Page 20 - Cyber Warnings
P. 20







Venafi Survey: Many Organizations Overlook Threats Hiding in

Encrypted Traffic

By Tim Bedard, director of threat intelligence and analytics for Venafi



Encryption plays a critical role in the safety and security of our digital economy. Whether it’s
protecting data from malicious actors or government intrusion, encryption provides
organizations with strength, integrity and privacy.

Encryption usage is on the upswing, especially with unpredictable geopolitical situations driving
data protection concerns. For example, almost three-fourths (72%) of security professionals say
they are more concerned about data privacy. As a result, two-thirds of security professionals
(66%) say their organizations are considering increasing their use of encryption.

But as we adopt these solutions, cyber criminals are finding ways to hide attacks inside the very
encrypted traffic that is designed to protect your privacy. These tactics will only become worse
as the drive for encryption continues to explode. After all, a recent study from A10 Networks
found that 41% of cyber attacks used encryption to evade detection.

But, are organizations successfully responding to these growing cyber risks? During RSA
Conference 2017, one of the largest information security events in the world, Venafi conducted
a survey to see if security professionals are properly defending themselves against threats
hiding in encrypted communications.

More than 1540 attendees participated in the survey, and unfortunately, the responses revealed
major gaps in their protection.

Interesting highlights from the survey included the following:

• Nearly a quarter of the respondents (23%) had no idea how much of their encrypted
traffic was decrypted and inspected.


• 41% of respondents thought they could detect and respond to a cyber attack hidden in
encrypted traffic within one week. Additionally, 20% believed they could detect and
respond to a cyber attack within 24 hours.


• A surprising number of respondents (41%) said they encrypted at least 70% of their
internal network traffic. Additionally, 57% said they encrypted 70% or more of their
external web traffic.

Ultimately, it’s pretty alarming that nearly one out of four security professionals is unaware if
their organization is actively looking for threats hiding in encrypted traffic.


20 Cyber Warnings E-Magazine – May 2017 Edition
Copyright © Cyber Defense Magazine, All rights reserved worldwide

   15   16   17   18   19   20   21   22   23   24   25