In light of the cyber attack targeting SolarWinds, security and risk professionals are working to identify instances of the Orion software within their organization -- including their broader partner ecosystem -- and reduce their exposure. How responsive have organizations been to the SolarWinds hack?

Bitsight is leveraging our continuous collection of security performance and software usage data on 260,000 organizations across 24 sectors to track the prevalence of Orion -- including trojanized versions of the software -- and observe steps taken by organizations to reduce their exposure.
Bitsight observes that many organizations with publicly exposed trojanized versions of Orion have acted over the last 3 days to remove those instances from the Internet or to patch them:
- Since Dec. 14, we have observed a 71% decline in organizations with publicly exposed trojanized versions of Orion
- We observed a 63% decline in organizations with publicly exposed trojanized versions of Orion on Dec. 16
- We observed an additional 8% decline in organizations with publicly exposed trojanized versions of Orion on Dec. 17
While these efforts may shut off further penetration, organizations once using trojanized versions of Orion may have been compromised since March; FireEye and Microsoft have suggested that a smaller number of organizations may have been impacted.