
The number of cyberattacks has been increasing at an unprecedented rate. I wish this statement, which we have been making for years now, was no longer true, but the sad and cold reality is that cyberattacks continue to hit businesses of all sizes.
Two reasons attacks keep increasing
Attacks are more far-reaching today than ever. One of the easiest means for hackers to penetrate networks now is increasing their reach, and their malware is able to spread further and faster than ever before. With networks remaining unpatched and users still susceptible to even common phishing attacks, it is easier for hackers to expand their targets than to morph their attack types.
While many attackers are merely increasing the volume of attacks in expectation of hitting more victims by the rule of numbers, some very crafty hackers are increasing their sophistication to outthink IT departments, simultaneously targeting multiple attack vectors. That focus on innovation, along with the speed and volume at which threats are administered, has made for increasingly successful campaigns against organizations that remain completely unprepared.
What a vulnerability scanner actually finds
A vulnerability scanner assesses a variety of vulnerabilities across your network, including computers, network systems, operating systems, and software. It can also identify weaknesses related to vendors, system admins, and users.
- Vendor-based issues range from software bugs, missing patches, vulnerable services, insecure configurations, and web app vulnerabilities. Since most vendors are not security-focused, they do not incorporate security in their products, leaving you less secure than you ever would have imagined.
- System admin issues. In most assessments we perform, we see admin access given to people who should not have it, or a lack of password policies.
- User-generated issues. Users share credentials with peers, fail to run virus scanning software, land on malicious sites, or unsuspectingly introduce backdoor vulnerabilities.
The benefits
Scanning against an updated database of known vulnerabilities is one of the easiest ways to identify both internal and external threats. When a new device connects, the scanner should detect any potential threats and identify rogue machines. And you likely do not have a clue how many devices connect to your network at any given time. Continual scanning lets you manage and track that.
What to keep in mind
Network scans are simply snapshots in time. If you do not see vulnerabilities at the moment you assess the network, threats that are very real may not present themselves, and you may be clueless when an attack strikes. Vulnerability scanners also only report cut-and-dry information. They will not determine what your response should be, and if you are simply relying on a tool to tell you the state of your network, you may be badly misjudging your security.
Scans themselves can pose threats. If you do not know what you are doing, a scan may crash an already vulnerable server, and scans may use enough network resources to jeopardize continuity. There is also the risk of improper handling of results. In some cases attackers have obtained security vulnerability information directly from network scans and easily exploited the loopholes.
And the most obvious reason to get an assessment: the bad guys are running network scans against you this very minute. Cyber criminals are scanning the internet looking for networks with vulnerabilities, using the very tools the good guys use, to hack into, penetrate, steal, and exploit your business data.



