Insights ·

Five interesting cybersecurity facts

By Nanorisk

Five interesting cybersecurity facts

A few facts worth knowing - not the usual statistics recycled from vendor whitepapers.

1. The average dwell time for an attacker inside a network before detection is still measured in days to weeks, not hours. Early detection depends on having something worth detecting against.

2. Most phishing campaigns don't need a convincing email - they need one person to click. Success rates on targeted campaigns regularly exceed 30% even in security-aware organisations.

3. CVSS scores measure severity, not exploitability in your environment. A critical-rated vulnerability behind a properly segmented network carries less real risk than a medium-rated one sitting on an exposed admin interface.

4. Credential stuffing attacks don't require any hacking skill. Billions of valid username and password combinations from historic breaches are freely available. If your users reuse passwords, that's your exposure.

5. The most common initial access vector in reported incidents isn't a zero-day - it's a known, unpatched vulnerability. Patch cadence remains one of the highest-value controls available.

None of these are new. That's rather the point - the fundamentals don't change, but they still aren't being applied consistently. If you want to understand where your organisation actually sits against these risks, that's exactly what a structured assessment is for.

Concerned this affects you?

We can assess your exposure and tell you plainly where you stand.

← All insights