Skip to main content
  • Personal
  • Business
  • Foundation
    Close
  • Select Region

      Select your region below to see curated info.

    • Global
    • India
    • MENA
  • mySHRM Login
  • MySHRM
    • Dashboard
    • Account
    • Logout
SHRM
  • Membership
    • Membership

      As a SHRM Member®, you’ll pave the path of your success with invaluable resources, world-class educational opportunities and premier events.

      Membership Benefits
  • Certification
    • SHRM Certification

      Demonstrate your ability to apply HR principles to real-life situations.

      • How to Get Certified
      • Eligibility Criteria
      • Exam Fees & Options
      • SHRM-CP
      • SHRM-SCP
      • Which Certification is Best for Me?
      • Recertification
      Prepare for the Exam
      • Exam Preparation
      • SHRM BASK
      • SHRM Learning System
      • Instructor-Led Learning
      • Self-Study
      Specialty Credentials

      Demonstrate targeted competence and enhance your HR credibility.

      PMQ

      Gain a deeper understanding and develop critical skills.

  • Events & Education
    • India Events

      Demonstrate your ability to apply HR principles to real-life situations.

      • SHRM Unconference
      • Tech Conference
      • India Annual Conference
      MENA Events
      • MENA Annual Conference
      Global Events
      • US Annual Conference
      Webinars
  • Resources
    • Resources

      Stay up to date with news and leverage our vast library of resources.

      • Compliance
      • HR Research
      • Legal & Compliance
      • Latest News & Trends
      • Tools & Guides
      HR Topics
      • AI in the Workplace
      • Civility at Work
      • Compensation & Benefits
      • Inclusion & Diversity
      • Talent Acquisition
      • Workplace Technology
      • Workplace Violence Prevention
  • SHRM Connect
  • Shop
    • SHRM Store

      Shop for HR certifications, credentials, learning, events, merchandise and more.

      Workplace Essentials
      • SHRM Memberships
      • SHRM Certification
      • Specialty Credentials
      • HR Tools & Tech
      Education
      • Seminars
      • eLearning
      • Books
      Merchandise
      • Accessories
      • Apparel
      • Office & Home
Become a Member
Renew
Rejoin Now
Renew
Close
  • Personal
  • Business
  • Foundation
  • Membership
    back
    Membership
    • Membership

      As a SHRM Member®, you’ll pave the path of your success with invaluable resources, world-class educational opportunities and premier events.

      Membership Benefits
  • Certification
    back
    Certification
    • SHRM Certification

      Demonstrate your ability to apply HR principles to real-life situations.

      • How to Get Certified
      • Eligibility Criteria
      • Exam Fees & Options
      • SHRM-CP
      • SHRM-SCP
      • Which Certification is Best for Me?
      • Recertification
      Prepare for the Exam
      • Exam Preparation
      • SHRM BASK
      • SHRM Learning System
      • Instructor-Led Learning
      • Self-Study
      Specialty Credentials

      Demonstrate targeted competence and enhance your HR credibility.

      PMQ

      Gain a deeper understanding and develop critical skills.

  • Events & Education
    back
    Events & Education
    • India Events

      Demonstrate your ability to apply HR principles to real-life situations.

      • SHRM Unconference
      • Tech Conference
      • India Annual Conference
      MENA Events
      • MENA Annual Conference
      Global Events
      • US Annual Conference
      Webinars
  • Resources
    back
    Resources
    • Resources

      Stay up to date with news and leverage our vast library of resources.

      • Compliance
      • HR Research
      • Legal & Compliance
      • Latest News & Trends
      • Tools & Guides
      HR Topics
      • AI in the Workplace
      • Civility at Work
      • Compensation & Benefits
      • Inclusion & Diversity
      • Talent Acquisition
      • Workplace Technology
      • Workplace Violence Prevention
  • SHRM Connect
  • Shop
    back
    Shop
    • SHRM Store

      Shop for HR certifications, credentials, learning, events, merchandise and more.

      Workplace Essentials
      • SHRM Memberships
      • SHRM Certification
      • Specialty Credentials
      • HR Tools & Tech
      Education
      • Seminars
      • eLearning
      • Books
      Merchandise
      • Accessories
      • Apparel
      • Office & Home
Become a Member
Renew
Rejoin Now
Renew
  • Select Region

      Select your region below to see curated info.

    • Global
    • India
    • MENA
SHRM
mySHRM Login
  • MySHRM
    • Dashboard
    • Account
    • Logout
Close

  1. Topics & Tools
  2. Workplace News & Trends
  3. Is Neglect Driving the Surge in Cybersecurity Breaches?
Share
  • Linked In
  • Facebook
  • Twitter
  • Email

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Vivamus convallis sem tellus, vitae egestas felis vestibule ut.


Error message details.

Copy button
Reuse Permissions

Request permission to republish or redistribute SHRM content and materials.


Learn More
News

Is Neglect Driving the Surge in Cybersecurity Breaches?

February 7, 2022 | Drew Robb

Two people sitting at a desk working on a computer.


​More and more companies are experiencing ransomware attacks.

Ransomware victims have included Colonial Pipeline, JBS and Kia. In each case, the company was locked out of vital systems and suffered outages, and their IT teams had to scramble for many hours to enable the workforce to return to productivity.

The evidence isn't just anecdotal. The ENISA Threat Landscape 2021 report by the European Union Agency for Cybersecurity discovered a 150 percent rise in ransomware compared to 2020, while a recent Enterprise Strategy Group study found that 48 percent of respondents had been the victim of at least one successful ransomware attack.

Yet there is one simple, basic security action that is found to be neglected inside many organizations—patch management.

According to Kaspersky's latest Incident Response Analytics Report, patch management combined with robust password policies can reduce the risk of cyberattacks on businesses by 60 percent. Patch management alone was found to decrease the risk of experiencing a security incident by 30 percent, the Moscow-based cybersecurity firm found.

"Security issues with passwords and unpatched software combine into the overwhelming majority of initial access vectors during attacks," Kaspersky researchers noted.

Yet patch management remains a weak spot in many organizations. In 31 percent of successful attacks, the vulnerabilities utilized by adversaries are several months old. Quite a few are greater than one year old. These are well-known, widely publicized security holes for which developers have created approved, free patches.

Major vulnerabilities, for example, have been found in Microsoft Exchange, Fortinet, Cisco, VMware and Java. In many cases, patches had been available for months or, in a few cases, years. Yet some IT departments have failed to deploy them. The U.K.'s National Cyber Security Centre's advisory in April 2021 about unpatched Fortinet virtual private networks drew attention to a vulnerability known as CVE-2018-13379 that had existed for two years. The problem remains unremedied in some organizations to this day.

Similarly, the U.S. Cybersecurity and Infrastructure Security Agency's (CISA's) list of the most exploited common vulnerabilities and exposures includes one dating back to 2017 that impacts Microsoft Office. The alert noted that such vulnerabilities represented easy targets for cybercriminals if they remain unpatched. These security flaws make the hacker's job easy as they represent a well-traveled channel into the enterprise and don't require innovation on the part of the criminals.

Other golden oldies include a Citrix NetScaler bug from 2019, a Microsoft Exchange vulnerability found in early 2020 and an Altassian remote code execution bug that is more than a year old. Patches were issued as soon as these holes were discovered.

"Cyber actors continue to exploit publicly known—and often dated—software vulnerabilities against broad target sets, including public- and private-sector organizations worldwide," CISA said. "However, entities worldwide can mitigate the vulnerabilities by applying the available patches to their systems and implementing a centralized patch management system."

Excuses, Excuses 

Ashley Leonard, CEO of Aliso Viejo, Calif.-based security firm Syxsense, said there are many reasons and excuses offered as to why patches are not deployed. They include a shortage of personnel, IT backlogs, lack of training, carelessness, patch-testing protocols taking too long, and missing or inadequate patch management systems.

He urged organizations to implement automated cloud-based patch management. Efficient patch management processes require an automated patching process that encompasses discovery of all devices and systems, approval of patches, distribution of updates, rebooting of systems, and reporting of patching success.

"To install a patch, you might need to obtain permission from the server owner," Leonard said. "If a reboot is required, it has to be scheduled, and when the process is complete, you should be able to prove compliance."

Traditional patch management systems were designed to protect systems within the corporate firewall. The COVID-19 pandemic has accelerated the move away from premise-based patching tools to cloud patch management that can address devices and workloads spread around home networks and dispersed geographies. The latest tools can also patch a wider range of systems, components and operating systems.

"Organizations have traditionally focused on patching operating systems like Microsoft Windows while ignoring the real threat and patch requirements from third-party applications, operating system drivers, Internet of Things devices and network infrastructure," Leonard said. "We are now seeing customers wanting to understand their entire attack surface and patch everything."

Securing Systems

The Kaspersky report offered tips on how to greatly reduce the threat of an attack on enterprise systems. These include a robust password policy, maintaining a high level of security awareness among employees via comprehensive training, implementing an endpoint detection and response solution, and automated patch management.

"Ensure that patch management or compensation measures for public-facing applications have zero tolerance," the report authors advised. "Regular updates of vulnerability details from software vendors, scanning the network for vulnerabilities and patch installations are crucial for the security of a company's infrastructure."

Drew Robb is a freelance writer in Clearwater, Fla., specializing in IT and business.

HR Technology
Privacy & Security Compliance
Risk Management

Was this resource helpful?

Leave Feedback

SHRM-CP Promo Image
Validate your HR expertise

Earning your SHRM-CP credential makes you a recognized expert and leader in the HR field.

Get Certified


Related Content

(opens in a new tab)
News
How One Company Uses Digital Tools to Boost Employee Well-Being

Learn how Marsh McLennan successfully boosts staff well-being with digital tools, improving productivity and work satisfaction for more than 20,000 employees.

(opens in a new tab)
News
A 4-Day Workweek? AI-Fueled Efficiencies Could Make It Happen

The proliferation of artificial intelligence in the workplace, and the ensuing expected increase in productivity and efficiency, could help usher in the four-day workweek, some experts predict.

(opens in a new tab)
News
Rising Demand for Workforce AI Skills Leads to Calls for Upskilling

As artificial intelligence technology continues to develop, the demand for workers with the ability to work alongside and manage AI systems will increase. This means that workers who are not able to adapt and learn these new skills will be left behind in the job market.

HR Daily Newsletter

Stay up to date with the latest HR news, trends, and expert advice each business day.

Success title

Success caption

Manage Subscriptions
Our Brands

SHRM Foundation Logo
SHRM Executive Network Logo
CEO Circle Logo
SHRM Business Logo
SHRM Linkage Logo
SHRM Labs
Overview


  • About SHRM
  • SHRM India Advisory Council
  • Careers at SHRM
  • Press Room
  • Contact SHRM India
  • Book a SHRM Executive Speaker
  • Ask an Advisor
  • SHRM Newsletter
  • Post a Job
  • Find an HR Job
  • Advertise with us
  • Copyright & Permission
Contact Us


Email: shrmindia@shrm.org
Phone: (1)800.103.2198
WhatsApp: +919810503727

SHRM India Corporate Information

© 2026 SHRM. All Rights Reserved
SHRM provides content as a service to its readers and members. It does not offer legal advice, and cannot guarantee the accuracy or suitability of its content for a particular purpose. Disclaimer

Follow Us

  • LinkedIn
  • Facebook
  • Twitter
  • Instagram
  • YouTube

  1. Your Privacy Choices

  2. Terms of Use

  3. Accessibility

Join SHRM for Exclusive Access to Professional Content

SHRM Members enjoy unlimited access to articles and exclusive member resources.

Already a member? Login
Free Article

Login to unlock unlimited access or join SHRM today to get unlimited access to articles and member-exclusive resources.

Already a member? Login
Limit Reached

You've reached the limit of 1 free article this month. Join to access unlimited articles and member-only resources.

Already a member? Login
Free Article

Login to unlock unlimited access or join SHRM today to get unlimited access to articles and member-exclusive resources.

Already a member? Login
Exclusive Executive-Level Content

You've reached the limit of 1 free article this month. Join the Executive Network and enjoy unlimited content.

Already a member? Login
Unlock Your Career with SHRM Membership

Please enjoy this free resource! Join SHRM for unlimited access to exclusive articles and tools.

Already a member? Login
Join SHRM for Exclusive Access to Professional Premium Content

SHRM Members enjoy unlimited access to articles and exclusive member resources.

Already a member? Login
Join SHRM for Exclusive Access to Student Content

SHRM Members enjoy unlimited access to articles and exclusive member resources.

Already a member? Login
Join SHRM for Exclusive Access to Executive Network Content

SHRM member enjoys unlimited access to articles and exclusive member resources.

Already a member? Login

Your membership is almost expired! Renew today for unlimited access to member content.

Renew now

Your membership has expired. Renew today for unlimited access to member content.

Renew Now

Your Executive Network membership is nearing its expiration. Renew now to maintain access.

Renew Now

Your membership has expired. Renew your Executive Network benefits today.

Renew Now