It should come as no surprise that the cybersecurity landscape has been changing dramatically throughout the year 2020. According to Bitsight research, up to 85% of the workforce in some industries has shifted to remote work in response to the COVID-19 pandemic — introducing corporate devices to a variety of new and evolving cyber threats. While malicious actors are taking advantage of this opportunity to advance their nefarious objectives, security teams are racing to adapt to our “new normal” operating environment so that they can continue to effectively mitigate risk across their growing attack surfaces.
This new cybersecurity climate offers a variety of challenges for private enterprises, but perhaps even more so for government entities — which may lag behind their private sector counterparts in certain areas that optimize remote work, such as cloud adoption. At the same time, these agencies are facing new regulations, such as the California Consumer Privacy Act (CCPA) and the New York State Department of Financial Services (NYDFS) Cybersecurity Regulation, which place new requirements on state CIOs and CISOs to manage their own security performance and develop an effective third-party risk management program. To make matters more complex, public security incidents continue to be on the rise. In fact, over 70 state and local governments across the United States suffered from ransomware attacks last year.
Now, more than ever, state CIOs and CISOs are facing increased pressure to demonstrate that they have the right risk management program in place. In an effort to understand the latest state government cybersecurity trends, we dove into our Bitsight Security Ratings data — analyzing the largest areas of improvement, the top risk vectors of concern, and more.
Breaking down the average state security ratings
Bitsight Security Ratings are calculated using externally observable data on compromised systems, security diligence, user behavior, and public disclosures. These four data categories are comprised of various risk vectors, including everything from botnet infections and exposed credentials to open ports and patching cadence.
In the Bitsight platform, each of the 50 United States has its own rating that provides an independent and objective measurement of its security posture. As of August 2020, the average Bitsight Security Rating for the 50 states as a whole was 530. And if you imagine, for a moment, that the 50 states represent an entire industry, this rating is considerably lower than that of its private sector peers.
Here’s a breakdown of the average Bitsight Security Ratings for a sample of private industries during this same time period:
- Finance: 720
- Legal: 710
- Healthcare/Wellness: 700
- Technology: 690
Of course, not all states are created equal when it comes to their security posture. While some states have Bitsight Security Ratings in the 700 range, others have ratings in the low 400s. That being said, looking at the average rating for the 50 states portfolio as a whole empowers us to identify some key trends and challenges in the local government space.
Where have the 50 states seen the largest security posture improvement?
Let’s start with the good news: When looking at this data set for the period of February to July 2020, we found that this group improved their overall security performance in a variety of risk vectors. In the chart below, increasing a grade in a particular risk vector indicates that the states in question reduced their risk exposure in that area.
|
Risk Vector |
Percentage of States That Increased Their Grade |
Percentage of States That Decreased Their Grade |
|
Server software: This risk vector analyzes versions of commonly installed IT infrastructure software. |
46% (23 states) |
2% (1 state) |
|
Botnet infections: This risk vector observes a unified network of machines that perform actions instructed by malware creators. |
46% (23 states) |
2% (1 state) |
|
Desktop software: This risk vector analyzes any potential vulnerabilities in versions of commonly installed operating systems. |
42% (21 states) |
12% (6 states) |
|
Unsolicited communications: This risk vector looks at any host that is observed trying to contact a server on another host that is not expected or supported. |
20% (10 states) |
0% (0 states) |
What were the top risk vectors of concern?
Now that we have a basic understanding of the areas in which the 50 states have improved their security posture, let’s take a deep dive into the other end of the spectrum. When looking at this data set for the same 6-month period, we found that there were two main areas of concern: patching cadence and SSL configurations.