Long-time readers know of my annual tradition of reviewing the improvements (or really, the lack of improvements) in the IT security world over the past year. This year had its share of good stats tempered by a hefty dose of stark reality. Let's start with the good news: Most computing devices and software became more secure in 2009. Increasingly, more vendors are starting to take computer security and patching seriously. Companies are making critical security patches available faster than in past years (across all platforms). More end-users are using auto-updating mechanisms to patch their OS and applications. The number of computers being applied with critical security patches is up. Responsible disclosure is up. Irresponsible, full disclosure is down. (See Figure 27 in the Microsoft Security Intelligence Report for the company's stats).

Original Article