Emerging threats

We support organisations striving to build a trustworthy, safe online environment where users can engage authentically in their communities.
Commercial organisationsWe support commercial organisations operating in a digital world, seeking to protect their reputation and prevent business disruption caused by cyber attacks and compliance breaches.
International programmes and developmentWe support international government organisations and NGOs working to provide infrastructure or improve the capabilities, security and resilience of their nation.
UK government and public sectorWe support UK government organisations responsible for safeguarding critical infrastructure, preserving public trust, and maintaining national security.



We’ve all spent a lot on cyber security tools, monitoring platforms and threat intelligence capabilities over the last decade, so why do so many enterprises continue to experience cyberattacks and breaches? And often because of well-known and entirely preventable vulnerabilities and misconfigurations.
Recent statistics show that known, preventable vulnerabilities remain one of the leading causes of security breaches. In 2025, CISA added 245 vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalogue, reinforcing that attackers continue to target a relatively small number of well-known issues that organisations fail to remediate quickly.
In the cyber security industry, we often call these ‘low-hanging fruit’ findings. They are the weaknesses that require minimal effort for attackers to identify and exploit, but are often overlooked as minor issues.
The broader problem here isn’t an absence of security technology (there’s plenty of that). It’s the lack of most fundamental protective measures that complement those technologies.
Cyber criminals often intentionally seek out these common weaknesses to gain access to business-critical systems and web applications. After all, why work harder when you can work smarter? When left exposed, these issues provide attackers with ready-made attack paths and opportunities to chain multiple weakness together into a larger and more dangerous breach. That’s why it’s so important to address simple vulnerabilities early; it reduces your exposure, and the long-term likelihood of a successful major breach.
Research has shown time and time again that the most resilient organisations have a layered approach to security, where multiple safeguards work together to reduce risk and impact of breaches. If one control fails or a vulnerability is missed, other measures can help prevent an incident from escalating into a serious security breach.
When web applications, supporting systems or cloud environments aren’t configured or maintained securely. This often looks like:
These weaknesses appear minor on their own, but if ignored, they create opportunities for attackers to gain access, steal sensitive data or disrupt critical operations.
A common example PGI encounters during security assessments involves administrative web interfaces that have been deployed with default or weak credentials, or are unnecessarily exposed to users who should not have access.
If an attacker is able to obtain credentials or exploit a misconfiguration, they may gain access to the application. This can give them access to sensitive data or areas, allow unauthorised changes, or provide a foothold for further attacks within the wider environment.
Simply changing default credentials, restricting access to administrative interfaces, and applying secure configuration standards can significantly reduce this risk.
When systems use insecure authentication methods such as weak passwords, legacy authentication protocols or a lack of multi-factor authentication. These weaknesses make it easier for attackers to gain unauthorised access using stolen or guessed credentials.
In 2018, organisations using legacy access methods at Citrix Systems were impacted by password-spraying attacks that exploited weak authentication controls. Unauthorised actors got access to shared network drives and limited internal resources, exposing business documents and sensitive information over several months (Oct 2018–Mar 2019).
Citrix performed a global password reset, strengthened authentication controls and improved logging and monitoring to detect suspicious activity.
When users, applications or service accounts have been granted more access than what is required. This expands the scope of the potential damage if credentials are compromised and allows attackers to abuse permissions to access sensitive systems and data.
PGI also identified in the security assessments of a web application where users with low-level privileges could bypass intended authorisation controls and perform actions reserved for higher-privileged roles. This created opportunities for individuals to undertake and approve work for which they were not appropriately authorised or qualified, introducing a direct safety, compliance and governance risk; a form of insider threat.
Software, frameworks or shared libraries that have not been updated to fix known security vulnerabilities. These weaknesses are frequently targeted because exploit techniques are commonly available.
During a security assessment, PGI identified a firewall web interface that was running an outdated software version affected by a publicly disclosed critical vulnerability. Although a security update had been available for some time, the vulnerability remained unpatched. If exploited, an attacker could have gained administrative control of the firewall, potentially allowing them to modify security policies, intercept network traffic or establish persistent access to the environment.
The issue was remediated by applying the latest vendor security updates and verifying the device configuration.
When confidential and sensitive data—customer records, credentials, internal documents—is unintentionally made publicly available due to misconfiguration or weak access controls.
In 2025, a misconfigured storage bucket in an Indian banking environment exposed large volumes of financial documents containing personal and account information. More than 273,000 records linked to 38 financial institutions were accessible, creating risks of fraud, identity theft and unauthorised access to sensitive customer data.
The issue was remediated by securing the cloud storage configuration and removing public access to the affected data.
When systems are deployed without removing unnecessary services, disabling insecure defaults or applying secure baseline configurations. This leaves avoidable attack paths exposed.
PGI also commonly identifies web applications where file upload functionality has not been adequately hardened. This allows for the application to be used to host malicious files. These files could then be served to users either through links or application functionality.
Organisations that consistently implement fundamental security controls are often better protected against compromise than those that focus solely on advanced security measures.
Strengthening security posture should start with reducing these common weaknesses through these fundamental practices:
Finding these issues before an attacker does
These are exactly the kinds of issues that penetration testing is designed to uncover - assessing how your systems behave under a simulated attack rather than how they are supposed to behave on paper. Automated scanning can flag some of these weaknesses, but it rarely demonstrates how several small issues could chain together into a viable path to a major breach.
PGI's penetration testing services cover web applications, infrastructure, cloud environments and internal networks, and every engagement ends with prioritised and practical remediation advice you can act on right away.
If you want to mitigate your 'low-hanging fruit' before someone else finds it, get in touch with our team.

Every organisation has that one member of staff who everyone relies on—that single point of failure (or SPOF).

The Ministry of Defence (MoD) recently requested that all industry partners must achieve at least DCC Level 0 by the end of 2026.

What happens when someone walks into your office unauthorised?Organisations in highly sensitive sectors often invest heavily in cyber defences, but physical security needs to be treated as an equally high priority.