 {"id":14051,"date":"2019-12-09T03:52:00","date_gmt":"2019-12-09T10:52:00","guid":{"rendered":"https:\/\/moderneuc.com\/?p=14051"},"modified":"2026-02-18T13:02:24","modified_gmt":"2026-02-18T20:02:24","slug":"security-compliance-risks","status":"publish","type":"post","link":"https:\/\/jorgep.com\/blog\/security-compliance-risks\/","title":{"rendered":"WaaS Security \/ Compliance Risks"},"content":{"rendered":"\n<p><\/p>\n\n\n\n<p>A key question you should be asking your team is <\/p>\n\n\n\n<h4 class=\"wp-block-heading\">A<strong>re  we keeping up with Windows 10 keeping up with updates?<\/strong><\/h4>\n\n\n\n<p>As of today, devices with the following versions of Windows 10 <em> <\/em><strong><em>ARE NOT receiving security\u00a0 updates<\/em><\/strong>:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li> Windows 10 Pro (OEM)&nbsp;&nbsp; version 1803 or earlier<\/li><li> Windows 10 Enterprise version 1709 or earlier <\/li><\/ul>\n\n\n\n<p><strong>Do they realize the risk and exposure they are taking?<\/strong><\/p>\n\n\n\n<p>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Read blog:\u00a0 <a href=\"https:\/\/jorgep.com\/blog\/keeping-up-with-windows-10\/\" class=\"rank-math-link\">Keeping up with Windows 10<\/a> <\/p>\n\n\n\n<p>In the past few weeks, I have encountered several customers that did not realize they were not getting quality updates on end-of-life versions and needed help understanding\u2026&nbsp;&nbsp;&nbsp;&nbsp;    One customer had over 1,200 devices on Windows 10 Pro v1607 still.<\/p>\n\n\n\n<p>If you are not familiar with the new Windows Servicing cadence were you need to stay  current and up-to-date, then you are introducing a lot of security risk and likely compliance governance issues.     <\/p>\n\n\n\n<p>Security risks alone are very high for unpatched software and devices.   A few examples:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/fortune.com\/2018\/05\/07\/security-equifax-vulnerability-download\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Equifax breach<\/a> was traced to an unpatched Java Virtual machine allowing  hackers to steal millions of data records.<\/li><li><a href=\"https:\/\/www.zdnet.com\/article\/singhealth-data-breach-reveals-several-inadequate-security-measures\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">SingHealth  breach <\/a> traced to  a workstation running a version of Microsoft Outlook that was not updated with a patch to address the use of the hacking tool. <\/li><li> A Fortune 500 corporation hadn\u2019t patched Windows to protect against the \u201cEternal Blue\u201d zero-day&nbsp;  opening the door to a September 2018 attack that spread the crypto-mining \u201cWannaMine\u201d malware onto over 1,000 machines throughout the company <\/li><\/ul>\n\n\n\n<p>Although all of the above examples are related to large organizations,  the Verizon Data Breach Report shows that&nbsp;<a aria-label=\" (opens in a new tab)\" href=\"https:\/\/enterprise.verizon.com\/resources\/reports\/dbir\/\" target=\"_blank\" rel=\"noreferrer noopener\">43% of cyber attacks target small businesses<\/a> where  61% of small business owners handle IT themselves, and 84% don\u2019t think they are at a risk of an attack.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Bottom line:   Stay Current!<\/h3>\n\n\n\n<p>Some usefull  resource<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li> <a aria-label=\"17 Types of Cyber Attacks To Secure Your Company From in 2019 (opens in a new tab)\" rel=\"noreferrer noopener\" href=\"https:\/\/phoenixnap.com\/blog\/cyber-security-attack-types\" target=\"_blank\">17 Types of Cyber Attacks To Secure Your Company From<\/a><\/li><li><a href=\"https:\/\/www.hackmageddon.com\/2019\/10\/28\/16-30-september-2019-cyber-attacks-timeline\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\"> 2019 list of known hacks<\/a>  <\/li><li><a href=\"https:\/\/www.hackmageddon.com\/2018-master-table\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">2018 list of known hacks <\/a><\/li><li><a href=\"https:\/\/jorgep.com\/blog\/windows-7-beyond-the-deadline\/\">Windows 7 Beyond The Deadline<\/a> <\/li><\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Organizations need to stay  up-to-date in their Windows 10 OS patching otherwise  they introduce a lot of security risk and likely compliance governance issues.     <\/p>\n","protected":false},"author":2,"featured_media":368825,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_kad_blocks_custom_css":"","_kad_blocks_head_custom_js":"","_kad_blocks_body_custom_js":"","_kad_blocks_footer_custom_js":"","ngg_post_thumbnail":0,"_kad_post_transparent":"","_kad_post_title":"","_kad_post_layout":"","_kad_post_sidebar_id":"","_kad_post_content_style":"","_kad_post_vertical_padding":"","_kad_post_feature":"","_kad_post_feature_position":"","_kad_post_header":false,"_kad_post_footer":false,"_kad_post_classname":"","footnotes":""},"categories":[681,441],"tags":[700,742,762,472,326,430,784],"class_list":["post-14051","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-moderneuc2","category-tech-talk","tag-cybersecurity","tag-moderneuc1","tag-security","tag-waas","tag-windows","tag-windows-10","tag-windows-servicing"],"taxonomy_info":{"category":[{"value":681,"label":"ModernEUC"},{"value":441,"label":"Tech Talk"}],"post_tag":[{"value":700,"label":"Cybersecurity"},{"value":742,"label":"ModernEUC"},{"value":762,"label":"Security"},{"value":472,"label":"Waas"},{"value":326,"label":"Windows"},{"value":430,"label":"Windows 10"},{"value":784,"label":"Windows Servicing"}]},"featured_image_src_large":["https:\/\/jorgep.com\/blog\/wp-content\/uploads\/WaaS-RiskCompliance-Featured.jpg",730,430,false],"author_info":{"display_name":"Jorge Pereira","author_link":"https:\/\/jorgep.com\/blog\/author\/jorge\/"},"comment_info":0,"category_info":[{"term_id":681,"name":"ModernEUC","slug":"moderneuc2","term_group":0,"term_taxonomy_id":691,"taxonomy":"category","description":"","parent":0,"count":266,"filter":"raw","cat_ID":681,"category_count":266,"category_description":"","cat_name":"ModernEUC","category_nicename":"moderneuc2","category_parent":0},{"term_id":441,"name":"Tech Talk","slug":"tech-talk","term_group":0,"term_taxonomy_id":451,"taxonomy":"category","description":"","parent":0,"count":690,"filter":"raw","cat_ID":441,"category_count":690,"category_description":"","cat_name":"Tech Talk","category_nicename":"tech-talk","category_parent":0}],"tag_info":[{"term_id":700,"name":"Cybersecurity","slug":"cybersecurity","term_group":0,"term_taxonomy_id":710,"taxonomy":"post_tag","description":"","parent":0,"count":29,"filter":"raw"},{"term_id":742,"name":"ModernEUC","slug":"moderneuc1","term_group":0,"term_taxonomy_id":752,"taxonomy":"post_tag","description":"","parent":0,"count":290,"filter":"raw"},{"term_id":762,"name":"Security","slug":"security","term_group":0,"term_taxonomy_id":772,"taxonomy":"post_tag","description":"","parent":0,"count":11,"filter":"raw"},{"term_id":472,"name":"Waas","slug":"waas","term_group":0,"term_taxonomy_id":482,"taxonomy":"post_tag","description":"","parent":0,"count":18,"filter":"raw"},{"term_id":326,"name":"Windows","slug":"windows","term_group":0,"term_taxonomy_id":336,"taxonomy":"post_tag","description":"","parent":0,"count":94,"filter":"raw"},{"term_id":430,"name":"Windows 10","slug":"windows-10","term_group":0,"term_taxonomy_id":440,"taxonomy":"post_tag","description":"","parent":0,"count":78,"filter":"raw"},{"term_id":784,"name":"Windows Servicing","slug":"windows-servicing","term_group":0,"term_taxonomy_id":794,"taxonomy":"post_tag","description":"","parent":0,"count":3,"filter":"raw"}],"_links":{"self":[{"href":"https:\/\/jorgep.com\/blog\/wp-json\/wp\/v2\/posts\/14051","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jorgep.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jorgep.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jorgep.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/jorgep.com\/blog\/wp-json\/wp\/v2\/comments?post=14051"}],"version-history":[{"count":1,"href":"https:\/\/jorgep.com\/blog\/wp-json\/wp\/v2\/posts\/14051\/revisions"}],"predecessor-version":[{"id":518862,"href":"https:\/\/jorgep.com\/blog\/wp-json\/wp\/v2\/posts\/14051\/revisions\/518862"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/jorgep.com\/blog\/wp-json\/wp\/v2\/media\/368825"}],"wp:attachment":[{"href":"https:\/\/jorgep.com\/blog\/wp-json\/wp\/v2\/media?parent=14051"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jorgep.com\/blog\/wp-json\/wp\/v2\/categories?post=14051"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jorgep.com\/blog\/wp-json\/wp\/v2\/tags?post=14051"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}