Sony Pixel Power calrec Sony

HP Identifies Top Enterprise Security reats

03/02/2014

HP Identifies Top Enterprise Security ThreatsAnnual report examines vulnerability and threat landscape, provides actionable security intelligence to protect attack surface

PALO ALTO, Calif. - HP today published the Cyber Risk Report 2013, identifying top enterprise security vulnerabilities and providing analysis of the expanding threat landscape.

Developed by HP Security Research, the annual report provides in-depth data and analysis around the most pressing security issues plaguing enterprises. This year's report details factors that contributed most to the growing attack surface in 2013-increased reliance on mobile devices, proliferation of insecure software and the growing use of Java-and outlines recommendations for organizations to minimize security risk and the overall impact of attacks.

Adversaries today are more adept than ever and are collaborating more effectively to take advantage of vulnerabilities across an ever-expanding attack surface, said Jacob West, chief technology officer, Enterprise Security Products, HP. The industry must band together to proactively share security intelligence and tactics in order to disrupt malicious activities driven by the growing underground marketplace.

Highlights and key findings from the report

While vulnerability research continued to gain attention, the total number of publicly disclosed vulnerabilities decreased by 6 percent year over year,(1) and the number of high-severity vulnerabilities declined for the fourth consecutive year, decreasing by 9 percent.(1) Although unquantifiable, the decline may be an indication as to a surge in vulnerabilities that are not publicly disclosed but rather delivered to the black market for private and/or nefarious consumption.

Nearly 80 percent(2) of applications reviewed contained vulnerabilities rooted outside their source code. Even expertly coded software can be dangerously vulnerable if misconfigured.

Inconsistent and varying definitions of malware complicate risk analysis. In an examination of more than 500,000 mobile applications for Android, HP found major discrepancies between how antivirus engines and mobile platform vendors classify malware.(3)

Forty-six percent(2) of mobile applications studied use encryption improperly. HP research shows that mobile developers often fail to use encryption when storing sensitive data on mobile devices, rely on weak algorithms to do so, or misuse stronger encryption capabilities, rendering them ineffective.

Internet Explorer was the software most targeted by HP Zero Day Initiative (ZDI) vulnerability researchers in 2013, and accounted for more than 50 percent(4) of vulnerabilities acquired by the program. This attention results from market forces focusing researchers on Microsoft vulnerabilities and does not reflect on the overall security of Internet Explorer.

Sandbox bypass vulnerabilities were the most prevalent and damaging for Java users.(2) Adversaries significantly escalated their exploitation of Java by simultaneously targeting multiple known (and zero day) vulnerabilities in combined attacks to compromise specific targets of interest.

Key recommendations

In today's world of rising cyberattacks and growing demands for secure software, it is imperative to eliminate opportunities for unintentionally revealing information that may be beneficial to attackers.

Organizations and developers alike must stay cognizant of security pitfalls in frameworks and other third-party code, particularly for hybrid mobile development platforms. Robust security guidelines must be enacted to protect the integrity of applications and the privacy of users.

While it is impossible to eliminate the attack surface without sacrificing functionality, a combination of the right people, processes and technology does allow organizations to effectively minimize the vulnerabilities surrounding it and dramatically reduce overall risk.

Collaboration and threat intelligence sharing among the security industry helps gain insight into adversary tactics, allowing for more proactive defense, strengthened protections offered in security solutions, and an overall safer environment.

Methodology

HP has published its Cyber Risk Report annually since 2009. HP Security Research leverages a number of internal and external sources to develop the report, including the HP Zero Day Initiative, HP Fortify on Demand security assessments, HP Fortify Software Security Research, ReversingLabs and the National Vulnerability Database. The full methodology is detailed in the report.

Additional information about HP Enterprise Security Products is available at www.hpenterprisesecurity.com.

HP will be addressing the latest trends in enterprise security at the RSA Conference 2014, taking place February 24-28 in San Francisco. Additional information about HP at this year's conference is available here.

HPs premier Americas client event, HP Discover, takes place June 10-12 in Las Vegas.

(1) Cyber Risk Report 2013, HP Security Research, February 2014, p.20-21.

(2) Cyber Risk Report 2013, p. 4-5.

(3) HP Fortify on Demand findings included in the Cyber Risk Report 2013, p. 24.

(4) ZDI data included in the Cyber Risk Report 2013, p. 6.

Java is a registered trademark of Oracle and/or its affiliates. Microsoft is a U.S. registered trademark of the Microsoft group of companies.

This news release contains forward-looking statements that involve risks, uncertainties and assumptions. If such risks or uncertainties materialize or such assumptions prove incorrect, the results of HP and its consolidated subsidiaries could differ materially from those expressed or implied by such forward-looking statements and assumptions. All statements other than statements of historical fact are statements that could be deemed forward-looking statements, including but not limited to statements of the plans
LINK: http://www8.hp.com/us/en/hp-news/press-release.html?id=1571359...
See more stories from hp

Most recent headlines

09/11/2025

Dalet Unveils Agentic AI Media Workflows at IBC2025

Dalet today announced a transformative leap forward for media operations: Agentic Artificial Intelligence (AI) that unifies the Dalet ecosystem under one natura...

06/10/2025

France Tlvisions Wins Prestigious 2025 EBU Technology & Innovation Award in Groundbreaking Collaboration with Dalet

France T l visions, France's leading broadcaster, has received the 2025 EBU ...

18/09/2025

DirecTV Adds Three Sports Channels to Its FAST Streaming Offering

DirecTV continues to expand its women's sports offerings by adding Sports Fanatics' and Whoopi Goldberg's Free Ad-Supported Television (FAST) All Wo...

18/09/2025

Fall Football Kicks Off With Native HDR Production, NextGen TV Telecast

WASHINGTON NextGen TV viewers are beginning to see what high dynamic range (HDR) brings to their football enjoyment with the launch of the sport's fall seas...

18/09/2025

FCC Extends Deadline for EEO Audit Replies

WASHINGTON After issuing audit letters seeking Equal Employment Opportunity data from a randomly selected group of TV and radio stations in August, the Federal ...

18/09/2025

Warner Bros. Discovery Signs New Deal with Nielsen

NEW YORK Warner Bros. Discovery and Nielsen have signed a new, long-term, multi-year deal that covers measurement for all Warner Bros. Discovery platforms acros...

18/09/2025

CIMM Launches Startup Program and Innovation Showcase

NEW YORK As part of its ongoing efforts to develop better measurement solutions, the Coalition for Innovative Media Measurement (CIMM) announced the launch of t...

18/09/2025

UPDATED: ABC Takes 'Jimmy Kimmel Live! Off the Air Indefinitely

IRVING, Texas Following threats from the Federal Communications Commission and the announcement that the nations largest station group, Nexstar Media Group, wou...

17/09/2025

Tech Focus: Audio Training, Part 2 - Manufacturers Offer Extensive Online Learning

Tech Focus: Audio Training, Part 2 - Manufacturers Offer Extensive Online Learni...

17/09/2025

Tech Focus: Audio Training, Part 1 - A1 Shortage Remains a Major-League Challenge for Sports Broadcasting

Tech Focus: Audio Training, Part 1 - A1 Shortage Remains a Major-League Challeng...

17/09/2025

Dua Lipa's Service95 Book Club' Goes Live at the New York Public Library

It was the ultimate convergence of pop culture and literary prestige: Last night, Dua Lipa brought her Service95 Book Club podcast to the stage for a special li...

17/09/2025

The Gauge: Mexico August 2025

During August, streaming's share of TV viewing in Mexico showed an increase of 0.4% compared to the previous month, accounting for 25% of TV viewing. Discl...

17/09/2025

Jo Aun Joins FOR-A America as Senior Manager, Product Engineering

CYPRESS, Calif. FOR-A America has named Jo Aun as senior manager of product engineering, a new role responsible for guiding the planning, development and rollou...

17/09/2025

PlayBox Neo and CIS Group Power CazeTV with a seamless Pl...

PlayBox Neo, in partnership with CIS Group, a leading provider of media and broadcast technology solutions, has successfully deployed PlayBox Neo's Dual Cha...

17/09/2025

Energy Regulatory Agency Underscores Commitment with Ene...

In a relationship that mirrors societal advances in sustainability, Brightline Lighting and the Federal Energy Regulatory Commission (FERC) Headquarters have en...

17/09/2025

Clear-Com Powers Star-Studded Communications at Houston A...

Clear-Com is proud to support the world-class productions of Alley Theatre, one of the oldest and largest nonprofit resident theatres in the United States. With...

17/09/2025

Arch Platform Technologies Announces Strategic Collaborat...

Arch Platform Technologies (www.archpt.io), a pioneer in automated, scalable cloud infrastructure for high-performance workflows, today announced a Strategic Co...

17/09/2025

With over 39bn EUR in assets under management and record-...

Over 300 selected decision-makers from start-ups, corporates, and VC funds worldwide will gather for the third edition of the event, united by a single goal: to...

17/09/2025

Telestream Celebrates Award Win at IBC2025

Telestream, a global leader in media workflow technologies, is excited to announce that its flagship Vantage platform and its next-generation AI capabilities re...

17/09/2025

Mediagenix Celebrates Triple Best of Show Wins at IBC2025...

Mediagenix, a global leader in smart content solutions that profitably connect the right content to the right audience, proudly announces its three Best of Show...

17/09/2025

PlayBox Neo Appoints Transtel Universal as Top Reseller P...

In a move to further establish a firm foothold across South East Asia, PlayBox Neo, the well-respected name in broadcast playout and channel branding, has appoi...

17/09/2025

Wisycom Unveils Two New Solutions at IBC 2025

Wisycom, a global leader in advanced wireless audio solutions, announced two major wireless solutions at IBC 2025 (Stand 8.D30). This includes the Portable RF-o...

17/09/2025

Six Berklee Alumni Win Emmy Awards

Six Berklee Alumni Win Emmy Awards The recipients were recognized for their contributions to acclaimed programs Severance, The Studio, The Penguin, SNL50: The...

17/09/2025

Applications Open for Berklee in Santo Domingo

Applications Open for Berklee in Santo Domingo The weeklong contemporary music program will run January 5-10, 2026. By Colette Greenstein September 17, 2025 ...

17/09/2025

Ukrainian Students Find Creative Consonance' at Berklee Valencia

Ukrainian Students Find Creative Consonance' at Berklee Valencia Through ELIA's UAx Platform, six students from Kyiv joined Berklee Valencia for a week...

17/09/2025

Meet Kenna Hilburn, Avids New Incoming Chief Product Officer

Earlier this year Avid announced Kenna Hilburn as its new senior vice president of product. Recently Hilburn was promoted to Avids new Chief Product Officer, su...

17/09/2025

SES and K2 Space to Accelerate Development of Next-Generation MEO Network

Transatlantic collaboration combines experience and agility to drive innovation in network design and delivery Luxembourg, September 16, 2025 - SES, a leading ...

17/09/2025

Fox TV Stations Join Madhive's Local Live Sports Marketplace

NEW YORK Madhive has announced that the Fox Television Stations have joined its Live Sports Marketplace....

17/09/2025

Sony Electronics Partners with Newhouse School at Syracuse University

SYRACUSE, N.Y. Sony Electronics has announced that it is partnering with the Newhouse School at Syracuse University to provide state-of-the-art equipment, hands...

17/09/2025

Roku's First TV Smart Projector Now Available in the U.S.

SAN JOSE, Calif. Roku has announced that the first smart projector using its Roku TV operating system, the Aurzen Roku TV Smart Projector D1R Cube, is now avail...

17/09/2025

Meet the Streamlabs Streaming Assistant, Accelerated by NVIDIA RTX

Today's creators are equal parts entertainer, producer and gamer, juggling game commentary, scene changes, replay clips, chat moderation and technical troub...

17/09/2025

Portrait Artist of the Year returns to Sky Arts with a dazzling line-up of celebrity sitters on 1 October

Wednesday 17 September 2025 UK artists capture icons of stage and screen, inclu...

17/09/2025

FOR-A America Appoints Jo Aun to Lead U.S. Product Development

Jo Returns to FOR-A as Senior Manager of Product Management and Engineering...

17/09/2025

AIR's Big Comeback with DPA Microphones

For the Moon Safari anniversary tour, AIR opened the doors to their backstage. Just a few hours before the Paris concert, DPA met with two key figures of the te...

17/09/2025

The Late Late Toy Show hits the road in search of Ireland's brightest young stars

Auditions will be held in Dublin, Cork and Galway The County Parade returns f...

16/09/2025

SVG All-Stars: Leigh Michaud, Manager, Remote Operations, ESPN

SVG All-Stars: Leigh Michaud, Manager, Remote Operations, ESPNThe UConn grad rose from ESPN's mailroom to become one of its most valuable ops leadersBy Bran...

16/09/2025

Live From IBC 2025: Friday's Latest From Halls 1-4, Outdoor Exhibits in Amsterdam

Live From IBC 2025: Friday's Latest From Halls 1-4, Outdoor Exhibits in Amst...

16/09/2025

Live From IBC 2025: Saturday's Latest From Halls 5-7 in Amsterdam

Live From IBC 2025: Saturday's Latest From Halls 5-7 in Amsterdam By SVG Staff Friday, September 12, 2025 - 17:00 Print This Story The SVG Europe and ...

16/09/2025

Live From IBC 2025: Sunday's Latest From Halls 8-10 in Amsterdam

Live From IBC 2025: Sunday's Latest From Halls 8-10 in Amsterdam By SVG Staff Saturday, September 13, 2025 - 17:00 Print This Story The SVG Europe and...

16/09/2025

Live From IBC 2025: Monday's Latest From Halls 11-14 in Amsterdam

Live From IBC 2025: Monday's Latest From Halls 11-14 in Amsterdam By SVG Staff Sunday, September 14, 2025 - 17:00 Print This Story The SVG Europe and ...

16/09/2025

Amazon Prime Video Picks Up Four Hours of Early-Round Masters Coverage in 2026

Amazon Prime Video Picks Up Four Hours of Early-Round Masters Coverage in 2026 By Jason Dachman, Editorial Director, U.S. Tuesday, September 16, 2025 - 10:15...

16/09/2025

VERSANT Inks Deal for League One Volleyball as Women's Sports Rights Slate Grows

VERSANT Inks Deal for League One Volleyball as Women's Sports Rights Slate G...

16/09/2025

ESPN VP, Corporate Communications, Katina Arnold Named SVP, Disney Advertising Communications

ESPN VP, Corporate Communications, Katina Arnold Named SVP, Disney Advertising C...

16/09/2025

IBC 2025 in Review: SVG Europe's Full Collection of Video Interviews From the Show Floor

IBC 2025 in Review: SVG Europe's Full Collection of Video Interviews From th...

16/09/2025

Celebramos 10 aos de Viva Latino en Spotify y el xito global de la msica latina

Hace una d cada, la m sica latina representaba apenas el 8% de las reproducciones globales en Spotify. Hoy, constituye m s de una cuarta parte (27%) de toda la ...

16/09/2025

Celebrating 10 Years of Spotify's Viva Latino Playlist and the Global Rise of Latin Music

A decade ago, Latin music made up just 8% of global Spotify streams. Today, it a...

16/09/2025

Spotify Welcomes Graham Norton and Select VICE Studios Content

Spotify is expanding our video lineup with a new partnership with Zoo 55, part of ITV Studios. For the first time, acclaimed content from ITV Studios is landing...

16/09/2025

One Enterprise, One Mission: Aligning the Supply Chain to the Warfighter

At DSEI 2025, James Dunne of L3Harris Maritime UK chaired a panel on aligning the supply chain to the warfighter, where leaders discussed modernising support fo...

16/09/2025

RTW chooses Calrec as technology partner

Calrec has strengthened its collaboration with audio metering expert RTW by integrating RTW's new TMxCore metering platform across its full range of Argo IP...

16/09/2025

Football and Back-to-School Dynamics Spark First Gains Since April for Traditional TV

College Football Scores Top Telecast in August with 16M+ Viewers on FOX, Followe...