Armis has published ‘The Anatomy of Cybersecurity: A Dissection of 2023’s Attack Landscape’. The report’s findings serve as a blueprint to help security teams prioritize efforts to reduce cyber risk exposure in 2024.
The report found that global attack attempts more than doubled in 2023, increasing 104%. Utilities (over 200% increase) and manufacturing (165% increase) were the most at risk industries. Attack attempts peaked in July, with communications devices, imaging devices and manufacturing devices experiencing intensified targeting during this period.
Key findings of the report include:
Geopolitical tensions exacerbate the cyber security landscape
Cyber warfare grew more widespread in 2023: top industries exposed to attack from state actors were those within manufacturing, educational services, and public administration.
Legacy technology steepens the incline of cyber security pros’ existing up-hill battle
Older Windows server OS versions (2012 and earlier) are 77% more likely to experience attack attempts compared to newer Windows Server versions.
This vulnerability is particularly evident in the server environment, with nearly a quarter of server versions facing end-of-support (EoS) scenarios. The Educational Services industry has a significantly higher percentage of servers (41%) with unpatched weaponized common vulnerabilities and exposures (CVEs), compared to the general average of 10%.
Industries still using end-of-life (EoL) or EoS OSs that are no longer actively supported or patched for vulnerabilities and security issues by the manufacturer: educational services (18%), retail (14%), healthcare (12%), manufacturing (11%) and public administration (10%).
Businesses struggle with effective vulnerability prioritization and remediation
Key facts in this area include:
- There were over 65,000 unique CVEs discovered in 2023.
- Wearable devices have the highest percentage (93%) of unpatched CVEs.
- A third of all devices are still not patched for Log4Shell.
- Irrespective of the weaponization status of a CVE, organizations consistently grapple with patch rates at 62% for non-weaponized and 61% for weaponized vulnerabilities.






