• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
Cyber Security News

Rapid7 Has Good News for UK Security Posture

You are here: Home / General Cyber Security News / Rapid7 Has Good News for UK Security Posture
April 13, 2023

The UK’s biggest community organizations have reduced publicity to superior-risk ports and increased email security over the previous two years, despite the fact that some corporations are still inviting too much cyber risk, according to Swift7.

The security vendor appraised the FTSE 350 in 3 spots for its new report, to supply a snapshot of the UK’s attack floor as of March 2023.

The resulting findings, outlined in The FTSE 350 Cyber Attack Area report, display important improvements from Rapid7’s 2021 Market Cyber-Exposure Report – putting UK corporations on a par with their world friends investing on the ASX 200 and the Fortune 500.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


For a single, a reasonably tiny quantity of UK organizations are exposing their group by way of significant-risk ports these types of as FTP, SSH, Telnet, RDP and SMB.

Just about two-thirds (37%) expose at most a single higher-risk port and around a fifth (21%) expose none at all. However, the monetary companies sector is a little something of an outlier, with an ordinary of just about 12 uncovered large-risk ports for every corporation.

“RDP and SSH are routinely exposed to the internet for distant administration, but the degree of publicity for an average enterprise listed here ought to motivate monetary services businesses to examine their external attack surface,” the report observed.

“Compared to 2021, nonetheless, the attack area of the FTSE 350 is tremendously enhanced. The trends specially in supplies, utilities, and wellbeing care are encouraging, where by each and every of individuals industries is exposing only SSH and RDP in very compact quantities.”

Go through a lot more on UK security risks: MI6 Manager: Digital Attack Floor Escalating “Exponentially”

Rapid7 also saw enhancements with deployment of DMARC to mitigate spoofing email attacks. The variety of FTSE 350 corporations with a legitimate plan has risen from 191 in 2021 to 247 these days, with the vast majority favoring a quarantine or reject plan.

Nonetheless, it warned that implementation of DNS Security extensions (DNSSEC) is still lousy, even though in line with worldwide peers. Just 4% of FTSE 350 companies are encouraging to lower their publicity to DNS attacks in this way.

Lastly, the report uncovered that the wide majority of IIS (80%) and Apache (89%) web servers have been running supported variations, while the figure fell to 30% for the fewer well-known Nginx servers.

When the success paint a beneficial picture of UK PLC’s attack surface, continued caution is needed, Speedy7 stated.

“Remember that security is a transferring goal – even though numerous of these corporations have their risk beneath handle currently, a new risk or even the initiation of a new information and facts technology approach tomorrow can entirely transform the landscape of a enterprise,” the report concluded.

“These issues will have to be tracked on an ongoing basis.”


Some parts of this write-up are sourced from:
www.infosecurity-journal.com

Previous Post: «chatgpt security: openai's bug bounty program offers up to $20,000 ChatGPT Security: OpenAI’s Bug Bounty Program Offers Up to $20,000 Prizes
Next Post: Lazarus Hacker Group Evolves Tactics, Tools, and Targets in DeathNote Campaign lazarus hacker group evolves tactics, tools, and targets in deathnote»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.