Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Businesses are confident that they have bots under control. They’re wrong.

For every bot that a business is detecting, there is at least one other, if not more that it is failing to detect

by Andy Still
September 17, 2020
in Insight
Businesses are confident that they have bots under control. They’re wrong.
Share on FacebookShare on Twitter

Businesses can make better decisions if they have a good idea of who is using their website. Are they young or old? Male or female? It turns out they are very likely not even people. The majority of web traffic is made up of automated bots, and a great deal of these are malicious.

The popular narrative around bots is that they are spreading misinformation on social media, but most aren’t involved in nation state-level propaganda. They’re trying to make money.

There’s a number of ways these malicious bots can attack a site. Credential stuffing takes advantage of the way people will reuse passwords and try to takeover accounts using usernames and passwords that have been stolen elsewhere. Other bots do similar things with huge lists of stolen credit card numbers, while more sophisticated bots will buy up limited edition items for sale at a markup elsewhere.

Businesses are, luckily, aware of this problem. Or they think they are—they know that bots exist and need to be stopped. But they are unaware of the sheer scale of the problem, a miscalculation that puts them at risk of successful bot attacks, with all the financial and reputational fallout that will entail.

What are businesses getting wrong?

Our research into how aware businesses are of the dangers of bots was partly reassuring. The majority of businesses have bot solutions in place, they have budget to deal with the problem, they understand what bots can do, and they know what the implications for the business are if things go wrong.

However, there’s one glaring problem. Asked how much of their website traffic is taken up by bot activity, most businesses said between 10%-19%. This is far too low. Only 1% said that bots were consuming over 50% of their web application resources—a far more realistic estimate based on both our own experience of bots and wider research.

This means that for every bot that a business is detecting, there is at least one other, if not more that it is failing to detect.

The designers of bots go to great lengths to disguise their activities. For example, there are bots that will test the rate-limiting capabilities of a site, then, once it has found this, it will operate in a way that means it can stay just below this limit. Other bots hide behind randomized activity that looks less “bot-like” or try to emulate human behaviour. The more sophisticated the bot, the more likely it is to fly under the radar—and the more likely it is to cause serious damage.

The inevitable conclusion is that there are bots out there taking over accounts, stealing data, and disrupting businesses, while remaining completely undetected.

How can businesses fix this?

Fixing the problem is not as simple as better bot detection. These businesses are fully aware of the problem and have solutions in place, but this doesn’t seem to be making the difference when it comes to visibility.

One major hurdle is the diffusion of responsibility. For most businesses, no one department is responsible for bots—most report that four or more departments have some say in bot management strategy, from CIO and CISO to CMO and even head of customer services. Diffuse responsibility makes it easy for problems to go unnoticed; they’re part of someone else’s remit. A ship sailing in icy waters may be captained by someone who knows how dangerous icebergs can be, but if no one person is given responsibility for looking out, disaster is inevitable.

There is also a general lack of awareness of the bot ecosystem. Bots make use of stolen credentials that are traded on dark web marketplaces and increasingly in less obscure places. Intelligence on these marketplaces would be invaluable to businesses looking to understand attacks on their site. What credentials are available that could be used against us? Have we been breached without knowing?

High awareness and low visibility make for a dangerous cocktail. It’s critical that businesses better understand the problem of sophisticated bots. Without a deep understanding of how bots operate, and the wider bot ecosystem, businesses are risking taking big financial hits and losing their customers’ loyalty.

Contributed by Andy Still, CTO, Netacea

ShareTweet
Previous Post

Staying ahead in the regulatory race

Next Post

Now is the time for security leaders to build business resilience

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol