Recent Bitsight research shows that 75% of retail businesses may be at increased risk of ransomware attacks as indicated by poor TLS/SSL configuration management. With the holiday shopping season upon us, it's more important than ever for retailers to evaluate their security posture.
Large retail businesses may have hundreds or even thousands of TLS/SSL certificates identifying specific Internet-connected devices. Plus, many lack an organization-wide framework for discovering, cataloging, and managing TLS/SSL configurations. Instead, management is conducted on an ad hoc basis, usually at a departmental level.
While poor TLS/SSL management does not directly result in successful ransomware attacks, Bitsight has found that it is a good indicator of overall security hygiene.
“Bitsight believes that the use of deprecated, insecure TLS protocols often indicates that an organization is unable or unwilling to upgrade to newer, supported technology,” said Ethan Geil, Senior Director, Data and Research at Bitsight. “If they are unable to fix SSL, it is likely that they are unable to patch other, more critical vulnerabilities, as well. Continuing to support insecure protocols is a symptom of poor security hygiene in general.”
