The XM Cyber 2022 Attack Path Management Impact Report is the industry’s first annual report that reveals the likelihood and impact of a breach, analyzes the attack techniques used to compromise an organization’s critical assets, and shares best practices to keep our most critical assets protected. In the 2022 attack path management research report, the XM Cyber research team analyzed nearly 2 million entities to bring insights on the methods, attack paths and impacts of attack techniques that compromise critical assets across on-prem, multi-cloud and hybrid environments, and developed tips for preventing them.
The Impact report begins with a close look at the methodology of attack paths and then reveals the impact of attack techniques used to compromise critical assets across organizations. It then goes on to share some striking statistics about how exposures across the enterprise lead to critical asset compromise. Analysis covers various environments including on-prem, cloud, multi cloud and hybrid networks to share how attackers are propagating the network.
What XM Cyber discovered was that 94% of critical assets can be compromised in just 4 hops or less from the initial breach point. That’s leveraging just 4 attack techniques with the majority of attacks that take place involving more than just 1 hop to reach an organizations’ critical assets. It is during the network propagation stage, once the attacker is inside the network, that the attacker is trying to connect different vulnerabilities and exploits together to breach critical assets. The disconnect: you can see your cloud security controls, but you can’t see the hidden attack paths between your on-prem and cloud environments
XM Cyber then saw that 75% of an organizations’ critical assets can be compromised in their then-current security state, because without seeing how the attacker sees your misconfigurations, vulnerabilities and mismanaged credentials in context to your critical assets, you are simply left exposed. The disconnect: you can see tons of security issues, but you can’t see which ones really matter. And not so surprisingly, 73% of the top attack techniques used to compromise critical assets involve mismanaged or stolen credentials.
In many cases, abused domain credentials give the attacker the initial breach point into your network and allows them to do further reconnaissance, pick a target, and move laterally until they compromise the critical asset. The disconnect: you can see which users potentially need access, but you can’t see which ones can expose your critical assets.