The Times Australia
News From Asia

.

Trend Micro Warns Devices and Accounts are Highest-Risk Assets

Cyber Risk Report highlights critical vulnerability, offers new ways to prioritize risk management

HONG KONG SAR - Media OutReach Newswire - 2 October 2024 - Trend Micro Incorporated (TYO: 4704; TSE: 4704), a global cybersecurity leader, today urged network defenders to gain greater visibility into risk across their attack surface, after unveiling a new study* which provides granular metrics by region, company size, industry, asset type and more.

To read a full copy of the report, Intercepting Impact: 2024 Trend Micro Cyber Risk Report, please visit: https://www.trendmicro.com/vinfo/hk/security/news/cybercrime-and-digital-threats/intercepting-impact-2024-trend-micro-cyber-risk-report

Jon Clay, VP of threat intelligence at Trend Micro: "Trend's cyber risk report shares key insights on where risks are greatest within organizations such as weak security controls, misconfigurations, and unpatched actively exploited vulnerabilities. Shifting towards a more risk-based approach to cybersecurity—discovering the entire attack surface, using AI to calculate the actual risk, and providing mitigating controls advice—allows an organization to improve its cybersecurity posture like never before. This is a game changer for the industry."

Using a risk event catalog, the Trend Vision One™ platform calculates a risk score for each asset type and an index for organizations by multiplying an asset's attack, exposure, and security configuration by impact. An asset with low business impact and few privileges has a smaller attack surface, while higher-value assets with more privileges have a larger attack surface.

The following assets are the most at risk:

  • Devices: 22.6 million total devices, with 877,316 classified as high-risk.
  • Accounts: 53.9 million total accounts, with 12,346 classified as high-risk.
  • Cloud Assets: 14.5 million total cloud assets, with 9,944 classified as high-risk.
  • Internet-Facing Assets: 1.1 million total, with 1,661 classified as high-risk.
  • Applications: 8.8 million total applications, with 489 classified as high-risk.

The number of high-risk devices is much higher than that of accounts, even though there are more accounts in total. Devices have a larger attack surface—i.e., they can be targeted with more threats. However, accounts are still valuable as they can grant threat actors access to various resources.

Elsewhere, the report also found:

  • Americas has the highest average risk index among regions, with an average risk index rating of 43.4, driven by vulnerabilities in the banking sector and critical infrastructure and the region's attractiveness to profit-driven actors.
  • Europe is the quickest region to patch vulnerabilities, indicating strong security practices.
  • Mining has the highest risk score of any vertical due to its strategic position in global supply chains and large attack surface.
  • Pharmaceuticals are the fastest sector to patch vulnerabilities by several days, reflecting the importance of protecting sensitive data.
  • The top detected risk event is accessing cloud applications with a high risk level based on historical application data, known security features, and community knowledge.
  • Old and inactive accounts, accounts with disabled security controls, and sensitive data being sent outside the network are other risk events with high event counts.
The report also uncovered many weak configurations that could lead to compromise, especially around security control settings.

As the threat landscape continues to evolve, organizations' ability to identify and manage risks is becoming increasingly crucial. The Trend Vision One™ platform, with its integrated Attack Surface Risk Management (ASRM), provides the necessary tools for comprehensive threat visibility and effective risk mitigation.

The following steps are recommended to help mitigate cyber risk:

  1. Optimize product security settings to get alerts on misconfigurations.
  2. When a risky event is detected, contact the device and/or account owner to verify the event. Investigate the event using the Trend Vision One™Workbench search function to find more information about or check event details on the product management server.
  3. Disable risky accounts or reset them with a strong password and enable multi-factor authentication (MFA).
  4. Apply the latest patches or upgrade application and operation system versions regularly.

*The report is based on telemetry data from Trend Micro's Attack Surface Risk Management (ASRM) solution in its flagship cybersecurity platform, Trend Vision One™, plus the native eXtended Detection and Response (XDR) tools. It's divided into two sections: the user side covers risk in assets, processes, and vulnerabilities, while the adversary side maps adversary behaviors, MITRE, and TTPs. Data points are based on telemetry from December 25, 2023, to June 30, 2024.
Hashtag: #trendmicro #trendvisionone #visionone #cybersecurity #cyberrisk #cyberriskindex





The issuer is solely responsible for the content of this announcement.

Trend Micro

Trend Micro, a global cybersecurity leader, helps make the world safe for exchanging digital information. Fueled by decades of security expertise, global threat research, and continuous innovation, Trend Micro's AI-powered cybersecurity platform protects hundreds of thousands of organizations and millions of individuals across clouds, networks, devices, and endpoints. As a leader in cloud and enterprise cybersecurity, Trend's platform delivers a powerful range of advanced threat defense techniques optimized for environments like AWS, Microsoft, and Google, and central visibility for better, faster detection and response. With 7,000 employees across 70 countries, Trend Micro enables organizations to simplify and secure their connected world.

Times Magazine

Building an AI-First Culture in Your Company

AI isn't just something to think about anymore - it's becoming part of how we live and work, whether we like it or not. At the office, it definitely helps us move faster. But here's the thing: just using tools like ChatGPT or plugging AI into your wo...

Data Management Isn't Just About Tech—Here’s Why It’s a Human Problem Too

Photo by Kevin Kuby Manuel O. Diaz Jr.We live in a world drowning in data. Every click, swipe, medical scan, and financial transaction generates information, so much that managing it all has become one of the biggest challenges of our digital age. Bu...

Headless CMS in Digital Twins and 3D Product Experiences

Image by freepik As the metaverse becomes more advanced and accessible, it's clear that multiple sectors will use digital twins and 3D product experiences to visualize, connect, and streamline efforts better. A digital twin is a virtual replica of ...

The Decline of Hyper-Casual: How Mid-Core Mobile Games Took Over in 2025

In recent years, the mobile gaming landscape has undergone a significant transformation, with mid-core mobile games emerging as the dominant force in app stores by 2025. This shift is underpinned by changing user habits and evolving monetization tr...

Understanding ITIL 4 and PRINCE2 Project Management Synergy

Key Highlights ITIL 4 focuses on IT service management, emphasising continual improvement and value creation through modern digital transformation approaches. PRINCE2 project management supports systematic planning and execution of projects wit...

What AI Adoption Means for the Future of Workplace Risk Management

Image by freepik As industrial operations become more complex and fast-paced, the risks faced by workers and employers alike continue to grow. Traditional safety models—reliant on manual oversight, reactive investigations, and standardised checklist...

The Times Features

What Is the Dreamtime? Understanding Aboriginal Creation Stories Through Art

Aboriginal culture is built on the deep and important meaning of Dreamtime, which links beliefs and history with the elements that make life. It’s not just myths; the Dreamtime i...

How Short-Term Lenders Offer Long-Lasting Benefits in Australia

In the world of personal and business finance, short-term lenders are often viewed as temporary fixes—quick solutions for urgent cash needs. However, in Australia, short-term len...

Why School Breaks Are the Perfect Time to Build Real Game Skills

School holidays provide uninterrupted time to focus on individual skill development Players often return sharper and more confident after structured break-time training Holid...

Why This Elegant Diamond Cut Is Becoming the First Choice for Modern Proposals

Personalised engagement styles are replacing one-size-fits-all traditions A rising diamond cut offers timeless elegance with a softer aesthetic Its flexible design wo...

Is sleeping a lot actually bad for your health? A sleep scientist explains

We’re constantly being reminded by news articles and social media posts that we should be getting more sleep. You probably don’t need to hear it again – not sleeping enough i...

Ricoh Launches IM C401F A4 Colour MFP to Boost Speed and Security in Hybrid Workplaces

Ricoh, a leading provider of smart workplace technology, today launched the RICOH IM C401F, an enterprise-grade A4 colour desktop multifunction printer (MFP) designed for Austral...