Urgent.News

What's breaking now, across thousands of outlets.

Tech

Why your business can't trust the data behind its own security decisions

Your asset data may be lying to you and it's putting your entire security strategy at risk.

Why your business can't trust the data behind its own security decisions

In a traditional IT setting, a critical vulnerability alert typically does not cause concern for the business's operational continuity. Affected devices can be identified and patched quickly. However, when this alert arises in cyber-physical systems (CPS) such as hospital imaging equipment, factory control systems, or HVAC networks, confirming whether the alert applies to a specific device can take days and often results in a guess rather than a definitive answer.

This uncertainty is a common problem, which is especially alarming given that CPS assets often form the backbone of critical infrastructure like energy and healthcare. The main reason for this widespread issue is poor visibility into CPS, which stems from the lack of product codes and inconsistent naming conventions. These systems were initially designed for physical reliability, not digital labeling, leading to devices reporting themselves differently depending on the protocol or integration.

Similarly, many devices lack an operating system version or name, making it difficult to match devices to known vulnerabilities. This complexity is further compounded by CVE advisories, which are compiled from patchy vendor data, often resulting in incomplete advisories. For business leaders, these issues add another layer of concern to their already anxiety-ridden state regarding threat visibility.

However, resolving this issue starts with shifting the focus from merely knowing a device exists on the network to understanding what it does, what process depends on it, and what happens if it is compromised. Specialized tools and automated approaches are necessary to manage the eclectic and proprietary nature of CPS assets. Implementing AI-driven mapping techniques can significantly improve product code identification, while automated responses to CVE alerts can ensure a prioritized and confident response, similar to that expected from a good vulnerability management program.

Ultimately, treating asset data quality as a board-level risk issue, rather than just IT housekeeping, is crucial to achieving a resilient security posture.

Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at techradar.com →

More in Tech

More from Thursday 3 September →