Armis Identifies the Riskiest Assets Introducing Threats to Global Businesses
Armis, the leading asset visibility and security company, today released new research identifying the riskiest connected assets posing threats to global businesses. Findings highlight risk being introduced to organizations through a variety of connected assets across device classes, emphasizing a need for a comprehensive security strategy to protect an organization’s entire attack surface in real-time.
This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20230905844605/en/
Source: Data from the Armis Asset Intelligence Engine collected between August 2022 and July 2023.
“Continuing to educate global businesses about the evolving and increased risk being introduced to their attack surface through managed and unmanaged assets is a key mission of ours,” said Nadir Izrael, CTO and Co-Founder of Armis. “This intelligence is crucial to helping organizations defend against malicious cyberattacks. Without it, business, security and IT leaders are in the dark, vulnerable to blind spots that bad actors will seek to exploit.”
Armis’ research, analyzed from the Armis Asset Intelligence Engine, focuses on connected assets with the most attack attempts, weaponized Common Vulnerabilities and Exposures (CVEs) and high-risk ratings to determine the riskiest assets.
Assets With The Highest Number of Attack Attempts
Armis found the top 10 asset types with the highest number of attack attempts were distributed across asset types: IT, OT, IoT, IoMT, Internet of Personal Things (IoPT) and Building Management Systems (BMS). This demonstrates that attackers care more about their potential access to assets rather than the type, reinforcing the need for security teams to account for all physical and virtual assets as part of their security strategy.
Top 10 device types with the highest number of attack attempts:
- Engineering workstations (OT)
- Imaging workstations (IoMT)
- Media players (IoT)
- Personal computers (IT)
- Virtual machines (IT)
- Uninterruptible power supply (UPS) devices (BMS)
- Servers (IT)
- Media writers (IoMT)
- Tablets (IoPT)
- Mobile phones (IoPT)
“Malicious actors are intentionally targeting these assets because they are externally accessible, have an expansive and intricate attack surface and known weaponized CVEs,” said Tom Gol, CTO of Research at Armis. “The potential impact of breaching these assets on businesses and their customers is also a critical factor when it comes to why these have the highest number of attack attempts. Engineering workstations can be connected to all controllers in a factory, imaging workstations will collect private patient data from hospitals and UPSs can serve as an access point to critical infrastructure entities, making all of these attractive targets for malicious actors with varying agendas, like deploying ransomware or causing destruction to society in the case of nation-state attacks. IT leaders need to prioritize asset intelligence cybersecurity and apply patches to mitigate this risk.”
Assets With Unpatched, Weaponized CVEs Vulnerable to Exploitation
Researchers identified a significant number of network-connected assets susceptible to unpatched, weaponized CVEs published before 1/1/2022. Zooming in on the highest percentage of devices of each type that had these CVEs between August 2022 and July 2023, Armis identified the list reflected in Figure A. Unpatched, these assets introduce significant risk to businesses.
Assets with a High-Risk Rating
Armis also examined asset types with the most common high-risk factors:
- Many physical devices on the list that take a long time to replace, such as servers and Programmable Logic Controllers (PLCs), run end-of-life (EOL) or end-of-support (EOS) operating systems. EOL assets are nearing the end of functional life but are still in use, while EOS assets are no longer actively supported or patched for vulnerabilities and security issues by the manufacturer.
- Some assets, including personal computers, demonstrated SMBv1 usage. SMBv1 is a legacy, unencrypted and complicated protocol with vulnerabilities that have been targeted in the infamous Wannacry and NotPetya attacks. Security experts have advised organizations to stop using it completely. Armis found that 74% of organizations today still have at least one asset in their network vulnerable to EternalBlue – an SMBv1 vulnerability.
- Many assets identified in the list exhibited high vulnerability scores, have had threats detected, have been flagged for unencrypted traffic or still have the CDPwn vulnerabilities impacting network infrastructure and VoIPs.
- Half (50%) of pneumatic tube systems were found to have an unsafe software update mechanism.
Additional research from Armis is available on the riskiest OT and ICS devices across critical infrastructure industries as well as the riskiest medical and IoT devices in clinical environments.
Learn more about Armis at www.armis.com.
About Armis
Armis, the leading asset visibility and security company, provides the industry’s first unified asset intelligence platform designed to address the new extended attack surface that connected assets create. Fortune 100 companies trust our real-time and continuous protection to see with full context all managed, unmanaged assets across IT, cloud, IoT devices, medical devices (IoMT), operational technology (OT), industrial control systems (ICS), and 5G. Armis provides passive cyber asset management, risk management, and automated enforcement. Armis is a privately held company and headquartered in California.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20230905844605/en/
Contact information
Rebecca Cradick
Senior Director, Global Communications
Armis
pr@armis.com
About Business Wire
For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Ant International’s WorldFirst launches Enterprise Solution to Power Enterprises Global Growth25.11.2025 05:59:00 EET | Press release
WorldFirst, Ant International’s global account service provider, has launched an API-integrated and AI-driven solution tailored to global enterprises It leverages WorldFirst's unified global account, full-range financial services, and AI capabilities such as smarter treasury management to help streamline global funds distribution, unlock new revenue streams, and strengthen customer relationships. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251124796928/en/ WorldFirst CEO Clara Shi unveiled the new enterprise solution at Ant International’s Global Voyage Event in Singapore McKinsey research predicts that within six years, digital platforms will facilitate over 30%—about $60 trillion—of global economic activity. Yet as enterprises operate digitally and expand globally, they face critical financial obstacles: inefficient payments, high costs, compliance complexity, and fragmented customer experience—all creating friction tha
Original “Titanic Cherub” From James Cameron’s Epic Film Heads to Auction December 9 & 1024.11.2025 22:48:00 EET | Press release
One of the most recognizable and beloved set pieces from James Cameron’s Titanic heads to auction on December 9 &10 —the original Grand Staircase Cherub, seen in multiple scenes of the 1997 blockbuster, including the pivotal moment when Jack and Rose meet in front of the First Class Dining Room and the climactic moment when the Atlantic Ocean bursts through the skylight and floods the staircase, and cherub. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251124056883/en/ The iconic “cherub” with Leonardo DiCaprio & Kate Winslet in James Cameron’s “TITANIC”. The ornate fixture—crafted for the full-scale recreation of Titanic’s Grand Staircase—was gifted by the production to Martin Biallas, CEO of SEE Global Entertainment, whose immersive exhibitions have brought the world’s most famous ship to millions of fans. It now resurfaces as a rare offering in Heritage Auctions’ Entertainment & Music Memorabilia Signature Auction (Sale
Access Advance Announces Major Growth in Its HEVC and VVC Patent Pools24.11.2025 17:10:00 EET | Press release
Access Advance LLC today announced significant expansions of both its HEVC Advance and VVC Advance Patent Pools during the second and third quarters of 2025, underscoring continued industry confidence in the company's balanced and transparent approach to video codec licensing. This growth follows the successful January 2025 launch of Access Advance's Video Distribution Patent ("VDP") Pool, demonstrating the company's expanding role in comprehensive video codec patent licensing solutions. Among the many highlights, Sharp Corporation joined the HEVC Advance Patent Pool as a Licensor, bringing valuable intellectual property assets to the pool's already extensive patent portfolio. Additionally, Huawei Technologies Co., Ltd., already an HEVC Advance Licensor and Licensee, expanded its collaboration with Access Advance by joining the VVC Advance Patent Pool as a Licensee. HP Inc. also expanded its license to include the VVC Advance Patent Pool after previously joining HEVC Advance in 2024, w
Andersen Global Strengthens Platform in Turkey with Addition of Member Firm24.11.2025 16:30:00 EET | Press release
Andersen Global enhances its presence in Turkey as Celen Corporate Property Valuation & Counseling Inc. becomes Andersen in Turkey, adding breadth to the capabilities provided under the Andersen brand in the country. Founded in 1995 and led by Managing Partner Guniz Celen, the Istanbul-based firm delivers a broad spectrum of services for domestic and international clients. With expertise in real estate corporate finance, tangible and intangible asset valuation, and asset management, Andersen in Turkey delivers solutions that support complex corporate finance decisions to clients in more than 18 countries. “Our mission has always been to provide solutions to the most complex challenges in the real estate and investment sectors,” said Guniz. “Joining the Andersen brand strengthens our capabilities as a trusted advisor and gives us access to global resources, enabling us to create even greater long-term value for our clients.” Global Chairman and CEO of Andersen Mark L. Vorsatz added, “Ce
Microsize and Schedio Group to Acquire Lonza’s Micro-Macinazione Site in Switzerland24.11.2025 16:05:00 EET | Press release
Microsize, a leading CDMO specializing in particle size reduction and control technologies, today announced it has signed an agreement to acquire Micro-Macinazione (Mic Mac), a dedicated micronization facility in Monteggio, Switzerland, from Lonza. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251124545344/en/ The agreement represents Microsize’s second acquisition from Lonza, following the successful 2022 divestment of its Quakertown, Pennsylvania site. In this transaction, Schedio Group – a Swiss-based provider of jet mills, isolators, spray dryers, and engineering services – is investing alongside Microsize to strengthen and localize its operational base in Europe, advancing a shared vision to lead the next generation of integrated particle engineering solutions. With more than 30 years of experience, Mic Mac has served the pharmaceutical industry with proven GMP-compliant jet milling and micronization capabilities for b
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
