home.social

#exposuremanagement — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #exposuremanagement, aggregated by home.social.

  1. Exposure Management Platforms Face Validation Test

    Are you tired of filling dashboards with green and closing hundreds of tickets, only to wonder if your organization is truly safer? The harsh reality is that most exposure management platforms fall short in connecting remediation to real risk reduction.

    osintsights.com/exposure-manag

    #ExposureManagement #VulnerabilityManagement #Cves #RiskReduction #Remediation

  2. 🚰 Water and wastewater utilities depend on complex cyber-physical systems to deliver essential services, but traditional IT-centric security approaches don’t address the unique risks in these environments.

    Discover how CPS Exposure Management helps utilities gain visibility into assets, prioritize risk based on operational impact, and strengthen resilience across #water and #wastewater systems.

    📄 Read here: claroty.com/resources/white-pa

    #ExposureManagement #WaterSecurity #CriticalInfrastructure #OTSecurity #CyberPhysicalSystems

  3. 🚰 Water and wastewater utilities depend on complex cyber-physical systems to deliver essential services, but traditional IT-centric security approaches don’t address the unique risks in these environments.

    Discover how CPS Exposure Management helps utilities gain visibility into assets, prioritize risk based on operational impact, and strengthen resilience across #water and #wastewater systems.

    📄 Read here: claroty.com/resources/white-pa

    #ExposureManagement #WaterSecurity #CriticalInfrastructure #OTSecurity #CyberPhysicalSystems

  4. In this interaction, Ryan Knisley, Chief Product Strategist at Axonius, shares the company’s product roadmap, CISO challenges, and how field insights shape solutions.

    It’s about giving security and IT teams the one thing they need most under pressure: ground truth they can build on.

    Knisley emphasizes that the organizations that are keeping pace with evolving threats are the ones with the most accurate, complete, and current understanding of their environment.

    Knisley raised critical questions about visibility in security:

    ✖️Will this new capability improve decision-making, or just create new decisions to manage?
    ✖️You can’t prioritize risk on identities you don’t know are active.
    ✖️Real integration means the platform consolidates fragmented data.

    Knisley outlines how CISOs must translate security into a language that is understandable and demonstrates a return on investment.

    🔗 Full interview: technadu.com/wrong-data-wrong-

    #Cybersecurity #AIinSecurity #ExposureManagement #ZeroTrust #CISO #AssetIntelligence #RiskManagement #CyberResilience

  5. Tomorrow (Thurs, July 20) I'm hosting a webinar to share key findings from several years' worth of published research on vulnerability remediation. We have 8 data-packed reports to cover in ~30 minutes. To accomplish that, I've chosen two representative charts from each report - which was TOUGH!

    Register here and let me know how you think I did: us02web.zoom.us/webinar/regist

    #vulnerability #vulnerabilities #devops #devsecops #vulnerabilitymanagement #vulnerability #vulnerabilityassessment #vulnerabilityscanning #exposuremanagement #remediation #cyberriskmanagement #informationsecurity #infosec #appsec #applicationsecurity #appsecurity

  6. Tomorrow (Thurs, July 20) I'm hosting a webinar to share key findings from several years' worth of published research on vulnerability remediation. We have 8 data-packed reports to cover in ~30 minutes. To accomplish that, I've chosen two representative charts from each report - which was TOUGH!

    Register here and let me know how you think I did: us02web.zoom.us/webinar/regist

    #vulnerability #vulnerabilities #devops #devsecops #vulnerabilitymanagement #vulnerability #vulnerabilityassessment #vulnerabilityscanning #exposuremanagement #remediation #cyberriskmanagement #informationsecurity #infosec #appsec #applicationsecurity #appsecurity

  7. Excerpt from my latest Cyentia Institute blog post, “Patching, Fast and Slow”:

    There are many ways one could measure how quickly vulnerabilities are patched. Most go with a simple average, but such point statistics are a poor representation of what’s really happening with remediation timeframes. Our favored method for this is survival analysis. I won’t get into the methodology here other than to say it tracks the “death” (remediation) of vulnerabilities over time to produce a curve that looks like the ones below comparing remediation speed among sectors.

    The lesson? Get remediation strategy advice from your investment firm rather than your insurer, perhaps? We could ask a bunch of other questions about why certain organizations or industries struggle more than others to address vulnerabilities…but this isn’t that post. But I do suspect the “system” guiding the patching strategies of these organizations makes a big difference in the shape of their remediation curves.

    You may have caught the title of this post being a reference to Daniel Kahneman’s book “Thinking, Fast and Slow.” That was partly because it’s catchy and fits the topic. But I also think there’s a parallel to be drawn from one of the main points of that book. Kahneman describes two basic types of thinking that drive human decision-making:

    System 1: Fast, automatic, frequent, emotional, stereotypic, unconscious

    System 2: Slow, effortful, infrequent, logical, calculating, conscious

    Maybe you see where I’m headed here. I’m not saying we can boil all patching down to just two different approaches. But my experience and research support the notion that there are two broad systems at play. Many assets lend themselves to automated, fast deployment of patches without much additional preparation or evaluation (e.g., newer versions of Windows and OSX). Those fall under System 1 patching.

    Other assets require manual intervention, testing, risk evaluation, or additional effort to deploy. That fits the System 2 definition well. The more your organization has to engage in System 2 rather than System 1 patching, the slower and shallower those remediation timelines will appear. Like normal decisions, we can’t do everything via System 1…some assets need that extra System 2 treatment. But problems (and/or delays) arise when there’s a mismatch between the system used and the decision (remediation) scenario.

    My takeaway for vulnerability management programs? Use System 1 patching as much as possible and System 2 patching only where necessary.

    See all the analysis leading up to this conclusion in the full post: cyentia.com/patching-fast-and-

    #patchmanagement #vulnerabilitymanagement #vulnerabilityassessment #vulnerabilities #exposuremanagement #riskmanagement #cyberriskmanagement #remediation #cve #appsec #appsecurity #secops #securityoperations #cybersecurity #infosec #infosecurity

  8. Excerpt from my latest Cyentia Institute blog post, “Patching, Fast and Slow”:

    There are many ways one could measure how quickly vulnerabilities are patched. Most go with a simple average, but such point statistics are a poor representation of what’s really happening with remediation timeframes. Our favored method for this is survival analysis. I won’t get into the methodology here other than to say it tracks the “death” (remediation) of vulnerabilities over time to produce a curve that looks like the ones below comparing remediation speed among sectors.

    The lesson? Get remediation strategy advice from your investment firm rather than your insurer, perhaps? We could ask a bunch of other questions about why certain organizations or industries struggle more than others to address vulnerabilities…but this isn’t that post. But I do suspect the “system” guiding the patching strategies of these organizations makes a big difference in the shape of their remediation curves.

    You may have caught the title of this post being a reference to Daniel Kahneman’s book “Thinking, Fast and Slow.” That was partly because it’s catchy and fits the topic. But I also think there’s a parallel to be drawn from one of the main points of that book. Kahneman describes two basic types of thinking that drive human decision-making:

    System 1: Fast, automatic, frequent, emotional, stereotypic, unconscious

    System 2: Slow, effortful, infrequent, logical, calculating, conscious

    Maybe you see where I’m headed here. I’m not saying we can boil all patching down to just two different approaches. But my experience and research support the notion that there are two broad systems at play. Many assets lend themselves to automated, fast deployment of patches without much additional preparation or evaluation (e.g., newer versions of Windows and OSX). Those fall under System 1 patching.

    Other assets require manual intervention, testing, risk evaluation, or additional effort to deploy. That fits the System 2 definition well. The more your organization has to engage in System 2 rather than System 1 patching, the slower and shallower those remediation timelines will appear. Like normal decisions, we can’t do everything via System 1…some assets need that extra System 2 treatment. But problems (and/or delays) arise when there’s a mismatch between the system used and the decision (remediation) scenario.

    My takeaway for vulnerability management programs? Use System 1 patching as much as possible and System 2 patching only where necessary.

    See all the analysis leading up to this conclusion in the full post: cyentia.com/patching-fast-and-

    #patchmanagement #vulnerabilitymanagement #vulnerabilityassessment #vulnerabilities #exposuremanagement #riskmanagement #cyberriskmanagement #remediation #cve #appsec #appsecurity #secops #securityoperations #cybersecurity #infosec #infosecurity