Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Misguided justifications for not remediating vulnerabilities

by The Gurus
June 5, 2020
in Opinions & Analysis
Share on FacebookShare on Twitter

According to Nuix’s recent Black Report, 75% of organisations only perform limited remediation after a penetration test. To take the positives, it’s good that organisations are paying attention to critical vulnerabilities. However, the report also shows that 64% of penetration testers say their biggest frustration is that organisations do not fix the things they know are broken.
Product and system owners face a few options when they learn about a vulnerability and the risks it poses. They can accept the risk, usually when the value of the asset is less than the cost of protecting it. A second option is mitigation, which can entail implementing external controls to the product, and relying on internal mechanisms to make it significantly more difficult to exploit a vulnerability.
In most cases, a third possibility – remediation – is the preferred course of action. However, product or system owners often choose not to remediate vulnerabilities, as remediation can be costly and complex. In this case, their justifications tend to be misguided. Here are some of the most common reasons organisations choose not remediate a vulnerability after they find out about it.
Root or user accounts are required to access data, and therefore are protected: By relying on this security measure, there’s an inherent assumption that organisations have effective controls around who can access the servers—physically and digitally. The main reason this fails the security test is that insiders can still access the data, which may or may not be encrypted. Considering it takes an attackerless than 12 hours to compromise a system, organisations cannot afford to rely solely on system-level access controls to protect application data. And if the asset includes database credentials that have significant privileges on the database, the product owner just provided another avenue for attack.
The framework provides protection: Frameworks are a very important part of developing secure applications. The longer a framework has been around, the greater the chance that most of the lower-hanging security issues have been resolved. However, even a well-tested framework is no guarantee of security. Firstly, because not all framework owners respond effectively to security issues offer effective general long-term support. They may not be effective when time comes to communicate issues to the community using the framework, or when fixing problems in a timely manner, or when effectively determining the source of an issue, or with patching the system and delivering updates to the customer. Secondly, most organisations do not use trusted local versions of the framework. If the organisation is always pulling down a copy of the framework from a shared repository, how do they verify that the download is legitimate and not compromised? Last, but not least, because it is possible for malicious code to be injected into open source frameworks. Once this has happened, there might not be a way to recover.
Browser controls are in place, and are sufficient: Browser controls provide a basic level of defence that is meant to act as a gatekeeper – not as an overall solution, given the lack of context browsers have regarding applications. Not allbrowsers support controls and there is no guarantee that current browsers will support them in the future. For example, the HTTP Strict Transport Security feature tells the browser to force any request coming from the page through HTTPS. This header provides a false sense of security. If cookies are not set to be HTTPOnly and Secure Only, any cross-site scripting vulnerability will result in the ability to steal cookies or local storage (HTML5).X-Frame-Options is a very important header to set, but be sure to set it correctly to prevent an attacker from building a site that frames the victim site. It helps prevent against attacks known as clickjacking. This protection also does not prevent cross-site scripting attacks that manipulate the document object model. Organisations can use Access-Control-Allow-Origin to prevent JavaScript hosted on third-party domains from running. Just remember, it doesn’t prevent a user from executing an attack using JavaScript that might have been dropped onto the web server via another attack vector.
Employees won’t misuse internal apps: Organisations tend to think that no employee will take advantage of an internal tool. They assume that employees never make mistakes and that external threats—hackers—will not get access to legitimate user accounts. The key is to remember that not all insider threats are malicious and that there is nothing to differentiate a hacker with stolen credentials from a legitimate user.
Networking controls are efficient: Some product owners use firewalls and network access controls as a justification for not remediating a vulnerability. They believe the network controls are effective enough to make fixing the application unnecessary. There are two challenges with this. The first is it assumes that there are no vulnerabilities in the network firewall or web application firewall and that both are patched in a timely manner when patches are available. The second is that in large, complex network architectures, it can be difficult or impossible to fully understand the flow of network traffic. If the firewall protecting them is misconfigured, there is an increased risk of accidental exposure.
No matter which decision product and system owners decide to make – be it acceptance, mitigation, or remediation – each of these paths carries its own risks and consequences.
Understanding the issues that lie beneath each option will be the key to success.
By Evan Oslick, Software Security Developer, Nuix

Tags: CybersecurityTechnology
ShareTweet
Previous Post

FireMon’s Intelligent Security Management (ISM) Platform (Review)

Next Post

Giving millennials the keys to a kingdom without borders

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol