{"id":35866,"date":"2019-07-19T08:31:13","date_gmt":"2019-07-19T00:31:13","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=35866"},"modified":"2019-07-19T08:32:09","modified_gmt":"2019-07-19T00:32:09","slug":"how-to-prevent-data-breaches-patch-now-or-pay-later","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2019\/07\/19\/how-to-prevent-data-breaches-patch-now-or-pay-later\/","title":{"rendered":"How to prevent data breaches: Patch now or pay later"},"content":{"rendered":"<p><strong><i>By Taylor Armerding, Security Expert at Synopsys Software Integrity Group<\/i><\/strong><\/p>\n<p>It\u2019s a pretty good bet that if a car dealership posted an ad announcing that the criminal underground was selling keys that could unlock owners\u2019 vehicles, but that it was offering free replacement locks that wouldn\u2019t be vulnerable, the responses would be quick and universal.<\/p>\n<p>Apparently, we\u2019re not quite there when it comes to software. <a href=\"https:\/\/click.mlsend.com\/link\/c\/YT0xMjAzMTU4NjE1NTI4MDQ4OTIzJmM9ejRjMiZlPTE5MjgmYj0yNjQ1MDAwOTYmZD1xMW43YjNv.xGsKn_84CY-G8sCTETu3r2sGElB83YEtBgfXw89cVXk\">A recent survey<\/a> of 340 information security professionals found that 27% of organisations worldwide acknowledged that they had been breached because of unpatched vulnerabilities.<\/p>\n<p><b>Organisations still ignoring patches<\/b><\/p>\n<p>That should be no surprise. The ever-lengthening list of headlines about breaches \u2014 some catastrophic like the SingHealth cyberattack in Singapore \u2014 reflect the reality that organisations still ignore patches for publicly reported vulnerabilities.<\/p>\n<p>There is, of course, more than one way to view those statistics. \u201cOnly\u201d one in four might sound like a positive \u2014 that means 75% weren\u2019t breached. But most people\u2019s expectation for physical security would be more like one chance in several hundred that a thief could defeat their home security system.<\/p>\n<p>And keep in mind that these aren\u2019t <a href=\"https:\/\/click.mlsend.com\/link\/c\/YT0xMjAzMTU4NjE1NTI4MDQ4OTIzJmM9ejRjMiZlPTE5MjgmYj0yNjQ1MDAwOTgmZD1tNW42cTly.jp0VLQ6jUkAfCsS-JuPjV4B0V_hNHZDoc4e9lLBbTqM\">\u201czero-day\u201d vulnerabilities<\/a> that haven\u2019t been seen before \u2014 these are known bugs or flaws, with patches available. The victims simply failed to apply the available patches.<\/p>\n<p><b>Why can\u2019t organisations prevent data breaches?<\/b><\/p>\n<p>The report also offers plenty of reasons why organisations are vulnerable.<\/p>\n<p>\u2022While 59% of respondents said they could detect new hardware or software added to their network within minutes or hours, 31% said it would take days, weeks or even months. Another 11% said they couldn\u2019t detect it at all.<\/p>\n<p>\u2022More than a third (35%) said they used automatic discovery solutions on less than half of their software and hardware assets. Another 13% said they didn\u2019t use automatic discovery at all.<\/p>\n<p>\u2022While a large majority reported doing some kind of vulnerability scanning, 39% said they did it monthly or less often than that.<\/p>\n<p>\u2022A large majority (74%) reported that they fixed vulnerabilities in a month or less, but that still leaves the \u201cone-in-four\u201d that don\u2019t. And while about half reported applying patches in two weeks or less, that means the other half don\u2019t.<\/p>\n<p>\u2022For creators and vendors of software products, the survey also came with a warning. A majority of respondents said their organisations would, in some cases, stop using a product because of vulnerabilities. Few \u2014 only 6% \u2014 said they did it frequently, but another 31% said they did it occasionally and 44% said while it was rare, it happens. And 82% said a patch for a disclosed vulnerability should be available within two weeks or less.<\/p>\n<p><b>Patching is fundamental<\/b><\/p>\n<p>Why is rigorous patching \u2014 a fundamental of good security \u2014 not close to 100%? That is the multi-million-dollar question. According to an IBM study, the average cost of a data breach last year was $3.86 million.<\/p>\n<p>Indeed, breaches are costly in multiple ways. Among the potential damages are loss of reputation, a drop in market value, compliance fines and legal liability. While most companies survive them, they can be an existential threat.<\/p>\n<p>The irony is that it doesn\u2019t have to be this way. While bulletproof security is impossible, organisations are not defenceless. There are multiple tools and other measures available that can improve the security of networks, applications and systems enough to prompt all but the most expert and motivated hackers to look for easier targets.<\/p>\n<p><b>How to prevent data breaches<\/b><\/p>\n<p>Doing that comes down to two fundamentals:<\/p>\n<p>First, application vendors need to build security into the software of their products before they ever hit the market. It won\u2019t be perfect, but it can come close. And in application security, unlike in most sports, close matters.<\/p>\n<p>Second, organisations that use software \u2014 and all of them do \u2014 need to know what they have, and keep it up to date. As has now become a clich\u00e9 (because it is true), you can\u2019t protect what you don\u2019t even know you have.<\/p>\n<p><b>Prevent data breaches by shifting left<\/b><\/p>\n<p>The template for how to do the first is now well established. It is preached from the podiums of every security conference. The universal expression is \u201cshift left,\u201d which means conducting security testing from the beginning and throughout the <a href=\"https:\/\/click.mlsend.com\/link\/c\/YT0xMjAzMTU4NjE1NTI4MDQ4OTIzJmM9ejRjMiZlPTE5MjgmYj0yNjQ1MDAxMDAmZD1mOWc0ejRu.oUl58DsAIduBzLlU3sFKUguaUMKzvpt27xa80xI14_o\">software development life cycle (SDLC)<\/a>. Don\u2019t \u201csave\u201d it for penetration testing at the end.<\/p>\n<p>There is a comprehensive menu of tools to help developers find and fix bugs. They include (but are not limited to):<\/p>\n<p>\u2022<a href=\"https:\/\/click.mlsend.com\/link\/c\/YT0xMjAzMTU4NjE1NTI4MDQ4OTIzJmM9ejRjMiZlPTE5MjgmYj0yNjQ1MDAxMDImZD1iNHE5dTZ1.tuDjrpmbocyTdFDFhwWziYNr-leP5ddvD1bMUav4KsY\">Architecture risk analysis (ARA)<\/a> &#8211; About half of the software defects that create security problems are flaws in design. ARA identifies those flaws and determines the level of risks to business information assets.<\/p>\n<p>\u2022<a href=\"https:\/\/click.mlsend.com\/link\/c\/YT0xMjAzMTU4NjE1NTI4MDQ4OTIzJmM9ejRjMiZlPTE5MjgmYj0yNjQ1MDAxMDQmZD1hNG0yYjRs.ScREmIACt3u_7pN_yO5kQfyUSgjh8Of0wDcnsehQt_c\">Static application security testing (SAST)<\/a> &#8211; This helps teams find and fix security and quality weaknesses in proprietary code as it is being developed.<\/p>\n<p>\u2022<a href=\"https:\/\/click.mlsend.com\/link\/c\/YT0xMjAzMTU4NjE1NTI4MDQ4OTIzJmM9ejRjMiZlPTE5MjgmYj0yNjQ1MDAxMDYmZD1zNnAzcTlt.SaaGPAPaUqUxrqbNBx6WTL2gamfV8qZDl5ngwFgI_0k\">Dynamic application security testing (DAST)<\/a> &#8211; This tool tests applications while they are running, simulating an attack by a hacker.<\/p>\n<p>\u2022<a href=\"https:\/\/click.mlsend.com\/link\/c\/YT0xMjAzMTU4NjE1NTI4MDQ4OTIzJmM9ejRjMiZlPTE5MjgmYj0yNjQ1MDAxMDgmZD16MW4zdThp.t-UQEZJfHzjzdYv26U2JS6dJ7lDW4As-YrWPY3Yi_1Q\">Interactive application security testing (IAST)<\/a> &#8211; This also tests running applications, but unlike DAST, it uses code instrumentation to observe application behaviour and data flow. It\u2019s useful for CI\/CD (continuous integration\/continuous delivery) development environments, where the priorities are speed and automation.<\/p>\n<p>\u2022<a href=\"https:\/\/click.mlsend.com\/link\/c\/YT0xMjAzMTU4NjE1NTI4MDQ4OTIzJmM9ejRjMiZlPTE5MjgmYj0yNjQ1MDAxMTAmZD1kMGMwcjBp.yE4tbqbZdjDiCk3i1baaRvJ2XtR3-khwCJKP5xCOLAU\">Software composition analysis (SCA)<\/a> &#8211; Almost every application in existence today is built, at least in part, on open source software components. SCA finds those components, along with any associated security vulnerabilities that have been reported against them.<\/p>\n<p>\u2022<a href=\"https:\/\/click.mlsend.com\/link\/c\/YT0xMjAzMTU4NjE1NTI4MDQ4OTIzJmM9ejRjMiZlPTE5MjgmYj0yNjQ1MDAxMTImZD1uNmQ4bzZj.SiUmVPhhKxJb94SoAeRN_YPRAapGFxm6YSBJ8M6Mf2E\">Pen testing<\/a> &#8211; This is best done at the end of development, and is considered an extension of DAST. The goal is to find vulnerabilities in web applications and services and then try to exploit them so developers can fix them before a product hits the market.<\/p>\n<p>Of course, at the end of all that, even if software is close to perfect, vulnerabilities will inevitably be discovered, either by bad guys who\u2019ll exploit them, or by good guys who\u2019ll report them to the makers before going public.<\/p>\n<p><b>Don\u2019t forget to patch, patch, patch<\/b><\/p>\n<p>And that leads to the second fundamental: Know what you have and keep it up to date \u2014 as in, patch, patch, patch. That applies both to vendors and their customers.<\/p>\n<p>Tim Erlin, Vice President of Product Management and Strategy at Tripwire, said besides secure development practices, vendors need \u201ca process for remediation of any discovered vulnerabilities. For vendors, the problem isn\u2019t really fixed until their customers actually apply a patch or other mitigation.\u201d<\/p>\n<p>Justin Hutchings, Senior Product Manager of Security at GitHub, the code-sharing and publishing service that also manages and stores revisions of projects, agreed. Obviously, it is the responsibility of companies to disclose and provide fixes for vulnerabilities in their software.<\/p>\n<p>But once the vulnerability has been disclosed, \u201cit\u2019s the responsibility of downstream software projects and IT organisations to patch vulnerabilities,\u201d he said.<\/p>\n<p>And the reality, which confirms the Tripwire findings, is that not all of them do. \u201cIn the last year, we\u2019ve sent nearly 27 million security vulnerability alerts to vulnerable software projects on GitHub,\u201d he said.<\/p>\n<p><b>Consider moving to the cloud<\/b><\/p>\n<p>\u201cWhile security vulnerability alerts provide users with information to secure their projects, industry data show that more than 70% of vulnerabilities remain unpatched after 30 days, and many can take as much as a year to patch,\u201d said Hutchings.<\/p>\n<p>One way to improve on that, he said, is to move business-critical software to the cloud. \u201cSoftware-as-a-service apps tend to be patched much faster because they\u2019re all centrally managed and don\u2019t rely on thousands of customers\u2019 individual upgrade cycles,\u201d he said.<\/p>\n<p>Yes, all of these measures cost money. But they are all much cheaper than dealing with the fallout from a major breach.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>By Taylor Armerding, Security Expert at Synopsys Software Integrity Group It\u2019s a pretty good bet that if a car dealership posted an ad announcing that the criminal underground was selling keys that could unlock owners\u2019 vehicles, but that it was offering free replacement locks that wouldn\u2019t be vulnerable, the responses would be quick and universal. [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":33491,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26,22],"tags":[6203,6151,286,6800],"class_list":["post-35866","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-opinions","category-spotlight","tag-data-breach","tag-high-tech","tag-it-security","tag-synopsis"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/35866","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=35866"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/35866\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/33491"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=35866"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=35866"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=35866"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}