WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts Organizations that Scan Applications in Production Have a Reduced Risk of Being Breached
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Organizations that Scan Applications in Production Have a Reduced Risk of Being Breached

Author: Charles Egli

Created: Thursday, August 15, 2019 - 18:30

Categories: Cybersecurity

In its 2018 Application Security Statistics Report, WhiteHat Security advocates for organizations to scan their applications for vulnerabilities while they are in production to reduce risks, costs, and complexity in the long run. “We find that organizations that take this approach experience markedly better AppSec outcomes – notably a 50 percent drop in window of exposure, an important metric that represents the amount of time that an application has a serious vulnerability that can be exploited to data breaches,” said Setu Kulkarni, WhiteHat’s vice-president of strategy and business development. Essentially, organizations that scan applications in production have a greatly reduced risk of being breached. WhiteHat cites its own data as well as that from the 2018 Verizon Data Breach Investigations Report (available on the WaterISAC portal), which notes that web applications were the biggest target for data breaches, as indicators that a new, fully integrated approach is needed. Read the report ay WhiteHat Security.

Related Resources

(TLP:CLEAR) Vulnerability Notification – Critical Vulnerability in Fortinet EMS Actively Exploited, CVE-2026-35616

May 29, 2026 in Cybersecurity, Security Preparedness

(TLP:CLEAR) GAO Report: Actions Needed to Address Persistent Cybersecurity Threats to the Water and Wastewater Sector

May 28, 2026 in Cybersecurity, Federal & State Resources, OT-ICS Security

(TLP:CLEAR) FBI Releases Multiple Alerts on Credential Theft and Evolving Ransomware Intrusion Techniques

May 28, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar