White paper

Audit Report: Internal Vulnerabilities of Endpoints

Security
Participating Company: 
Promisec

As a leader and pioneer of agentless endpoint management solutions, Promisec is intrinsically involved in the inspection, validation, remediation and compliance of several million endpoints (laptops, desktops and servers) around the globe. Our customers include everyone from small to medium size businesses to industry leaders in State and Local Government, Insurance, Finance, Healthcare, Education and more. In addition to being a critical component of the IT and security posture of many of the world’s best brands, the rapid growth of our company frequently has our solutions put to the test in the form of “Proof of Concepts” in hundreds of organizations of all types and sizes each year. Promisec is not a typical endpoint management solution, often identified by the marketplace as Antivirus, PC Lifecycle Management and Patch Management solutions, although we compliment those solutions making them work better, often by a factor of 20-30% or more. Agentless inspection ability is the only way companies can ensure compliance and we are not just talking about the alphabet soup of compliance…PCI, SOX, HIPPA, etc. –We are talking about specific endpoint policies and configurations that our customers tell us they want and need to be in place. Promisec’s unique agentless inspections provides unprecedented and 100% accurate visibility of customer’s internal networks providing us one of the best views in the industry for endpoint trends, risks and compliance posture. In this report, our fourth annual, we take a look at the inspection findings of approximately 100,000 endpoints in 50+ organizations of various size and industry, which mirrors typical findings we see in almost every organization around the globe. The report shows a breakdown of the typical threats faced in organizations, identifying the most common threats, and describing the different types of threats and miss-configurations most prevalent in the marketplace. The main findings of the report are as follows: - 100% of organizations have security and compliance issues in 10-30% of their endpoints - Unmanaged workstations have more than doubled at 9%of endpoints in 2010 - Missing or miss-configured anti-virus agents is an increasing problem with 21% of endpoints having disabled, missing, or out-of-date policy violations - 23% of endpoints were missing patch management or lifecycle management agents - 20% of endpoints had unauthorized file sharing and peer-to-peer applications - 18% of laptops have issues with the encryption agent they are supposed to have installed and running - 16% of endpoints did not have the latest Microsoft service packs or Hotfixes - 4% of endpoints had unauthorized dual connectivity or hacking software - 13% of endpoints contained unauthorized usage of USB or removable storage devices