Demo of the CyCognito Platform

See the CyCognito platform in action to understand how it can help you identify, prioritize and eliminate your most critical risks. 

State of External Exposure Management, Summer 2024 Edition

Download the report now to stay ahead of emerging threats and strengthen your organization’s security posture for 2024. 

The Total Economic Impact™ of The CyCognito Platform

Read The Total Economic Impact™ of The CyCognito Platform — a Forrester study. Cost Savings And Business Benefits Enabled By The CyCognito Platform. 

 
Research

This Holiday Shopping Season, Your Attack Surface is Open for Business

Emma-Zaballos
By Emma Zaballos
Product Marketing Manager
November 21, 2023

Cyber Monday is right around the corner. Celebrated on the Monday after Thanksgiving, this annual holiday has become one of the most anticipated shopping events each year since its inception in 2005.

The National Retail Foundation and Adobe Analytics found that over 77 million people spent upwards of 11 billion dollars on Cyber Monday in 2022.

This November 27 is no exception. Millions of consumers will flock to ecommerce websites in search of the best deals. Along the way, they will provide their personally identifiable information (PII) – credit cards, addresses, even passports – to carry out transactions. 

But can shoppers be assured that the sites they do business with are secure and compliant? 

CyCognito research reveals that, unbeknownst to them, consumer PII may be at great risk.

Cyber Monday Ecommerce Security Pitfalls

Ecommerce organizations, like many businesses today, live in the cloud. In fact, over half (52%) of ecommerce web apps are hosted in the cloud.

But as our research has uncovered, ecommerce applications, cloud or not, are not without security gaps. 

Insecure Sockets, Unlocked Storefronts: 

2% of ecommerce web apps still lack HTTPS. With over 26 million ecommerce stores worldwide, this figure could impact 520,000 sites. 

WAFs are MIA: 

Over a quarter (28%) of ecommerce web apps lack a web application firewall (WAF).

One in four (24%) ecommerce web apps that collect PII are missing a WAF.

Keep an eye on PII: 

58% of all ecommerce web apps collect user PII.

Missing cookies consent:

78% of all ecommerce web apps fail to ask users to consent to cookies, creating a potential compliance headache for the organization.

Buyer beware! – multiple security issues amp up risks

Trust issues: 

13% of ecommerce web apps have certificate validity issues.

Broken protocols: 

Nearly half (48%) of ecommerce web apps have one or more cryptographic vulnerabilities. 

Criminal discounts, critical issues: 

2% of ecommerce web apps have at least one critical security issue. Half of those web apps contain PII. 

Over three quarters (76%) of the critical issues found in ecommerce web apps are also easily exploitable.

Stung by OWASP: 

7% of all ecommerce web apps under monitoring have at least one issue from the OWASP Top Ten list. 

Easy as (pumpkin) pie: 

Almost one third (31%) of ecommerce web apps have at least one easily exploitable issue. 

Cyber Monday is just once a year – active security testing shouldn’t be

Cyber Monday is filled with urgency – the urgency of getting a good deal, on the shoppers’ side, and the urgency of capitalizing on the biggest ecommerce days of the year for retailers. Cybercriminals take advantage of this urgency to exploit misconfigurations and vulnerabilities, which can cause massive reputational damage to inattentive organizations in the process. 

This holiday shopping season, retailers need to take the time to ensure that ecommerce websites aren’t putting shoppers at risk. Checking for low-hanging fruit, like missing WAFs or expired certificates, can serve as indicators of more serious security issues. 

If your organization owns ecommerce sites, you need complete peace of mind. Prioritize actively testing across the entire ecosystem of ecommerce sites. By testing for all issues continuously, not just once a year or once a quarter, your security team will have time to identify, prioritize and remediate potentially serious vulnerabilities that could result in stolen PII and frustrated shoppers. 

Methodology

For this report, CyCognito’s research team aggregated and analyzed ecommerce web application assets across its customer base in September 2023. All findings are anonymized and normalized. These customers span multiple industry verticals and include a mix of small, medium, and large enterprises across the globe, including Fortune 500 companies.


Topics



Search the Blog



Recent Posts






Tim Matthews
How to Budget for EASM
By Tim Matthews
November 18, 2024


Top Tags



CyCognito Research Report

State of External Exposure Management, Summer 2024 Edition

State of External Exposure Management, Summer 2024 Edition

Download the report now to stay ahead of emerging threats and strengthen your organization’s security posture for 2024.

O'Reilly Report

Moving from Vulnerability Management to Exposure Management

Moving from Vulnerability Management to Exposure Management

Download the report to learn about the historical trends behind the emergence of exposure management, how to develop a strategic plan and assemble a team to smoothly transition frameworks, and example tech stacks to consider for your organization.

Request a Free Scan

See Exactly What Attackers See

Get a Free Scan of Your Attack Surface

Get a free scan of your attack surface and gain valuable insight into your organization's risk posture by allowing CyCognito to discover, contextualize, and test externally exposed assets on a portion of your parent company or a single subsidiary.