3 ms·
The 85% number sounded really odd and specific. Turns out the 85% number is quoted from the "Top 30 Targeted High Risk Vulnerabilities" published in 2015[1], w
by randomdrake 9y ago
The 85% number sounded really odd and specific.
Turns out the 85% number is quoted from the "Top 30 Targeted High Risk Vulnerabilities" published in 2015[1], which came from Public Safety Canada's "Top 4 Strategies to Mitigate Targeted Cyber Intrusions" also from 2015[2], which came from the Australian Signals Directorate's report "Top four mitigation strategies to protect your ICT system" from 2012[3], which says (emphasis mine):
"At least 85% of the intrusions that ASD responded to in 2011 involved adversaries using unsophisticated techniques that would have been mitigated by implementing the Top 4 mitigation strategies as a package."
A far cry from "as many as 85 percent of all targeted attacks" quoted from Intel in 2018.
[1] - https://www.us-cert.gov/ncas/alerts/TA15-119A https://www.us-cert.gov/ncas/alerts/TA15-119A
[2] - https://www.publicsafety.gc.ca/cnt/ntnl-scrt/cbr-scrt/tp-strtgs-en.aspx https://www.publicsafety.gc.ca/cnt/ntnl-scrt/cbr-scrt/tp-str...
[3] - https://www.asd.gov.au/publications/protect/top_4_mitigations.htm https://www.asd.gov.au/publications/protect/top_4_mitigation...