HP releases the 2012 Cyber Security Risk Report

The HP 2012 Cyber Risk Report is an annual collaboration among groups within HP Enterprise Security Products that gives organizations a view into the threat landscape that can help them determine how to best deploy their limited resources to reduce their security risk.

Key findings include:

  • Web applications remain a popular and viable attack vector, due in no small measure to a lack of both organizations and developers to correct longstanding vulnerabilities.
  • Old and new technologies alike introduce new security vulnerabilities. Both mobile application vulnerabilities and SCADA vulnerabilities have seen dramatic increases over the past five years.
  • Even though the amount of critical vulnerabilities as a percentage of total vulnerability disclosures has dropped, this has not served to make enterprises safer, but in fact harder to secure.

Delivering Security Intelligence to the modern enterprise

Enterprises and governments are experiencing the most aggressive threat environment in the history of information technology. Disruptive computing trends greatly increase productivity and business agility—but at the same time, introduce a host of new risks and uncertainty. Based on market-leading products from ArcSight, Atalla, Fortify and TippingPoint, the HP Security Intelligence and Risk Management platform enables your business to take a proactive approach to security that integrates information correlation, deep application analysis and network-level defense mechanisms—unifying the components of a complete security program and reducing risk across your enterprise.

 
Application Security (Fortify)Application Security (Fortify)

A suite of tightly integrated solutions and processes for ensuring proactive application security

Quickly and affordably test the security of ANY code through our cloud-based security as a service

Protect your company from security attacks against applications in production

Integrate vulnerability analysis across the entire software life cycle—from development to QA testing and to deployed applications

Reduce business risk by finding, prioritizing and fixing vulnerabilities that pose the biggest threat

Thoroughly analyze complex web applications and services

Information Security (ArcSight)Information Security (ArcSight)

Complete visibility into internal and external threats, breaches, fraud and risks across the IT infrastructure

Out-of-the box connectors to collect, consolidate and normalize data to unify searching, reporting and analysis

Powerful enterprise security management software for analyzing and correlating every event that occurs across your organization

A security management software solution for collecting log activity, consolidating information for storage efficiency and correlating events

An application built on HP's SIEM platform for monitoring user activity across accounts, applications and systems

Universal log management solution for collecting machine data from any log generating source that unify searching, storing, and analysis

Suite of content that delivers log review and security monitoring based on security and audit best practices—helps organizations meet a broad set of regulatory compliance requirements and institute a strong IT governance program

Integrated Security SolutionsIntegrated Security Solutions

Industry-leading products and world-class professional services tailored to the way you do business

An APT solution that provides the intelligence you to identify and remediate APTs and security threats in your network

A cloud security solution for mitigating threats and complying with security regulations in virtual and cloud infrastructures

A customized security intelligence service for protecting sensitive data stores against loss and theft

A customized solution for detecting and mitigating security and privacy breaches by monitoring data access

A modular IT risk and compliance solution that maps IT devices to business services and gives CISOs pinpoint decision intelligence

Protect your company from security attacks against applications in production

Visibility into potential insider threats gained by identifying suspicious or risky user behavior

A customized global service that lets you use centralized logging to comply with SOX, PCI, FISMA, HIPAA, etc.

Mobile device, (iPhone, iPad and Android) security to reduce mobile application risk

Network transparency and adaptive monitoring to help you maintain integrity and availability

Correlate security events with current, reliable reputation-based security threat intelligence.

Professional consulting services to help you build, mature and maintain world-class security operations

Expert consultants and education, industry-tested security technology and a secure development process model

Your foundation for collecting, analyzing, and storing data for effective risk management and compliance

Network and Cloud Security (TippingPoint)Network and Cloud Security (TippingPoint)

Next Generation Network Security for Physical, Virtual and Cloud Networks powered by HPTippingPoint X-Armour

Best-in-class threat protection for virtualized and cloud infrastructure based on proven data center solutions

Next-generation intrusion prevention system for protecting against advanced persistent threats and cyber attacks

Centralized, global vision and policy control for large-scale deployments of all HP TippingPoint platforms

An easy-to-use SSL appliance to keep encrypted attacks from compromising web servers and applications

Payments and Data Security (Atalla)Payments and Data Security (Atalla)

A comprehensive solution for protecting, managing and controlling access and keeping data highly available

High-performance hardware security module for cryptographic processing solutions and key management for card payments authorization and ATM/POS PIN verification

Secure key management to reduce the risk of data encryption and reputation damage and ease regulatory compliance

Security Education and Technical SupportSecurity Education and Technical Support

Prompt, 24 X 7 access to technical support engineers, online portal, upgrades, incident status, and more

In-depth support for HP Atalla Security products and expert instruction in their installation and use.

Flexibly delivered instruction for every level of experience with HP ArcSight, Fortify and TippingPoint

Professional training courses focused on skills and knowledge specific to HP Fortify technologies

Dedicated technical support for resolving HP Fortify product issues

Professional training courses focused on skills and knowledge specific to HP TippingPoint technologies

Comprehensive incident support and technical assistance for resolving HP TippingPoint product issues

Security ResearchSecurity Research

Actionable security intelligence to proactively identify threats and manage risk

Offers IT managers the ability to manage and control applications and bandwidth use across the enterprise.

An application for creating custom HP TippingPoint Next Generation IPS security filters to proactively protect your assets

An industry-leading lab specializing in vulnerability discovery, analysis and protection

Industry-leading security research to help you find, fix, and prevent security vulnerabilities in software

An extensive database of malicious IP and DNS entries for identifying and denying access to malicious actors

An easy-to-use, real-time threat-monitoring portal for evaluating the threat landscape and guiding IPS policy changes

Adaptive web application firewall technology added to the HP TippingPoint Next Generation IPS (NGIPS)

A program with nearly 3,000 researchers diligently finding and disclosing security vulnerabilities

Focus on security across the enterprise.

This HP Software community focuses you as an IT leader and delivers actionable insights to help you focus on security across the enterprise.

Manage risk in an insecure world

Security expert Bruce Schneier discusses accepting that you can’t “get in front” of security threats and risk management.

Manage risk in an insecure world

 

Download HP ArcSight Logger for FREE!

Events