70 percent of Windows environments at risk from malicious attacks

IT admins report heightened interest in visibility: configurations, settings and standards.

  • 8 years ago Posted in
ManageEngine has published the results of the global ManageEngine Active Directory and Windows Server Security - Trends and Practices Survey, 2016. Among the critical findings is that 70 percent of IT administrators across the globe say that their Windows environments are at risk of malicious attacks.

Over the past few years, the success rate of attacks, both internal and external, on corporate networks has been growing. At the centre of most corporate networks is Active Directory. Since Active Directory is the most important technology to control access to the network and resources, it is important to secure all aspects of this portion of a network.

However, the growing success rate of attacks suggests that many organisations do not secure Active Directory correctly. Recently, ManageEngine conducted a survey to better understand the common security practices followed by IT admins that specialise in Active Directory and Windows Server. The full survey and results from 327 practitioners is available at https://www.manageengine.com/products/active-directory-audit/windows-ad-security-survey.html.

"Organisations clearly are paying closer attention to the security for Active Directory," said Derek Melber, technical evangelist for ManageEngine and microsite manager of Security Hardening for Active Directory and Windows Servers. "However, the survey results also indicate that Windows environments are far from being secure, and improved overall visibility is essential."

Active Directory and Windows Server Security - Trends and Practices

Analysis of the survey results reveals key factors that influence security. It also outlines important suggestions for the year ahead regarding security of Windows environments. In turn, organisations can enhance security measures to ensure a more secure and smoother environment to run business operations. Insights into various aspects of Windows environment security include:

  • Awareness of and concern about internal attacks
  • Interest in a security solution with change notification alerts
  • Ease of accessing current Windows security settings
  • Knowledge of current Windows security standards
  • Frequency of using tools to generate security reports

Survey Highlights

  • 70 percent of respondents agree that their Windows environments are not completely secure from malicious attacks, while another 10 percent admit to being unaware of the security standards for Windows environments.
  • 72 percent of respondents seek a solution that sends alerts when security configurations change, yet 55 percent have not begun to use one.
  • 47 percent of IT admins find it difficult and time consuming to gain awareness of the current security settings of their Windows environments. A small percentage of respondents use scripts but find it tedious.

Inferences from the Survey Findings

  • The results clearly indicate that organisations need to take immediate action to secure their Windows environments.
  • The findings imply a visibility gap in the market. Despite the market availability of solution providers, at least half the organisations do not use a configuration alert system and may need to perform requirement-to-solution mapping to reduce this gap.
  • For efficient management of their Windows environments, IT admins could benefit from exploring available reporting solutions.
Research shows ‘game needs to be changed,’ with security innovation years behind that of the...
73% of organizations lack automated patch management, and 62% experienced incidents involving...
Quest Software has signed a definitive agreement with Clearlake Capital Group, L.P. (together with...
Dell EMC PowerProtect Cyber Recovery for AWS provides a fast, easy-to-deploy public cloud vault to...
Aqua’s cloud native application protection platform becomes the only solution that protects cloud...
54% of organisations working on a security transformation project now or in the next 12 months.
Node4 has released its Mid-Market IT Priorities Report 2021. The independent report reveals that...
Zscaler Zero Trust exchange cloud-based architecture enables superior green security capabilities...