Absolute Security has published findings from its new research report, the Cyber Resilience Risk Index 2024. The research revealed that most industries continue to run almost two months behind in patching software vulnerabilities, endpoints remain vulnerable to threats, and most enterprise PCs will need to be replaced to support AI-based technologies. All factors creating numerous compliance and security challenges.
Key report findings include:
- The majority of organizations are not ready for AI: despite the rush to leverage AI on endpoints, 92% of PCs have insufficient RAM capacity needed to support enterprise and commercial use cases. Organizations that want to take advantage of AI will need to replace entire device fleets, requiring them to ensure mass deployments can remain secure against threats and compliant with internal and external security policies.
- Essential security tools are failing: when not supported by remediation capabilities, endpoint protection platforms (EPP) and network access security applications on managed PCs fail to operate effectively 24% of the time. In addition, on almost 14% of these devices, unsupported EPPs are not even present, opening high-risk security gaps.
- Organizations are falling behind in critical patching: although the overall number of days to patch software vulnerabilities continues to drop, most industries continue to run weeks or months behind in complying with their own patching policies. Education and government are the top sectors with the worst patching records, taking 119 and 82 days respectively to patch.
The report explains why cyber resilience should be an organizational priority, rather than simply cyber security.
‘Cyber Resilience is a paradigm larger and more critical than traditional cybersecurity’ states the report. ‘Organizations with effective Cyber Resilience capabilities have digital operations that can withstand and quickly recover to normal business operations following cyberattacks, technical malfunctions, or deliberate tampering attempts.’
Cyber resilience is relatively new but several factors are pushing it into the mainstream, says the report: ‘These include White House directives calling for it to be built into software supply chains, recognition that legacy detection and prevention strategies aren’t sufficient to defend against advanced threats, and leading industry groups identifying Cyber Resilience as an emerging trend.’






