Certificate failures can cost firms over $250,000
Overview
A recent report from DigiCert warns that the shift to 47-day public TLS certificates by 2029 will significantly increase the burden of certificate management for businesses. Organizations will face the need to renew certificates over eight times more frequently than before and will have to perform domain validations 40 times more often. This change could lead to costly outages, with failures potentially costing companies upwards of $250,000. The report emphasizes that companies should prepare for these challenges to avoid disruptions that can impact business operations. Proper certificate management is essential to prevent unexpected downtime and financial losses.
Key Takeaways
- Affected Systems: TLS certificates, DigiCert services
- Action Required: Organizations should enhance their certificate management practices and prepare for more frequent renewals and validations.
- Timeline: Disclosed on October 2023
Original Article Summary
The move toward 47-day public TLS certificates by 2029 will increase the certificate management workload for enterprises, according to DigiCert’s Certificate Management Outlook. Organizations will need to renew certificates more than eight times as often as under the previous certificate lifecycle and conduct 40 times as many domain validations. What certificate management challenges were listed as a combination of very or extremely concerned? (Source: DigiCert) Certificate failures cause costly outages Certificate failures can disrupt business … More → The post Certificate failures can cost firms over $250,000 appeared first on Help Net Security.
Impact
TLS certificates, DigiCert services
Exploitation Status
No active exploitation has been reported at this time. However, organizations should still apply patches promptly as proof-of-concept code may exist.
Timeline
Disclosed on October 2023
Remediation
Organizations should enhance their certificate management practices and prepare for more frequent renewals and validations.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.