Endpoint //

Authentication

4/16/2018
03:00 PM
50%
50%

Companies Still Suffering From Poor Credential Hygiene: New Report

Credentials are being mis-handled and it's hurting most companies, according to a new report out today.

A new report, the 2018 Privileged Access Threat Report from Bomgar, contains cause for worry for those who care about IT security since its numbers carry the clear message that, when it comes to keeping up with identities, most companies are getting it wrong.

According to the survey of more than 1,000 IT professionals with ties to system access, half of companies polled say that they either have had a serious breach or expect one within the next six months. Of those giving a positive response to the breach question, roughly two-thirds pin the blame on mis-used credentials.

Blame for this credential abuse falls on two large points: employee mis-use, and mis-use by trusted third parties. Third parties come in for most of the scrutiny, but it's clear that employees are far from off the hook.

Poor password hygiene, from writing down passwords (mentioned by 65% of organizations) to telling co-workers your password (54% of organizations) continues to vex companies.

As for the third parties, the credential problem seems to point to a larger company culture issue: 73% of those responding say that their companies are too reliant on third parties for critical work, while 72% say that they are simply too trusting of their third party vendors.

For more, read here.

Interop ITX 2018

Join Dark Reading LIVE for two cybersecurity summits at Interop ITX. Learn from the industry’s most knowledgeable IT security experts. Check out the security track here. Register with Promo Code DR200 and save $200.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
How Cybercriminals Clean Their Dirty Money
Alexon Bell, Global Head of AML & Compliance, Quantexa,  1/22/2019
Facebook Shuts Hundreds of Russia-Linked Pages, Accounts for Disinformation
Sara Peters, Senior Editor at Dark Reading,  1/17/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
The Year in Security 2018
This Dark Reading Tech Digest explores the biggest news stories of 2018 that shaped the cybersecurity landscape.
Flash Poll
New Best Practices for Secure App Development
New Best Practices for Secure App Development
The transition from DevOps to SecDevOps is combining with the move toward cloud computing to create new challenges - and new opportunities - for the information security team. Download this report, to learn about the new best practices for secure application development.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-1637
PUBLISHED: 2019-01-23
A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software improperly validates Advanced Recording Fo...
CVE-2019-1638
PUBLISHED: 2019-01-23
A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software improperly validates Advanced Recording Fo...
CVE-2019-1639
PUBLISHED: 2019-01-23
A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software improperly validates Advanced Recording Fo...
CVE-2019-1640
PUBLISHED: 2019-01-23
A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software improperly validates Advanced Recording Fo...
CVE-2019-1641
PUBLISHED: 2019-01-23
A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software improperly validates Advanced Recording Fo...