Security firm Sophos ran a 40-day test of visiting computers from corporate users, and the results aren’t pretty. Four in five of the machines checked were lacking in at least one area of security.
The Sophos Endpoint Assessment Test scans were voluntary and only applied to people visiting from a corporate site, as Sophos’ specialty is business protection, not consumer security. The scan covered three areas: current patch levels, firewalls and up-to-date security software.
They found 81 percent of the 580 computers checked were lacking some key security component; either they didn’t have all of the patches issued by Microsoft, the firewall was disabled, or the antivirus software was out of date or disabled.
The tests found that 63 percent of tested systems were missing at least one Microsoft security patch from Windows, Office, Internet Explorer, Windows Media Player or Adobe’s Flash Player. Meanwhile, 51 percent of endpoints tested had disabled client firewalls and 15 percent had out-of-date or disabled endpoint security software, like an antivirus client.
Sophos then checked with the firms to find out what the story was behind said security failings. The company found people tend to be rather dependent on their software and tools, when the software can’t know everything.
“Some times these tools don’t know what they don’t know,” Bill Emerick, vice president of product management for Network Access Control at Sophos, told InternetNews.com. “I do believe that IT organizations are well-intended and trying to make the right investments. I think in some cases our toolsets are failing us and we have more work ahead of us.”
For example, the survey found most people are relying on Windows Update, which comes with Windows software, but it only checks for Windows patches. To check for fixes to Microsoft Office or other applications, users need Microsoft Update, which is a separate download from Microsoft.
Microsoft did not respond to a query from InternetNews.com to comment on the survey’s findings as of press time.
Exploiting vulnerabilities
The risk for end users is that when Microsoft issues its monthly patches on “Patch Tuesday,” the second Tuesday of the month, malware writers examine the fixes, which points them right at the vulnerabilities. They then write malware to exploit the vulnerabilities that Microsoft has pointed out, hoping to snare people who were slow to patch.
It’s easy to miss a patch from Microsoft. Emerick estimates there are between 600 and 700 total fixes from the company. A common claim is that people don’t patch because their company is concerned it might break applications, but Sophos said that concern is overrated. The more common reason is people just plain forget to do so.
Other reasons for the poor showing: some end users may decline the updates until a later time and then forget to update it later; others disable firewalls on their PCs because they figure the corporate firewall is enough; antivirus end users often make the same assumptions and disable their PC’s security, thinking corporate security is enough.
This article was first published on InternetNews.com.
Huawei’s AI Update: Things Are Moving Faster Than We Think
FEATURE | By Rob Enderle,
December 04, 2020
Keeping Machine Learning Algorithms Honest in the ‘Ethics-First’ Era
ARTIFICIAL INTELLIGENCE | By Guest Author,
November 18, 2020
Key Trends in Chatbots and RPA
FEATURE | By Guest Author,
November 10, 2020
FEATURE | By Samuel Greengard,
November 05, 2020
ARTIFICIAL INTELLIGENCE | By Guest Author,
November 02, 2020
How Intel’s Work With Autonomous Cars Could Redefine General Purpose AI
ARTIFICIAL INTELLIGENCE | By Rob Enderle,
October 29, 2020
Dell Technologies World: Weaving Together Human And Machine Interaction For AI And Robotics
ARTIFICIAL INTELLIGENCE | By Rob Enderle,
October 23, 2020
The Super Moderator, or How IBM Project Debater Could Save Social Media
FEATURE | By Rob Enderle,
October 16, 2020
FEATURE | By Cynthia Harvey,
October 07, 2020
ARTIFICIAL INTELLIGENCE | By Guest Author,
October 05, 2020
CIOs Discuss the Promise of AI and Data Science
FEATURE | By Guest Author,
September 25, 2020
Microsoft Is Building An AI Product That Could Predict The Future
FEATURE | By Rob Enderle,
September 25, 2020
Top 10 Machine Learning Companies 2020
FEATURE | By Cynthia Harvey,
September 22, 2020
NVIDIA and ARM: Massively Changing The AI Landscape
ARTIFICIAL INTELLIGENCE | By Rob Enderle,
September 18, 2020
Continuous Intelligence: Expert Discussion [Video and Podcast]
ARTIFICIAL INTELLIGENCE | By James Maguire,
September 14, 2020
Artificial Intelligence: Governance and Ethics [Video]
ARTIFICIAL INTELLIGENCE | By James Maguire,
September 13, 2020
IBM Watson At The US Open: Showcasing The Power Of A Mature Enterprise-Class AI
FEATURE | By Rob Enderle,
September 11, 2020
Artificial Intelligence: Perception vs. Reality
FEATURE | By James Maguire,
September 09, 2020
Anticipating The Coming Wave Of AI Enhanced PCs
FEATURE | By Rob Enderle,
September 05, 2020
The Critical Nature Of IBM’s NLP (Natural Language Processing) Effort
ARTIFICIAL INTELLIGENCE | By Rob Enderle,
August 14, 2020
Datamation is the leading industry resource for B2B data professionals and technology buyers. Datamation's focus is on providing insight into the latest trends and innovation in AI, data security, big data, and more, along with in-depth product recommendations and comparisons. More than 1.7M users gain insight and guidance from Datamation every year.
Advertise with TechnologyAdvice on Datamation and our other data and technology-focused platforms.
Advertise with Us
Property of TechnologyAdvice.
© 2025 TechnologyAdvice. All Rights Reserved
Advertiser Disclosure: Some of the products that appear on this
site are from companies from which TechnologyAdvice receives
compensation. This compensation may impact how and where products
appear on this site including, for example, the order in which
they appear. TechnologyAdvice does not include all companies
or all types of products available in the marketplace.