Checkmate on 94% of critical assets in just four moves

Issue 2 2022 News & Events

XM Cyber, a hybrid cloud security company, announced findings from its first annual Impact Report. Attack Path Management Impact Report: 2021 Year in Review incorporates insights from nearly two million endpoints, files, folders and cloud resources throughout 2021. The XM research team analysed the methods, attack paths and impacts of attack techniques that imperil critical assets across on-premises, multi-cloud and hybrid environments and developed tips for thwarting them.

Today’s security tools enable organisations to detect all kinds of misconfigurations, vulnerabilities and other security gaps. However, they fail to show how these seemingly unrelated issues form hidden attack paths that hackers can use to pivot through a hybrid cloud environment and compromise critical assets.

XM’s Impact Report takes the attackers’ perspective to show how, once they get a foothold in the network, they can easily move towards critical business assets. The report was enabled by the company’s namesake attack path management platform, which allows users to see all of the ways that hackers can leverage attack paths across cloud and on-premises environments, aiding mitigation and prevention efforts.

Key insights include:

• 94% of critical assets can be compromised within four steps of the initial breach point.

• On average, 75% of an organisation’s critical assets can be compromised in their current security state.

• 73% of the top attack techniques involve mismanaged or stolen credentials.

• 95% of organisational users have long-term access keys attached to them that can be exposed.

• 78% of businesses are open to compromise every time a new Remote Code Execution (RCE) technique is found.

• The main attack vectors in the cloud are misconfigurations and overly permissive access.

• By knowing where to disrupt attack paths, organisations can reduce 80% of issues that would otherwise have taken up security resources.

An attack path is a chain of attack vectors (vulnerabilities, misconfigurations, user privileges, human errors, etc.) that a hacker can use to move laterally through the network. Hybrid cloud computing architecture is especially vulnerable as attackers can exploit security gaps to obtain a foothold in the network and then move laterally between on-premises and cloud applications. XM Cyber’s report outlines the security gaps and hygiene issues that exist in multiple attack paths across on-premises and cloud environments, demonstrating the importance of risk visibility across the entire network.

“Modern organisations are investing in more and more platforms, apps and other tech tools to accelerate their business, but they too often fail to realise that the interconnection between all these technologies poses a significant risk,” said Zur Ulianitzky, head of research, XM Cyber. “When siloed teams are responsible for different components of security within the network, nobody sees the full picture. One team may ignore a seemingly small risk, not realising that in the big picture it’s a stepping stone in a hidden attack path to a critical asset. To keep pace with today’s technology and business demands, attack path remediation must be prioritised.”

Highlights of the report include:

• Methodology and synopsis of the attack path.

• The top attack techniques used to compromise critical assets in 2021.

• New attack techniques used in 2021.

• Cross-platform attack insights.

• Key findings across on-prem and cloud.

To download the XM Cyber Research Impact Report, visit https://info.xmcyber.com/2022-attack-path-management-impact-report or use the short link: www.securitysa.com/*xm1




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

The line between locking residents out and restricting their access
News & Events Security Services & Risk Management Residential Estate (Industry)
A June 2026 High Court judgment has clarified one of the most contested issues in modern estate governance: when an HOA's digital access restrictions amount to unlawful self-help or spoliation, and when they do not.

Read more...
Compressing cyberattack timelines and targeting ungoverned AI identities
Information Security News & Events
Sophos AI Security 2026 report finds attackers are moving beyond experimentation and operationalising AI for attacks using identity as the primary initial access vector, rather than inventing new attack types.

Read more...
SAFPS urges taxpayers to remain alert to fraud
Security Services & Risk Management News & Events
The SAFPS warns taxpayers about evolving SARS scams this tax season, highlighting common fraud tactics, practical prevention tips, and trusted reporting channels to stay protected.

Read more...
Dallmeier extends software maintenance up to 10 years
Dallmeier Electronic Southern Africa Surveillance News & Events
Dallmeier is expanding its software maintenance offering and now provides an additional maintenance package for cameras and recorders, enabling customers to keep their video security systems up to date for up to 10 years.

Read more...
Sophos launches AI-native cybersecurity defence system
News & Events Information Security Security Services & Risk Management
Built for a threat landscape reshaped by AI, Sophos Fusion unites security operations, endpoint, network security, identity, email, and cloud into one defence system that prevents, detects, investigates, and responds at AI speed.

Read more...
ONVIF releases Profile V draft for cloud video without vendor lock-in
News & Events Surveillance
The cloud profile will give system integrators, consultants and end users a standards-based way to build and maintain cloud video systems using ONVIF-conformant products from different manufacturers.

Read more...
Video surveillance market faces faster growth, and 2026 price shock
Surveillance News & Events
Novaira Insights has released its 2026 edition of The World Market for Video Surveillance Hardware and Software, highlighting a stronger global growth profile in 2025, tentative improvements in China’s market outlook, and unprecedented price increases in 2026.

Read more...
Stop supplier fraud at the moment of payment
News & Events Security Services & Risk Management
Cape Town-built platform bridges the gap between onboarding and transaction by securing identity inside the live channels where companies exchange invoices and banking details.

Read more...
Enter the Global Tech Innovator 2026 Competition
News & Events
KPMG One Africa calls on Africa’s most innovative tech entrepreneurs from the 13 One Africa member firm countries across southern Africa, East Africa, and West Africa to submit their applications before Sunday, 2 August 2026.

Read more...
From the editor's desk: The high price of cheap
Technews Publishing News & Events
Bringing fire and safety, along with intrusion and perimeter protection, into the same publication is an interesting exercise. At their core, all these systems exist for one reason: to warn people ...

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.