1. Ransomware Risk
Outdated systems are low-hanging fruit for cybercriminals looking to perpetrate ransomware attacks.
When Bitsight analyzed hundreds of ransomware events to estimate the relative probability that an organization will be a ransomware target, we found that those with a poor patching cadence correlated with increased ransomware risk. In fact, organizations with a patching cadence grade of D or F were more than seven times more likely to experience a ransomware event compared to those with an A grade.
Despite the clear risk, many organizations lack the visibility to know where security gaps exist so they can proactively fend off ransomware attacks or mitigate their effects. Read our guide—How to Avoid Ransomware—to learn more.
2. Business and Functional Disruption
Outdated systems can also cause major business disruption. Consider the many interconnected devices on your network, from IoT sensors and devices at the edge to cloud-based infrastructure and services. Outdated software on any of these devices can expose your entire digital infrastructure and data to cyber risk.
For example, in the healthcare sector outdated and unpatched medical devices, such as MRI machines, insulin pumps, and defibrillators, are increasingly targeted by threat actors. According to an FBI alert:
- 53 percent of connected medical devices in hospitals have known critical vulnerabilities. Approximately one third of healthcare devices have an identified critical risk potentially implicating technical operation and functions of medical devices.
- If these systems aren't patched or secured, per the FBI, they could “…negatively impact an organization’s operational functions, overall safety, data confidentiality, and data integrity.
3. Third-Party Breach
While it’s critical that you discover and remediate the risk posed by outdated systems inside your organization, it’s just as important to assess your third parties. For instance, if a vendor manages your sensitive data and accesses your network using an outdated browser or operating system, they could inadvertently expose your data to risk.
Similarly, if you host data in the cloud, a hacker could exploit an unpatched security vulnerability in a cloud provider’s web application firewall appliance and take control of the device or reach into the network where your data is housed.
4. Mobile Device Compromise
As your business grows, the more mobile devices get connected to your network. Studies show that two out of three people (67 percent) use their own devices to complete work and 55 percent of employees solely use their mobile devices for work while traveling.
If one of these mobile devices is running an outdated operating system or browser, your corporate network could be compromised. Despite the fact that mobile phone updates often provide important security updates and bug fixes, many employers don’t have BYOD security policies in place or a means to enforce them. Security teams also have a difficult time monitoring BYOD usage or seeing when personal devices connect to the network.
Despite the fact that mobile phone updates often provide important security updates and bug fixes, many employers don’t have BYOD security policies in place or a means to enforce them. Security teams also have a difficult time monitoring BYOD usage or seeing when personal devices connect to the network.
5. Internet of Things (IoT) Risk
Connected IoT devices such as webcams, medical sensors, smart devices, digital twins, GPS trackers, industrial robots, and environmental sensors can cause extensive damage if they operate on outdated software while being linked to the corporate network.
The compromise of one IoT device can impact your entire organization and its connected supply chain. This can result in delays in operations and financial loss far beyond the impacted device.
By 2030, there will be 29 billion connected IoT devices, making it almost impossible to manually inventory and monitor their security postures.