International Cyber Expo International Cyber Expo
  • About Us
Tuesday, 21 July, 2026
IT Security Guru
International Cyber Expo
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Here’s Why the 20th Anniversary of Windows XP’s Release Is Scarier Than It Sounds

32 percent of organizations still have at least one Windows XP device connected to their network

by The Gurus
October 31, 2019
in Guru's Picks
Windows XP
Share on FacebookShare on Twitter

It may be hard to remember today, but when Windows XP was released on Oct. 25, 2001, it was a revelation. Aimed at both consumers and businesses, it married a user-friendly interface with reliability, replacing clunky and crash-prone Windows 2000. When upgrades to the system became available in the ensuing years, many businesses and individuals decided they had sunk too much time and money into XP-compatible hardware and training to make switching worthwhile.

In fact, according to a 2018 Spiceworks report, 32 percent of businesses still have Windows XP installed on at least one device in their network. As we approach the 20th anniversary of XP’s release, we’re seeing the full consequences of the continued use of this out-of-date, unsupported operating system by users around the world.

XP usage is just one of many data points that illuminate the perilous networked landscape we inhabit today. That’s why Verisk has identified digital vulnerability as an emerging global risk as criminal and state agents exploit these outdated systems for nefarious ends. By looking at the numbers behind these seemingly small lags in cyber security, we can see the true threat digital vulnerability poses in modern life.

Here’s how one computer in the Accounting department running an outdating operating system could impact your business (or government, or family). One Friday in May of 2017, a ransomware attack began with an initial infection in Asia. Within one day, 230,000 computers in more than 150 countries were infected.

By the time the Wannacry ransomware attack—as it is now known—was over, economic losses were estimated to run from the hundreds of millions to up to $4 billion. And the attack could have been worse had its creators (believed to be North Koreans agents) chosen to target vital infrastructure. That wasn’t the end of it: Just this May, Microsoft released a patch for Windows XP, which it stopped releasing updates for five years ago. As Wired magazine reported, “The last time Microsoft bothered to make a Windows XP fix publicly available was a little over two years ago, in the months before the WannaCry ransomware attack swept the globe. This week’s vulnerability has similarly devastating implications.”

I’m not saying that XP is behind the world’s growing cyber-vulnerability crisis: it isn’t. Microsoft has been pushing users away from the program for years, and those using the operating system today make up a tiny fraction of networked computers. What’s clear is that currently, our patch cadence—the speed at which vulnerabilities are addressed—lags behind the pace at which malicious actors are identifying weaknesses; that these attacks are getting more audacious and more costly; and that relatively few people realize the connection between cyberattacks and what are often viewed as benign digital security lapses. Too often, it is the well-meaning employee or technophobic grandfather who accidentally allows criminals into what should be a tightly guarded digital sphere.

This doesn’t mean that a future of Wild West lawlessness in the digital world is inevitable. While both criminals and nefarious state actors are becoming savvier in their attacks, policymakers and cybersecurity experts are also redoubling their efforts.

On Oct. 2, 2019, the U.S. House of Representatives passed the Cybersecurity Vulnerability Remediation Act, which amends the Homeland Security Act to include that “the director may, as appropriate, identify, develop, and disseminate actionable protocols to mitigate cybersecurity vulnerabilities, including in circumstances in which such vulnerabilities exist because software or hardware is no longer supported by a vendor.” This move attempts to address the problem identified here, and other state and federal laws are beginning to gain momentum in this area.

However, to effectively combat bad actors online, we must change public perceptions of cyberattacks. As I wrote for the Verisk Risk Report, cyberattacks must be seen as a hurricane in the Caribbean during storm season, when they are too often viewed as an earthquake in New York City: unpredictable, devastating, and unlikely to reoccur.

This year is on track to be “the worst year on record” for breach activity, with 4.1 billion records exposed as of June 30, according to a mid-year report by QuickView. Compared to the previous year, the number of breaches was up 54 percent. Today, we have an unprecedented view of the problem we face thanks to the power of data analytics and its impact on risk assessment. We need to use this power to better inform every citizen of how they can help protect their communities through simple actions, like not snoozing that security update for one more day.

Humans have always used data to understand patterns and influence future events. We’ve collected the data; we see the upwards trend of increasing digital attacks; now, we need to start preemptively educating people how they can influence this situation going forward.

Whether they work in a café, a bank, or a hospital, no conscientious employee would leave a door propped open when leaving work for the night, nor would they hand out security codes to shady strangers on the street. That is because we are all trained in the basic security protocols of the physical world. Now that we can understand the scale of the problem, it’s time to bring this training into the digital era, to ensure a secure and resilient future for all, offline and on.

Prashant Pai is vice president of cyber offerings at Verisk (Nasdaq:VRSK), a leading data analytics provider.

ShareTweet
Previous Post

Why is working culture so important for the benefit of the business?

Next Post

Four principles for security metrics

Recent News

What Does the Cyber Industry Want to See From the New UK Government?

What Does the Cyber Industry Want to See From the New UK Government?

July 20, 2026
Purple Logo, capitalised letters: SALT.

Salt Security tackles AI governance challenge with 100 pre-built agentic security policies

July 20, 2026
New Continuous Runtime Security Validation service aims to strengthen fintech cyber resilience

New Continuous Runtime Security Validation service aims to strengthen fintech cyber resilience

July 20, 2026
Scams Now Drive Almost Half of All Malware Detections as Attackers Weaponise Everyday Trust

Scams Now Drive Almost Half of All Malware Detections as Attackers Weaponise Everyday Trust

July 20, 2026

Eskenzi PR banner ad

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol