Tiny fraction of attack pathways expose businesses to security risks

April 20, 2023

According to a study from XM Cyber, just a tiny fraction of attack pathways expose most businesses’ important assets to security concerns.

The study, titled “Navigating the Paths of Risk: The State of Exposure Management,” examined more than 60 million exposures in more than 10 million organizations and discovered that 75% of exposures were not exploitable. Only 2% of the exposures, however, constituted a serious danger to more than 90% of an organization’s important assets.

According to the survey, the average firm has around 11,000 exploitable security exposures every month, affecting both on-premises and cloud infrastructure, with bigger companies having up to 250,000 exposures. Critical assets were discovered to be “one hop away,” allowing attackers easy access to them.

Furthermore, despite the fact that these approaches affect 82% of firms, many organizations overlook attack vectors that exploit credentials and permissions. The study also discovered that zero-trust architecture was insufficient in defending enterprises against security exposure strategies that relied on trust.

To prevent human mistake, the report advises that suppliers deliver products with “security by default” options. The survey also discovered that security personnel are overburdened by dead-end security exposure notifications, making it simpler for attackers.

The sources for this piece include an article in CPOMAGAZINE.

Top Stories

Related Articles

February 13, 2026 Cybersecurity researchers have uncovered a malicious Google Chrome extension designed to steal sensitive data from Meta Business more...

February 5, 2026 A security researcher at Koi named Oren Yomtov has uncovered a widespread malware operation embedded inside an more...

February 4, 2026 More than three million Fortinet devices have been exposed to a critical authentication-bypass vulnerability that is being more...

February 4, 2026 A now-patched security flaw in Docker’s built-in AI assistant exposed users to the risk of remote code more...

Jim Love

Jim is an author and podcast host with over 40 years in technology.

Share:
Facebook
Twitter
LinkedIn