TMCnet News
Invicti Security Reports on Lost Year in Web Application SecurityAUSTIN, Texas, April 13, 2021 /PRNewswire/ -- Invicti Security™, a global leader in web application security, today released the spring volume of its Invicti AppSec Indicator Report, which examines the prevalence of web vulnerabilities across more than 3,500 targets in every industry and more than 100 countries. The findings indicate that as organizations shifted focus to support remote work and business continuity amid the challenges of 2020, web application security suffered. The report, released in previous years as the Acunetix Web Vulnerability Report, was developed through an examination of anonymized data collected via Acunetix, an Invicti DAST and IAST product used by thousands of companies and government organizations to discover and scan web assets for vulnerabilities and prioritize them for remediation. The large dataset includes data from more than 188,000 web scans, 173,000 network scans, and more than 290 million monthly HTTP requests provided the basis for the analysis. Between 2016 and 2019, the number of high-severity and medium-severity vulnerabilities decreased steadily every year, with an average reduction rate of 22% in high-severity vulnerabilities year over year. If that trend had continued, the overall incidence of high-severity vulnerabilities would have decreased from 26% to about 20%. However, progress came to an abrupt halt in 2020, probably as a result of resource reallocation to address Covid-19 business impacts and enable remote work worldwide. Among the 2020 report's findings:
With many of the Covid-related changes to consumer and business behaviors expected to endure beyond the end of the pandemic, web application security is more critical than ever. From growing usage of business tools such as chat, web conferencing, and collaboration environments, to increased consumer adoption of e-commerce, attack surfaces continue to expand. Recent research indicates that the largest percentage of breaches in 2020 began with a web application, yet at the same time, the number and severity of a variety of other types of attacks reached new highs in 2020, diverting the time and resources of security organizations away from web application security. "It's very troubling to see this loss of momentum due to reduced attention to web application security," said Invicti president and COO Mark Ralls. "As we look ahead, we hope to see organizations adopt best practices and invest in security, so that they can continue to advance their web security posture, protect their customers, and avoid being the next big security breach headline." The full report is available here. Related: About Invicti Security View original content to download multimedia:http://www.prnewswire.com/news-releases/invicti-security-reports-on-lost-year-in-web-application-security-301267787.html SOURCE Invicti Security |