Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

New Report Shows Lack of Awareness About Malicious Third-party Code Leaves Decision Makers in the Dark About Security Risks

A survey of security professionals that underscores the lack of awareness people have about vulnerabilities in third-party client-side scripts and the unaddressed threats that can result.

by The Gurus
November 8, 2019
in Threat Detection
PerimeterX
Share on FacebookShare on Twitter

PerimeterX, the company that protects the world’s largest and most reputable websites and mobile applications from malicious activities, today released “Third-Party Code: The Hidden Risk in Your Website,” a survey of security professionals that underscores the lack of awareness people have about vulnerabilities in third-party client-side scripts and the unaddressed threats that can result.

Industry estimates state that the typical website is comprised of approximately 70 percent third-party code. The survey found that while almost all websites are running at least some third-party client-side scripts, 60 percent of those surveyed estimated the proportion of third-party code to be significantly lower – a dangerous misconception.

“Today, a company’s website is a primary avenue for interaction with customers and for significant revenue. As a result, they are a large target for cybercriminals, and website attacks show no sign of slowing down. Enterprises must protect their web applications from client-side attacks to prevent both the risk of massive fines, as in the case of the recent British Airways GDPR fine, as well as damage to brand reputation,” said Kim DeCarlis, CMO, PerimeterX. “This report highlights a large gap between perception and reality. It serves as a wake-up call for organizations to take preventive action and not wait until they’ve been attacked and the damage has been done.”

Additional findings include:

  • Nearly two-thirds of those surveyed believe they have only some or very little insight about the third-party client-side scripts that are running on their websites. Only 11 percent believe that they have complete insight into third-party client-side scripts.
     
  • Only 38 percent of those surveyed can provide assurances to their senior management that their corporate websites are completely secure and compliant with key privacy regulations. This creates not only significant liabilities, such as regulatory fines and brand damage, but personal ones, as well: 70 percent of those surveyed believe that website owners definitely would be terminated following a major data breach.
     
  • Decision makers are concerned about a variety of threats, including digital skimming, Magecart and supply chain attacks. And they have good reason to be concerned: 36 percent of those surveyed reported that their websites had been attacked in the past.

“From our perspective, the key issue here is that decision makers are largely in the dark with regard to the security risks that their organizations face, and they are not investing in the tools that will enable them to address these problems. We feel that this is not an issue about lack of willingness to invest to solve the problems, but more about a lack of awareness of the problem and how to address it,” noted Michael D. Osterman, president of Osterman Research, who conducted the survey.

The survey was conducted during July and August 2019 with a total of 307 organizations in the United States at e-commerce, financial services, travel and hospitality, and media and entertainment organizations. To qualify, respondents were required to be familiar with third-party scripts or scripts from third-party libraries and how they are used on their organizations’ websites. For more information, read the full report.

Share3Tweet
Previous Post

Securonix Integrates MITRE ATT&CK Framework Into Analytics And Threat Hunting

Next Post

How to Empower a Security Driven Future

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol