
HP Identifies Top Enterprise Security ThreatsAnnual report examines vulnerability and threat landscape, provides actionable security intelligence to protect attack surface
PALO ALTO, Calif. - HP today published the Cyber Risk Report 2013, identifying top enterprise security vulnerabilities and providing analysis of the expanding threat landscape.
Developed by HP Security Research, the annual report provides in-depth data and analysis around the most pressing security issues plaguing enterprises. This year's report details factors that contributed most to the growing attack surface in 2013-increased reliance on mobile devices, proliferation of insecure software and the growing use of Java-and outlines recommendations for organizations to minimize security risk and the overall impact of attacks.
Adversaries today are more adept than ever and are collaborating more effectively to take advantage of vulnerabilities across an ever-expanding attack surface, said Jacob West, chief technology officer, Enterprise Security Products, HP. The industry must band together to proactively share security intelligence and tactics in order to disrupt malicious activities driven by the growing underground marketplace.
Highlights and key findings from the report
While vulnerability research continued to gain attention, the total number of publicly disclosed vulnerabilities decreased by 6 percent year over year,(1) and the number of high-severity vulnerabilities declined for the fourth consecutive year, decreasing by 9 percent.(1) Although unquantifiable, the decline may be an indication as to a surge in vulnerabilities that are not publicly disclosed but rather delivered to the black market for private and/or nefarious consumption.
Nearly 80 percent(2) of applications reviewed contained vulnerabilities rooted outside their source code. Even expertly coded software can be dangerously vulnerable if misconfigured.
Inconsistent and varying definitions of malware complicate risk analysis. In an examination of more than 500,000 mobile applications for Android, HP found major discrepancies between how antivirus engines and mobile platform vendors classify malware.(3)
Forty-six percent(2) of mobile applications studied use encryption improperly. HP research shows that mobile developers often fail to use encryption when storing sensitive data on mobile devices, rely on weak algorithms to do so, or misuse stronger encryption capabilities, rendering them ineffective.
Internet Explorer was the software most targeted by HP Zero Day Initiative (ZDI) vulnerability researchers in 2013, and accounted for more than 50 percent(4) of vulnerabilities acquired by the program. This attention results from market forces focusing researchers on Microsoft vulnerabilities and does not reflect on the overall security of Internet Explorer.
Sandbox bypass vulnerabilities were the most prevalent and damaging for Java users.(2) Adversaries significantly escalated their exploitation of Java by simultaneously targeting multiple known (and zero day) vulnerabilities in combined attacks to compromise specific targets of interest.
Key recommendations
In today's world of rising cyberattacks and growing demands for secure software, it is imperative to eliminate opportunities for unintentionally revealing information that may be beneficial to attackers.
Organizations and developers alike must stay cognizant of security pitfalls in frameworks and other third-party code, particularly for hybrid mobile development platforms. Robust security guidelines must be enacted to protect the integrity of applications and the privacy of users.
While it is impossible to eliminate the attack surface without sacrificing functionality, a combination of the right people, processes and technology does allow organizations to effectively minimize the vulnerabilities surrounding it and dramatically reduce overall risk.
Collaboration and threat intelligence sharing among the security industry helps gain insight into adversary tactics, allowing for more proactive defense, strengthened protections offered in security solutions, and an overall safer environment.
Methodology
HP has published its Cyber Risk Report annually since 2009. HP Security Research leverages a number of internal and external sources to develop the report, including the HP Zero Day Initiative, HP Fortify on Demand security assessments, HP Fortify Software Security Research, ReversingLabs and the National Vulnerability Database. The full methodology is detailed in the report.
Additional information about HP Enterprise Security Products is available at www.hpenterprisesecurity.com.
HP will be addressing the latest trends in enterprise security at the RSA Conference 2014, taking place February 24-28 in San Francisco. Additional information about HP at this year's conference is available here.
HPs premier Americas client event, HP Discover, takes place June 10-12 in Las Vegas.
(1) Cyber Risk Report 2013, HP Security Research, February 2014, p.20-21.
(2) Cyber Risk Report 2013, p. 4-5.
(3) HP Fortify on Demand findings included in the Cyber Risk Report 2013, p. 24.
(4) ZDI data included in the Cyber Risk Report 2013, p. 6.
Java is a registered trademark of Oracle and/or its affiliates. Microsoft is a U.S. registered trademark of the Microsoft group of companies.
This news release contains forward-looking statements that involve risks, uncertainties and assumptions. If such risks or uncertainties materialize or such assumptions prove incorrect, the results of HP and its consolidated subsidiaries could differ materially from those expressed or implied by such forward-looking statements and assumptions. All statements other than statements of historical fact are statements that could be deemed forward-looking statements, including but not limited to statements of the plans
Most recent headlines
05/01/2027
Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be ...
04/08/2026
Dalet, a leading technology and service provider for media-rich organizations, t...
04/07/2026
April 7 2026, 19:00 (PDT) Detective Conan: Fallen Angel of the Highway Opens in...
01/06/2026
January 6 2026, 05:30 (PST) Dolby Sets the New Standard for Premium Entertainment at CES 2026
Throughout the week, Dolby brings to life the latest innovatio...
02/05/2026
Dalet, a leading technology and service provider for media-rich organizations, t...
01/05/2026
January 5 2026, 18:30 (PST) NBCUniversal's Peacock to Be First Streamer to ...
25/04/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
24/04/2026
Churchill Downs Inc. (CDI) has announced a definitive agreement to acquire the intellectual property of the Preakness Stakes and Black-Eyed Susan Stakes from 1/...
24/04/2026
Daktronics has partnered with DCL (Design Communications, Ltd.) to design, manuf...
24/04/2026
Chyron has announced PRIME Translate, a workflow solution that produces live content simultaneously in multiple languages within the PRIME platform. The system ...
24/04/2026
Eutelsat has announced a new partnership with Co-op Cable, introducing an expand...
24/04/2026
Pitch Dublin, an indoor golf simulation and hospitality venue on Dawson Street i...
24/04/2026
G&D and VuWall have announced two senior leadership appointments, effective Apri...
24/04/2026
Victory , the free sports streaming service from A Parent Media Co. Inc. (APMC), has announced a multi-year agreement to become the exclusive local streaming ho...
24/04/2026
The former business major from Massachusetts has found his home in graphics and bug operation while contributing to live ESPN productions
In the live-sports-vi...
24/04/2026
The Mid-Atlantic Sports Network (MASN) and Spectrum have announced a multiyear carriage agreement making MASN available to Spectrum customers in areas of southe...
24/04/2026
The NFL Draft is rebuilt from the ground up in a new city every year. The three-day fan festival is expected to draw 500,000 or more attendees, with millions fo...
24/04/2026
Diversified has continued expansion of its sports and media capabilities to supp...
24/04/2026
NAB reports that the 2026 NAB Show wrapped with more than 58,000 registered atte...
24/04/2026
Clear-Com has announced significant updates to its Arcadia Central Station and E...
24/04/2026
NAB reports that the 2026 NAB Show wrapped with more than 58,000 registered atte...
24/04/2026
Ratings Roundup is a rundown of recent rating news and is derived from press rel...
24/04/2026
B/R NFL Draft Live' refines the digital giant's productions around footb...
24/04/2026
Study highlights five pillars shaping modern fan engagement as broadcasters reth...
24/04/2026
The 2026 event, the first Draft with NFL Network under the ESPN umbrella, will b...
24/04/2026
In-venue and creative video staffers at the professional and collegiate level ha...
24/04/2026
Integral to the Draft production for three almost decades, the company tells the...
24/04/2026
Championing documentaries that illuminate and expand the artform is at the core ...
24/04/2026
The Peabody Awards spotlight excellent work that endures. This year's winner...
24/04/2026
Earth Day is a chance to reflect on our connection to the natural world. To mark the 57th Earth Day on April 22, Spotify's editors have pulled together a co...
24/04/2026
This past weekend, Spotify was at the heart of the largest literary event in the...
24/04/2026
All data tells a story, and in our case, that story is written by you. To celebrate 20 years of Spotify, we're sharing bite sized moments that capture how t...
24/04/2026
Over the past 20 years, Spotify's look and feel has evolved with the way people use our platform, while ensuring we preserve an intuitive, personal, and fam...
24/04/2026
It's been 20 years since Spotify began, but the real story is what the world chose to play. For the first time, we're unveiling the most streamed artist...
24/04/2026
Whether you're relaxing at home or on the go, Spotify is there across more than 2,000 devices, ready with your favorites or something new to discover. Now, ...
24/04/2026
Nintendo and Spotify are welcoming fans to the Super Mario Bros. 40th anniversary and the release of The Super Mario Galaxy Movie with new playlists and a speci...
24/04/2026
30 October - 1 November 2026
The Audio Engineering Society (AES) have announced that the AES Show 2026 will be held on Halloween weekend - Friday 30 October...
24/04/2026
New closed-back design promises honest' low end
Sennheiser have just announced the launch of a new pair of flagship closed-back headphones which they s...
24/04/2026
Powerful 12-channel hardware sequencer announced
Cre8audio are renowned for their innovative, and often visually striking designs, and although their latest...
24/04/2026
Room correction now supports full 9.1.6 Dolby Atmos setups
The software element of IK Multimedia's room-correction system has just received an update th...
24/04/2026
New content for BBO Tutti & BBO Riffs
VSL have recently introduced some new free content expansions for two of their most popular Big Bang Orchestra Packs: ...
24/04/2026
Rohde & Schwarz to highlight its R&S EVSD1000 UAV-based navigation analyzer at I...
24/04/2026
The National Film and Video Foundation (NFVF) is pleased to announce that the ca...
24/04/2026
ITV's Director of Drama Polly Hill has commissioned six part propulsive, lun...
24/04/2026
The NASA 777 aircraft departs the L3Harris facility in Waco, Texas....
24/04/2026
WASHINGTON, April 23, 2026 - L3Harris Technologies (NYSE: LHX) has closed a $1 b...
24/04/2026
In partnership with Airbus U.S. Space & Defense, Inc., L3Harris Technologies is advancing autonomous aviation for the U.S. Marine Corps' Aerial Logistics Co...
24/04/2026
L3Harris' hC2 software, powered by Systematic SitaWare, strengthens battlefield decision-making by using open architectures to connect platforms, sensors an...
24/04/2026
Artist rendering of L3Harris' AERIS X next-generation airborne early warning...
24/04/2026
AgileTV presents in Las Vegas its technological proposition to power safer, more scalable and efficient TV ecosystems for telecom operators, ISPs and entertainm...