• About Us
King of Computer Media
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
King of Computer Media
No Result
View All Result

Home - Anti-Virus Software and Internet Security - Trend Micro 2025 Information Security Risk Report: Global enterprise information security resilience continues to improve, and proactive information security governance becomes the core of the trend

Trend Micro 2025 Information Security Risk Report: Global enterprise information security resilience continues to improve, and proactive information security governance becomes the core of the trend

KOCPC Editor by KOCPC Editor
April 11, 2025 - Updated on August 4, 2026
in Anti-Virus Software and Internet Security, Latest Technology News

Trend Micro (Tokyo Stock Exchange stock code: 4704), a global leader in network security, recently released the latest “Trend Micro 2025 Security Risk Report”, revealing the current status and trends of global enterprise security governance. The report shows that the scores of global enterprises on the Cyber ​​Risk Index (CRI) are declining year by year. The average CRI score in 2024 will be 38.4 points, a decrease of 6.2 points from 2023, reflecting the significant improvement in the information security protection and risk management capabilities of enterprises after the introduction of proactive information security solutions.

Trend Micro 2025 Security Risk Report: Proactive Security Governance Becomes the Core of the Trend

“Trend Micro customers are embracing our proactive security vision and using AI-driven Trend Vision One™ Cyber ​​Risk Exposure Management to identify risks and prioritize their prevention. With this advantage, they can build security resilience, quickly contain threats, and use time and resources more efficiently. With the right mentality and tools, any enterprise can follow this approach to security management,” said Jin Jingxiu, President of Trend Micro Enterprise Platform.

Jin Jingxiu emphasized that proactive information security governance combined with the correct mentality and tools allows enterprises to not only build solid information security resilience, but also to quickly respond and suppress risks in the face of increasingly complex threats, while improving the efficiency of resource and time utilization.

In the past year, although global enterprises as a whole are still in the “moderate risk” range, the CRI score has dropped from 42.5 points in February 2024 to 36.3 points in December, indicating that corporate information security governance is moving in the direction of more active and continuous evaluation, and has begun to make risk-oriented decisions.

This trend shows that traditional static defense strategies are no longer able to cope with the current ever-changing threat environment. Enterprises are gradually turning to dynamic and continuous security assessments and examining the effectiveness of security strategies through quantitative indicators.

According to this year’s report, the following is a summary of key points:

Cloud applications become the most dangerous source of risk

The report points out that the most threatening security incident in 2024 is “access to dangerous cloud applications”, followed by “idle Microsoft Entra ID accounts”, indicating that there are major gaps in enterprises’ identity authentication and access management (IAM) in cloud environments. Other top ten security risks are related to email security, user account management, and login credential protection, and most risks are closely related to incorrect configuration settings.

It is worth noting that more than 1 billion organizations around the world do not enable multi-factor authentication (MFA) when logging into Entra ID accounts, showing that enterprises still have obvious deficiencies in automated identity protection mechanisms and need to accelerate their implementation to reduce exposure.

Mean time to patch (MTTP): Europe and Japan perform best

According to report statistics, the most frequently detected and unpatched vulnerabilities in 2024 are “elevation of privilege” (EoP) vulnerabilities released in the first half of the year, which are of high severity. Judging from the vulnerability patching time in different regions and industries, Europe (23.5 days) and Japan (27.5 days) have the best MTTP performance; in terms of industry, non-profit organizations (19 days) and the technology industry (22 days) are the fields with the fastest vulnerability patching speed.

On the other hand, the medical industry (41.5 days) and the telecommunications industry (38 days) are the industries with the slowest vulnerability patching speed, indicating that they still need to improve their information security resource allocation or operating procedures. Trend Micro provides virtual patches to protect customers on average three months before manufacturers release official patches.

Industry and regional risk inventory: education, energy and agriculture are the most vulnerable

The report pointed out that the industries with the highest CRI and the greatest exposure in 2024 are education, communications, energy and agriculture, showing that the information security protection of these industries is still relatively weak and they are easily targeted by attackers.

From a regional perspective, Europe’s CRI score improved the most, falling by 7 points in response to the implementation of information security regulations such as NIS2 and DORA. The Americas and Asia, Middle East and Africa (AMEA) regions still have room for improvement. Japan once again demonstrates its leading position in information security governance, with an average CRI score of only 34.3, the lowest in the world.

Ransomware and emerging AI threats emerge

The report pointed out that among the information security incidents reported in 2024, LockBit, RansomHub and Play ransomware were the three main ransomware threats. Trend Micro research found that companies with a CRI above the average are about 12 times more likely to encounter ransomware attacks than companies with a CRI below the average, showing that good information security governance can significantly reduce the risk of attacks.

In addition, the rise of AI technology not only brings more protective tools to enterprises, but also breeds new threat types. For example, AI-assisted deepfake phishing, virtual kidnapping scams, and automated hacker detection have become new challenges for information security defense. However, AI has also become the best assistant for security personnel. Trend Micro uses its own large-scale language model (LLM) for security, Trend Cybertron, to help enterprises more accurately predict and defend against cyberattacks.

 

Promoting proactive security governance: Recommended actions companies should take

In order to help global enterprises further reduce CRI scores, Trend Micro recommends that enterprises adopt the following proactive security governance measures:

Optimization of security settings:Enterprises should give full play to the capabilities of their security products to ensure that when configuration errors, vulnerabilities or other risks occur, they can receive timely alert notifications and establish complete visibility of the attack surface.

Quickly contact the device or account holder:When a high-risk event is detected, the relevant device or account holder can be proactively contacted through the Trend Vision One Workbench search function to facilitate quick confirmation and investigation.

Inventory and manage idle accounts:Enterprises should delete unused idle accounts, deactivate risky accounts, reset strong passwords, and fully enable multi-factor authentication (MFA) to reduce identity authentication risks.

Regularly apply the latest patch updates:Enterprises need to develop the habit of regularly checking and applying the latest patch updates or upgrading application and operating system versions to reduce the risk of system vulnerabilities.

The “Trend Micro 2025 Information Security Risk Report” reveals that corporate information security governance has entered a new era of active defense and continuous risk assessment. With the deepening of digital transformation and the popularization of cloud environments, information security is no longer a simple defense issue, but an important core of corporate operational resilience and competitiveness. If global enterprises can actively introduce AI technology, strengthen their information security governance structure, and promote continuous information security assessment and risk-oriented decision-making, they will surely gain key competitive advantages in this ever-changing era of cyber threats.

Download the detailed content of Trend Micro’s 2025 Information Security Risk Report

Source: KOCPC Chinese

Tags: Information securityTrend Micro

Recent Posts

  • The Xiaomi Pad 8S Pro has passed network access certification and will debut with the self-developed XRING O3 chip.
  • The entire Google Pixel 11 lineup has been leaked! Official promotional renders of the Pixel 11 Pro XL have also surfaced
  • Are Chinese phone battery capacities falsely labeled? A brief look at the “capacity locking” phenomenon in Chinese silicon-carbon batteries.
  • NCC is leaderless, recklessly sending out national-level alert messages!?
  • What does “QR” in QR Code mean?

Recent Comments

No comments to show.
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology

No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology