This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

A Hitchhiker’s Guide to the 2020 National • Industry • Cloud Exposure Report (NICER)

Download resources

About this session

Tod Bearsley, a research director at Rapid7, and Bob Rudis, the company's chief data scientist, present the 2020 National, Industry and Cloud Exposure Report (NICER), a free, science-focused survey of the internet with a deliberate deep dive on Canada. They explain their method: Project Sonar's internet-wide full-protocol scans paired with a global network of honeypots that captures attacker behaviour. Across roughly 330 million discovered IPs they define exposure as dangerous services, outdated software, unencrypted protocols and DDoS amplifiers. Canada ranks ninth most exposed, with tens of thousands of SMB, RDP and Telnet endpoints that have no business on the internet, plus large volumes of unpatched routers. The pair repeatedly stress that these numbers, though slowly declining thanks to ISP filtering, are echoed worldwide, and note that the pandemic did not blow perimeters open as feared; instead traffic consolidated behind HTTPS. They puncture the assumption that the cloud is inherently secure, describing it as where organisations lift-and-shift legacy junk, and give guidance for security teams, cloud providers and national cyber centres.

Rapid7 has built upon four years of work measuring the internet for National Exposure Index (NEI) and Industry Cyber Exposure (ICER) reports to create the most comprehensive, modern atlas of internet-facing services to-date. This session will provide an overview of the findings, including a comparison of the internet pre- and post-pandemic, along with a guide for how to digest the 150-page deep-dive into 24 critical internet protocols and services.   

Key takeaways

  • Get dangerous services off the public internet: SMB and Telnet have no legitimate reason to be exposed, and RDP belongs behind a VPN, not directly online.
  • Treat both high and medium severity vulnerabilities as remediation targets; medium findings often mean information leaks (passwords, connection strings) that are one step from remote code execution.
  • Scan your own external attack surface continuously, because everyone else already scans you and hones exploits against exposed services risk-free.
  • Do not assume the cloud is secure by default; lift-and-shift puts legacy insecure services (like plain FTP) online, so review cloud security controls explicitly.
  • Lean on ISPs and national cyber centres to block junk protocols; that pressure, more than user diligence, is what is slowly driving SMB, Telnet and RSYNC exposure down.

Speakers

Tod Bearsley
Tod Bearsley
Research Director · Rapid7
Bob Rudis
Bob Rudis
Chief Security Data Scientist · Rapid7

Resources

Tags

More from GoSec 2020

Also from Tod Bearsley

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.