[Hands-On Defense] Unpatched Software Causes 33% of Successful Attacks

Stu Sjouwerman | May 23, 2023

JasperArt_2023-05-23_09.45.05_4As you all know, KnowBe4 frequently promotes security awareness training and we also mention that unpatched software is a distant number two issue after social engineering.

We generally say that unpatched software is involved in 20%-40% of successful exploits. It's been hard though to get good figures on that for years and even CISA has not published hard numbers, even though they appear to focus on it. They have definitely seen an increase of successful attacks against unpatched software and firmware...but at what overall percentage?

Unpatched software is responsible for 33% of successful attacks
 
Well, this article (https://www.action1.com/patching-insights-from-kevin-mandia-of-mandiant/) states that Kevin Mandia (who created Mandiant, which sold to Google recently) says unpatched software is responsible for 33% of successful attacks. Mandia is a true veteran, and we greatly trust anything he says. Social engineering is likely involved in 70% to 90% of successful attacks, as a comparison.

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.