  • Contact
Wednesday, July 23, 2025
    Login
FutureCISO
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
No Result
View All Result
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
No Result
View All Result
FutureCISO
No Result
View All Result
Home Process Compliance and Governance

Unpatched vulnerabilities rank high in cybersecurity risks

FutureCISO Editors by FutureCISO Editors
July 23, 2025
Unpatched vulnerabilities rank high in cybersecurity risks

Photo by Jorge Jesus: https://www.pexels.com/photo/computer-program-language-text-614117/

Share on FacebookShare on Twitter

The Ponemon Institute report, "2024 State of Enterprise Cyber Risk in the Age of AI" sheds light on the evolving landscape of cybersecurity challenges faced by enterprises. The report highlights pressing concerns that keep cybersecurity professionals awake at night.

The report outlines that many organisations struggle to keep pace with the rapidly changing requirements of cyber risk strategies. Notably, unpatched vulnerabilities have emerged as a primary concern, exacerbated by the growing reliance on AI tools.

While AI has become a pivotal asset in prioritising threats and vulnerabilities, nearly half of the surveyed organisations expressed worry over vulnerabilities stemming from AI-generated code.

This dual role of AI—as both a defender and a potential threat—has led to a critical need for organisations to reassess their security postures.

The first key finding is that organisations must revert to the basics when managing AI-generated vulnerabilities. The speed at which AI can produce code may inadvertently increase the number of vulnerabilities.

Rather than fixate on the generation of these vulnerabilities, firms should establish robust systems for identification and remediation, prioritising vulnerabilities based on their organisational context.

The second significant issue identified is the persistence of unpatched vulnerabilities, which remain the top concern for security professionals. Misconfigurations and end-of-life (EOL) software compound this challenge, with inadequate vulnerability scanning practices observed across the board.

Alarmingly, half of the organisations conduct vulnerability scans for Common Vulnerabilities and Exposures (CVEs) only once a week or less. Given that attackers can exploit vulnerabilities within days, this infrequent scanning leaves organisations at a considerable disadvantage.

Finally, the report reveals a widening gap between the concerns of security teams and the priorities of executive leadership. While security professionals recognise the potential business impact of vulnerabilities, 87% of CISOs and CSOs lack responsibility for defining metrics in their cyber risk management strategies.

Related:  Cybersecurity remains resilient amid declining TMT deal activity in 2023

Reports are often perceived as unengaging by executives, highlighting the need for improved communication. Translating cyber risk into monetary terms could make these issues resonate more with leadership, thereby enhancing the relevance of cybersecurity reporting.

As organisations navigate the complexities of AI-driven cybersecurity threats, addressing unpatched vulnerabilities and improving communication with executive teams will be vital steps in strengthening overall cyber resilience.

Tags: BalbixCVEcyber risksmisconfigurationPonemon Institute
FutureCISO Editors

FutureCISO Editors

No Result
View All Result

Recent Posts

  • Unpatched vulnerabilities rank high in cybersecurity risks
  • Study claims MSPs essential to cyber resilience
  • Modernised access management boosts Panasonic cyber resilience
  • AI-powered defence:  Pioneering a new era in enterprise security
  • Local expertise fuels Thailand’s cybersecurity agenda

Categories

  • Blogs
  • Compliance and Governance
  • Culture and Behaviour
  • Cybersecurity careers
  • Data Protection
  • Endpoint Security
  • Incident Response
  • Network Security
  • People
  • Process
  • Resources
  • Risk Management
  • Technology
  • Training and awarenes
  • Videos
  • Webinars and PodChats
  • White Papers

Strategic Insights for Chief Information Officers

FutureCISO serves the interests of the Chief Information Security Officer (CISO) and the information security profession. Its purpose is to provide relevant and timely industry insights around all things important to security professionals and organisations that recognize and value the importance of protecting the organisation’s data and its customers’ privacy.

Cxociety Media Brands

  • FutureIoT
  • FutureCFO
  • FutureCIO

Categories

  • Privacy Policy
  • Terms of Use
  • Cookie Policy

Copyright © 2024 Cxociety Pte Ltd | Designed by Pixl

Login to your account below

or

Not a member yet? Register here

Forgotten Password?

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
Login

Copyright © 2024 Cxociety Pte Ltd | Designed by Pixl