SANS Endpoint survey results released: Endpoint Security processes and visibility remain challenges

Centralised logging and automation solutions are now a necessity to detect, defend against and respond to modern attacks, according to the SANS 2019 Endpoint Protection and Response Survey released by SANS Institute. These solutions include data analytics tools – such as security information and event management (SIEM) and endpoint detection and response (EDR) – as well as anomaly detection technologies like user behaviour monitoring and machine learning.

SANS instructor and survey co-author, Justin Henderson, said: “Attacks often start on employee workstations, then pivot to critical data sources on servers. That makes endpoints ground zero for protecting an organisation’s assets. But defending them from attacks isn’t easy.”

In fact, 39% of survey respondents have concerns about employee-owned mobile devices and lack processes to cover them in corporate policy. Employer-owned devices fare better, with only 25% being concerned about such endpoints and unable to cover them in organisational security plans. This lack of control may be related to the fact that fewer than 27% of employee-owned laptops and mobile devices are centrally managed.

“Due to the never-ending nature of cyberattacks, it is vital that organisations collect the data that will enable them to quickly identify the attack, mitigate any damage and remediate the issues,” according to survey co-author and SANS instructor John Hubbard. “However, due to the complex nature of logging and multitude of data sources, many organisations struggle to gather the proper data they need to conduct efficient incident response and remediation activities.”

While 11% of respondents report an inability to identify what data has been breached, and 66% find it difficult, the SANS survey indicates that a combination of file access auditing, DLP and EDR solutions might help organisations that struggle with these activities. The 2019 survey also shows that the use of next-generation endpoint controls is increasing within organisations. Anomaly detection increased by 10% and machine learning solutions increased by 12%. Even tools such as automation tools and vulnerability scanners increased in implementation by 5% year-over-year.

Other statistics identified in the report included: 62% of breaches can be identified within the first 24 hours, 28% of survey respondents confirmed that attackers had accessed endpoints with Phishing identified as the top attack vector (cited by 57.8% of respondents), followed by browser-based drive-by download attacks (51.8%) and then credential theft or compromise (48.2%).

For more security news visit here.

About Security Buyer

Security Buyer is the leading authority in global security content, delivering expert news, in-depth articles, exclusive interviews, and industry insights across print, digital, and event platforms. Published 10 times a year, the magazine is a trusted resource for professionals seeking updates and analysis on the latest developments in the security sector.

To submit an article, or for sponsorship opportunities, please contact our team below.

Rebecca Spayne picture 2025

Rebecca Spayne

Managing
EDITOR

Georgina Turner image

Georgina Turner

Sales
Manager

Afua Akoto image - Security Buyer

Afua Akoto

Marketing Manager

Read the Latest Issue

Follow us on X

Follow us on X

Click Here

Follow us on LinkedIn

Follow us on LinkedIn

Click Here

Advertise here

Reach decision makers and amplify your marketing

Advertise here

Click Here

Related News

SANS

SANS Institute to Enhance Regional Security Awareness

SANS Institute, the global leader in cybersecurity training and certifications, has announced SANS Dubai February 2023 to be held in-person…
SANS

Nozomi Networks Sponsored SANS Survey

Nozomi Networks Inc., OT and IoT security, announced the SANS 2022 OT/ICS Cybersecurity Report finds ICS cybersecurity threats
SANS

Celebrating 15 Years of Online Training

Celebrating 15 Years of Online Training, SANS Institute Announces Updated OnDemand Training Platform. Provides Improved…
SANS

SANS brings Cyber Safari training

SANS Institute has announced the SANS Cyber Safari 2022 training programme to be held at the JW Marriot Hotel Riyadh from 1-13 October, 2022
SANS

Big Interview – Ned Baltagi

Security Buyer Middle East catches up with Ned Baltagi, Managing Director, Middle East, and Africa at SANS Institute for a Big Interview
ned baltagi

SANS announces Summer Dunes 2022

SANS Institute has announced the SANS Summer Dunes 2022 training program, to be held in person from June 18 to June 23, 2022.
Ned Baltagi

SANS announces its biggest ever Gulf Region Cyber Security Training Event in Dubai

SANS Institute, the world leader in cyber security training and certification, returns to Dubai in November with its biggest yet Gulf Region event
SANS Institute

SANS Institute to deliver its first ever cyber security training event in Oman at SANS Muscat 2019

SANS Institute has announced SANS Muscat 2019 will be held in Oman, from April 27, 2019 to May 2, 2019 at the InterContinental Hotel, Muscat.
Scroll to Top