Only 31% of critical infrastructure firms patch critical flaws within 3 days
A new Onyxia Cyber survey of 300 CISOs finds major differences in cyber resilience standards across critical infrastructure, healthcare, financial services, retail and technology. The report says patching, MFA coverage, phishing readiness and other basics vary sharply by sector, creating uneven risk across essential industries.
Why it matters: - The survey shows there is no single baseline for cyber resilience across major industries. - That inconsistency matters because the same threat can face very different defenses depending on the sector. - Onyxia Cyber says organizations that set measurable targets and benchmark against peers are better positioned for emerging attacks.
What happened: - Onyxia Cyber released its third annual CISO research report, "Industry Divides: Uncovering the CISO's Resilience Priorities Across Sectors." - The survey covered 300 chief information security officers across financial services, healthcare, critical infrastructure, technology and retail. - Critical infrastructure organizations were the slowest on patching, with only 31.3% targeting critical vulnerability remediation within three days. - IT & Technology led that measure at 69.0%, while Financial Services came in at 61.4%.
The details: - Healthcare reported the highest phishing click-through rate at 5.53%, nearly double Financial Services at 3.13%. - Healthcare also had the highest share of inactive privileged accounts at 3.42%. - Financial Services posted the lowest unmanaged device rate at 1.76% and the lowest inactive privileged account rate at 1.05%. - Financial Services also had the highest acceptable SOC false-positive rate at 13.23%, compared with 7.23% in Healthcare. - IT & Technology expected employees to report 86.71% of phishing emails, versus 76.02% in Critical Infrastructure. - Critical Infrastructure was the only sector where zero CISOs said their organizations require 100% MFA coverage for user accounts. - By contrast, 35% of Financial Services CISOs said their organizations require complete MFA coverage. - Retail & eCommerce organizations patched 62% of critical vulnerabilities within three days. - Retail's MFA coverage gap was 3.72%, more than double the Financial Services benchmark. - Retail's average phishing simulation reporting rate was 78.9%, the second lowest in the survey. - Onyxia said the retail patching pattern reflects years of PCI-DSS pressure. - Onyxia made the report available for download at the full report.
Between the lines: - The report suggests some sectors have normalized weaker controls even when those gaps create obvious operational risk. - The sharpest divides are not just in technical hygiene, but in identity security and workforce behavior. - Critical infrastructure's lack of a universal MFA expectation stands out because the sector underpins power, water and transportation systems. - Even stronger-performing sectors still tolerate blind spots, which shows maturity in one control area does not guarantee resilience overall.
What's next: - Onyxia Cyber says security teams should benchmark continuously against the broader market, not just peers in their own sector. - The company argues that organizations need context-aware data to decide what acceptable risk should look like. - As compliance deadlines and threat pressure increase, sectors with weaker identity and patching standards may face more scrutiny.
The bottom line: - The report's core message is simple: cyber resilience is uneven, and the weakest industry norms may be setting the real floor for risk.
Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.
Sign up for:
Finance Times Gazette
The daily local news briefing you can trust. Every day. Subscribe now.
Check Your Email!
We sent a one-time activation link to: .
Confirm it's you by clicking the email link.
If the email is not in your inbox, check spam or try again.
Welcome back!
is already signed up. Check your inbox for updates.