Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Friday, 26 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

75% of Organisations Have Gaps in Core Security Controls, Research Finds

Despite strong vulnerability scores, majority of organisations have gaps in core security controls like MFA, endpoint detection and policy management, creating overlapping exposure across enterprise environments.

by Guru Writer
January 29, 2026
in Editor's News, Featured, Features
75% of Organisations Have Gaps in Core Security Controls, Research Finds
Share on FacebookShare on Twitter

New research by Nagomi Security has revealed an alarming disconnect between how secure organisations think they are, compared to where real exposure exists. This overconfidence, as explored in Nagomi’s The Illusion of Maturity: 2026 Enterprise Exposure Snapshot, means that organisations are facing overlapping exposure within their networks, potentially putting them at significant risk. Notably, incomplete multi-factor authentication (MFA), missing or misconfigured endpoint detection and response (EDR) and weakened endpoint policies appear in more than 75% of organisations, often affecting the same systems at the same time.

The report also shows that exposure is evenly spread across environments. In most organisations, risk concentrates in a small number of high-impact conditions that persist over time. Amongst the surveyed enterprises, most organisations showed 20–40 total exposure findings that collapse into roughly seven high-signal conditions after correlation.

Worryingly, the research also found that misconfigurations scale faster than vulnerabilities. A single misconfiguration or degraded control can affect thousands of assets, creating more exposure than dozens of individual vulnerabilities. These conditions often sit outside traditional vulnerability metrics, so dashboards may look healthier even as attack paths remain open.

Emanuel Salmona, co-founder and CEO of Nagomi Security, said: “Exposure is being created faster than most organisations can realistically fix it. Teams see the issues, but remediation slows down as work moves across tools, owners, and priorities. That operational latency leaves risk sitting in the environment far longer than it should. Real resilience comes from tightening operations and collapsing the time between seeing exposure and actually eliminating it.”

Similarly, the report found that vulnerability management outperforms every other control area, with 91% of assets passing vulnerability assessments, while identity and endpoint controls pass at roughly 50%, and security awareness and training falls below 30%. However, more than 60% of organisations fail advanced endpoint detection and response (EDR) policy tests, even when agents are deployed across the environment.

This is particularly concerning as single exposure conditions routinely impact thousands of assets, including scenarios where one exploited remote code execution vulnerability combined with weakened endpoint protections affects approximately 2,000 assets per organisation on average.

Yet, the research does suggest that 30% of assets demonstrate strong control coverage across identity, endpoint, and security awareness at the same time, which is a step in the right direction, despite leaving the majority exposed to convergent failure paths. This means that more work needs to be done – and fast.

The findings highlight a structural challenge for security teams: progress is often measured at the control level, while real risk accumulates where controls fail together. The report calls for a shift away from siloed metrics toward identifying and eliminating the high-impact exposure conditions attackers consistently exploit.

ShareTweet
Previous Post

VaynerX Engages Keeper Security to Standardise Credential Security Globally

Next Post

CyberASAP Demo Day: Exclusive First Look at the UK’s Next-Generation Cyber Security Innovations

Recent News

Keeper Security launches Microsoft Teams integration for privileged access management

Keeper Security launches Microsoft Teams integration for privileged access management

June 26, 2026
UK Museums Are a Cyber Incident Waiting to Happen and the Government Knows It

UK Museums Are a Cyber Incident Waiting to Happen and the Government Knows It

June 25, 2026
pqc

New Forescout Data Reveals Slow Progress Toward Quantum-Safe Security

June 24, 2026
AI-Powered Phishing Attacks Surge 1,380% as Criminal Platforms Render MFA Obsolete

AI-Powered Phishing Attacks Surge 1,380% as Criminal Platforms Render MFA Obsolete

June 24, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol