• ABOUT US
  • Advertise With Us
  • Contact US
  • Edit Calendar
IT Magazine for Channel Partners in India | SMEChannels
Advertisement
  • Home
  • News
    • AI & ML
    • Cloud Computing
    • Cyber Security
    • Surveillance
    • Automation
    • Server & Storage
    • Power Solutions
    • Networking
  • Hardware News
    • PC-and-Notebooks
    • Component
    • Printers & Peripherals
    • Software
    • Semiconductor
  • Events & Webinars
    • Channel Accelerator Awards 2025
    • Channel Accelerator Awards 2024
    • MSP India Summit 2024
    • MSP India Summit 2023
    • Channel Accelerator Awards 2023
    • SME Channels Summit & Awards 2022
    • SME Channels Summit & Awards 2021
    • WEBINAR
    • SME AWARDS 2020
  • Women in IT
  • Corporate News
  • Interview
  • Executives Movement
  • Partner Corner
No Result
View All Result
  • Home
  • News
    • AI & ML
    • Cloud Computing
    • Cyber Security
    • Surveillance
    • Automation
    • Server & Storage
    • Power Solutions
    • Networking
  • Hardware News
    • PC-and-Notebooks
    • Component
    • Printers & Peripherals
    • Software
    • Semiconductor
  • Events & Webinars
    • Channel Accelerator Awards 2025
    • Channel Accelerator Awards 2024
    • MSP India Summit 2024
    • MSP India Summit 2023
    • Channel Accelerator Awards 2023
    • SME Channels Summit & Awards 2022
    • SME Channels Summit & Awards 2021
    • WEBINAR
    • SME AWARDS 2020
  • Women in IT
  • Corporate News
  • Interview
  • Executives Movement
  • Partner Corner
No Result
View All Result
IT Magazine for Channel Partners in India | SMEChannels
No Result
View All Result
Home Cyber Security

Proprietary Research from Tenable Calculates External Attack Surface of India’s Largest Organizations

SME Channels by SME Channels
July 12, 2023
in Cyber Security, News

Kartik Shahani, Country Manager, Tenable India.

Tenable, Inc. has conducted research exposing critical cyber hygiene issues within India’s largest organizations. The research sheds light on the geographic distribution of assets and unveils alarming problems related to outdated software, weak encryption practices, and misconfigurations. 

On June 28, 2023, an examination of the external attack surface of 25 of India’s organizations with the largest market caps [as listed on Companies Market Cap] was conducted. The findings revealed that the average organization possesses over 12,000 internet-facing assets which are susceptible to potential exploitation, resulting in a total of more than 300,000 assets across the study group. These findings illustrate the immense scale of the cybersecurity architecture that organizations must secure to protect sensitive data and critical systems. 

Looking at the geographical distribution of these assets, the research findings highlight that over 50% of internet-facing assets are located in the United States. Meanwhile, 7% of these assets can be found in India, with an additional 3% dispersed across Finland, the Netherlands, and the British Virgin Islands. This distribution has significant implications from a data protection standpoint, particularly considering the Indian government’s increased emphasis on local data privacy regulations.

“Indian organizations are rapidly embracing cloud migration and emerging technologies, which, in turn, leads to a rise in cyber risk due to the growing number of internet-facing assets. This poses a significant threat to organizations, regardless of their criticality,” explained Kartik Shahani, Country Manager at Tenable India. “In India, we face a dual challenge of limited visibility into the unknown unknowns and poor cyber hygiene. It’s crucial for organizations to understand that cybercriminals do not wait around. They are constantly monitoring attack surface maps to identify the most vulnerable points of entry. Indian organizations must prioritize achieving visibility and protecting their internet-facing assets to effectively mitigate cyber risk.”

Weak SSL/TLS encryption  

One striking observation is that out of the total number of assets for all companies tracked, organizations had nearly 80,000 assets that still support TLS 1.0 [a security protocol first defined in 1999 for establishing encrypted channels over computer networks] that was disabled by Microsoft in September [2022]. This is just one example demonstrating how challenging it’s become for organizations with large internet footprints to identify and update outdated technology. 

Outdated version of Log4J still present
The examination revealed that out of the total assets for all companies tracked, nearly 40,000 are still susceptible to the Log4J vulnerability. This alarming finding highlights a significant concern, as known vulnerabilities like Log4J are the primary cause of a majority of cyberattacks. By relying on outdated versions of Log4J, organizations are leaving themselves exposed to potential cybersecurity breaches.  

Misconfiguration increases external exposure
Another concerning finding was that over 8,000 assets out of the total, initially intended for internal use, have been inadvertently exposed and are now accessible externally. Not hardening these internal assets presents a substantial risk to organizations, as it effectively opens the door for malicious actors to target sensitive information and critical systems.

API vulnerabilities amplify risk 

Furthermore, the identification of more than 4,000 APIs out of the total number of assets among organizations’ digital infrastructure poses a substantial risk to their security and operational integrity. APIs serve as crucial connectors between software applications, facilitating seamless data exchange. However, inadequate authentication, insufficient input validation, weak access controls and vulnerabilities in dependencies within API v3 implementations create a vulnerable attack surface. Such weaknesses can be exploited by malicious actors to gain unauthorized access, compromise data integrity, and launch devastating cyber attacks.

“An alarming reality is that only a handful of organizations possess a comprehensive understanding of their complete digital footprint. One of the most prevalent and perilous security oversights is the inadvertent misconfiguration of cloud and other public-facing resources, making them vulnerable to any attacker on the Internet,” highlighted Nathan Wenzler, chief cybersecurity strategist at Tenable.  

“These ‘unknown unknowns’ make it crucial for every business or government entity to have the ability to discover and remediate previously unknown attack vectors and other points of vulnerability. By proactively preventing attacks rather than merely managing them after they take place, organizations can effectively safeguard their digital infrastructure.” 

 

Previous Post

MSP India Summit 2023 Announces MSP Business Coming of Age

Next Post

PM Modi is in a Hurry for Development of the Nation

Related Posts

Zoom
Networking

Zoom expands enterprise agentic AI platform to orchestrate workflows across collaboration and customer experience

March 11, 2026
Gazal Kalra and Shalabh Gupta, Co-Founders, Nuuk.
Corporate News

Nuuk Partners with Zetwerk to strengthen Make In India Manufacturing

March 11, 2026
Yanbing Li, Chief Product Officer at Datadog.
Cyber Security

Datadog Launches MCP Server to Provide AI Agents with Secure, Real-Time Access to Unified Observability Data

March 10, 2026
Nithya Cadambi, General Manager of Global Centres of Excellence at Commvault
Executives Movement

Commvault Appoints Nithya Cadambi as General Manager of Global Centres of Excellence

March 10, 2026
RAH Infotech
News

RAH Infotech and PointGuard AI Collaborate to Redefine Enterprise AI and Application Security

March 10, 2026
Chandrodaya Prasad
Guest Article

Why the Next Endpoint and SASE Disruption will not Come from a Security Vendor

March 9, 2026

Print Magazine

About Us

SMEChannels is a leading IT Channel magazine, which represents the voice of more than 32,000 partners in India. The focus is to work towards the growth of the entire channel ecosystem. Therefore, the magazine covers all the topics that are relevant to the partner ecosystem. Broadly we cover technologies that go as solutions and services. Therefore, the topics we cover include cloud computing, big data & analytics, security, surveillance, mobility, enterprise applications, data center, 3D printing, robotics, machine learning, IOT, etc.

Contact Us

For Editorial:
Sanjay Mohapatra, Group Editor
Email : sanjay@accentinfomedia.com
Phone No. +91 99100 97969
Manash Ranjan Debata, Editor
Email : manash@accentinfomedia.com

For Print and Online Advertisement :

Sangram Rajeswar, Marketing Lead
Email : sangram@accentinfomedia.com
Phone No. +91 7042135833, +91 9938039199

For Events and Webinar:
Sanjib Mohapatra, Director
Email : sanjib@accentinfomedia.com

Usefull Links

  • ABOUT US
  • Advertise With Us
  • Contact US
  • Edit Calendar
  • ABOUT US
  • Advertise With Us
  • Contact US
  • Edit Calendar

@2026 Powered By SMEChannels Theme By Accent Info Media

No Result
View All Result
  • Home
  • News
    • AI & ML
    • Cloud Computing
    • Cyber Security
    • Surveillance
    • Automation
    • Server & Storage
    • Power Solutions
    • Networking
  • Hardware News
    • PC-and-Notebooks
    • Component
    • Printers & Peripherals
    • Software
    • Semiconductor
  • Events & Webinars
    • Channel Accelerator Awards 2025
    • Channel Accelerator Awards 2024
    • MSP India Summit 2024
    • MSP India Summit 2023
    • Channel Accelerator Awards 2023
    • SME Channels Summit & Awards 2022
    • SME Channels Summit & Awards 2021
    • WEBINAR
    • SME AWARDS 2020
  • Women in IT
  • Corporate News
  • Interview
  • Executives Movement
  • Partner Corner

@2026 Powered By SMEChannels Theme By Accent Info Media