home.social

#exposuremanagement — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #exposuremanagement, aggregated by home.social.

  1. Exposure Management Shields Against Lurking Vulnerabilities

    Don't let a single vulnerability be the Death Star of your defense - even the strongest systems can be undermined by a shared insider weakness. Start with asset discovery to proactively manage exposure and shield against lurking threats.

    osintsights.com/exposure-manag

    #ExposureManagement #VulnerabilityManagement #PatchManagement #ThreatLandscape #AssetDiscovery

  2. Cyber insurers are shifting from yearly audits to continuous validation.
    Kimberly Manibusan from Qualys explains why insurers now want measurable proof of:
    🔴 Faster remediation
    🔴 Patch management effectiveness
    🔴 Continuous security visibility

    📖 Read:
    technadu.com/cyber-insurers-no

    #CyberInsurance #CyberSecurity #CyberRisk #ExposureManagement

  3. 📢 Don't miss runZero's Rob King on the latest episode of the Nexus podcast.

    Rob and host Michael Mimoso discuss the challenges of protecting #OT environments and why traditional mitigations and tools often fall short in converged networks.

    🎧 Listen today: runzero.com/resources/ot-asset

    #OTsecurity #ITOTConvergence #ExposureManagement

  4. 📢 Don't miss runZero's Rob King on the latest episode of the Nexus podcast.

    Rob and host Michael Mimoso discuss the challenges of protecting #OT environments and why traditional mitigations and tools often fall short in converged networks.

    🎧 Listen today: runzero.com/resources/ot-asset

    #OTsecurity #ITOTConvergence #ExposureManagement

  5. Exposure Management Platforms Face Validation Test

    Are you tired of filling dashboards with green and closing hundreds of tickets, only to wonder if your organization is truly safer? The harsh reality is that most exposure management platforms fall short in connecting remediation to real risk reduction.

    osintsights.com/exposure-manag

    #ExposureManagement #VulnerabilityManagement #Cves #RiskReduction #Remediation

  6. 🚰 Water and wastewater utilities depend on complex cyber-physical systems to deliver essential services, but traditional IT-centric security approaches don’t address the unique risks in these environments.

    Discover how CPS Exposure Management helps utilities gain visibility into assets, prioritize risk based on operational impact, and strengthen resilience across #water and #wastewater systems.

    📄 Read here: claroty.com/resources/white-pa

    #ExposureManagement #WaterSecurity #CriticalInfrastructure #OTSecurity #CyberPhysicalSystems

  7. 🚰 Water and wastewater utilities depend on complex cyber-physical systems to deliver essential services, but traditional IT-centric security approaches don’t address the unique risks in these environments.

    Discover how CPS Exposure Management helps utilities gain visibility into assets, prioritize risk based on operational impact, and strengthen resilience across #water and #wastewater systems.

    📄 Read here: claroty.com/resources/white-pa

    #ExposureManagement #WaterSecurity #CriticalInfrastructure #OTSecurity #CyberPhysicalSystems

  8. Liat Hayun, SVP Product Management at Tenable, on ownership and exposure:
    Remove “someone should fix this.”

    Adopt “I am the only one who will fix this.”
    “A vulnerability in a vacuum is just a line of code.”

    Security teams are drowning in signals. Context defines actionability.

    Read: technadu.com/from-national-sec

    #WomenInCyber #ExposureManagement #SecurityLeadership #LeadHerInSecurity #Tenable

  9. Tenable’s new insights show a growing AI exposure gap as organizations adopt AI faster than they can secure it. While many align with frameworks, fewer encrypt data or run AI-specific tests. With AI expanding across multi-cloud and hybrid environments, visibility and identity security matter more than ever.
    How is your team approaching AI risk?
    Follow for more updates.

    #AIsecurity #CloudSecurity #ExposureManagement #AIGovernance #CyberRisk #AIAdoption

  10. In this interaction, Ryan Knisley, Chief Product Strategist at Axonius, shares the company’s product roadmap, CISO challenges, and how field insights shape solutions.

    It’s about giving security and IT teams the one thing they need most under pressure: ground truth they can build on.

    Knisley emphasizes that the organizations that are keeping pace with evolving threats are the ones with the most accurate, complete, and current understanding of their environment.

    Knisley raised critical questions about visibility in security:

    ✖️Will this new capability improve decision-making, or just create new decisions to manage?
    ✖️You can’t prioritize risk on identities you don’t know are active.
    ✖️Real integration means the platform consolidates fragmented data.

    Knisley outlines how CISOs must translate security into a language that is understandable and demonstrates a return on investment.

    🔗 Full interview: technadu.com/wrong-data-wrong-

    #Cybersecurity #AIinSecurity #ExposureManagement #ZeroTrust #CISO #AssetIntelligence #RiskManagement #CyberResilience

  11. Alex Spivakovsky of Pentera: “Most breaches don’t hinge on zero-days; hackers rely on misconfigurations, over-permissioned identities, and process gaps.”

    Read how exposure management and continuous validation redefine cyber resilience 👇
    technadu.com/building-cyber-re

    #Pentera #CyberSecurity #ExposureManagement #AdversarialTesting

  12. 🧠 EDR Tools Are Not Exposure Management Solutions.

    They’re reactive, not proactive - designed to respond after compromise, not prevent it.
    EDR misses entire classes of assets like routers, IoT, and third-party systems.

    💬 What’s your approach to achieving full attack surface visibility?

    Follow @technadu for more discussions on vulnerability intelligence and exposure reduction.

    #CyberSecurity #ExposureManagement #EDR #Tenable #InfoSec #ThreatDetection #VulnerabilityIntelligence #TechNadu

  13. Today we're excited to announce new investments in the 🇺🇸 U.S. Public Sector to enhance protection of #OT, #IoT, #IoMT and Facility-related control systems/Building Management Systems...

    Introducing our enhanced #ExposureManagement and #Federal Information Security Modernization Act support with Security Technical Implementation Guide (#STIG)-hardened configuration management controls. These 🆕 capabilities within Claroty Continuous Threat Detection (CTD) will enable greater efficiency and operational improvements across U.S. Federal Departments and Agencies, State, Local and Education, and the #defense industrial base, when protecting increasingly vulnerable CPS assets.

    📰 Read more: claroty.com/press-releases/cla

    #PublicSector #PubSec #ClarotyFederal #BMS #FRCS #FISMA #SLED #DoD

  14. Today we're excited to announce new investments in the 🇺🇸 U.S. Public Sector to enhance protection of #OT, #IoT, #IoMT and Facility-related control systems/Building Management Systems...

    Introducing our enhanced #ExposureManagement and #Federal Information Security Modernization Act support with Security Technical Implementation Guide (#STIG)-hardened configuration management controls. These 🆕 capabilities within Claroty Continuous Threat Detection (CTD) will enable greater efficiency and operational improvements across U.S. Federal Departments and Agencies, State, Local and Education, and the #defense industrial base, when protecting increasingly vulnerable CPS assets.

    📰 Read more: claroty.com/press-releases/cla

    #PublicSector #PubSec #ClarotyFederal #BMS #FRCS #FISMA #SLED #DoD

  15. Tomorrow (Thurs, July 20) I'm hosting a webinar to share key findings from several years' worth of published research on vulnerability remediation. We have 8 data-packed reports to cover in ~30 minutes. To accomplish that, I've chosen two representative charts from each report - which was TOUGH!

    Register here and let me know how you think I did: us02web.zoom.us/webinar/regist

    #vulnerability #vulnerabilities #devops #devsecops #vulnerabilitymanagement #vulnerability #vulnerabilityassessment #vulnerabilityscanning #exposuremanagement #remediation #cyberriskmanagement #informationsecurity #infosec #appsec #applicationsecurity #appsecurity

  16. Tomorrow (Thurs, July 20) I'm hosting a webinar to share key findings from several years' worth of published research on vulnerability remediation. We have 8 data-packed reports to cover in ~30 minutes. To accomplish that, I've chosen two representative charts from each report - which was TOUGH!

    Register here and let me know how you think I did: us02web.zoom.us/webinar/regist

    #vulnerability #vulnerabilities #devops #devsecops #vulnerabilitymanagement #vulnerability #vulnerabilityassessment #vulnerabilityscanning #exposuremanagement #remediation #cyberriskmanagement #informationsecurity #infosec #appsec #applicationsecurity #appsecurity

  17. Excerpt from my latest Cyentia Institute blog post, “Patching, Fast and Slow”:

    There are many ways one could measure how quickly vulnerabilities are patched. Most go with a simple average, but such point statistics are a poor representation of what’s really happening with remediation timeframes. Our favored method for this is survival analysis. I won’t get into the methodology here other than to say it tracks the “death” (remediation) of vulnerabilities over time to produce a curve that looks like the ones below comparing remediation speed among sectors.

    The lesson? Get remediation strategy advice from your investment firm rather than your insurer, perhaps? We could ask a bunch of other questions about why certain organizations or industries struggle more than others to address vulnerabilities…but this isn’t that post. But I do suspect the “system” guiding the patching strategies of these organizations makes a big difference in the shape of their remediation curves.

    You may have caught the title of this post being a reference to Daniel Kahneman’s book “Thinking, Fast and Slow.” That was partly because it’s catchy and fits the topic. But I also think there’s a parallel to be drawn from one of the main points of that book. Kahneman describes two basic types of thinking that drive human decision-making:

    System 1: Fast, automatic, frequent, emotional, stereotypic, unconscious

    System 2: Slow, effortful, infrequent, logical, calculating, conscious

    Maybe you see where I’m headed here. I’m not saying we can boil all patching down to just two different approaches. But my experience and research support the notion that there are two broad systems at play. Many assets lend themselves to automated, fast deployment of patches without much additional preparation or evaluation (e.g., newer versions of Windows and OSX). Those fall under System 1 patching.

    Other assets require manual intervention, testing, risk evaluation, or additional effort to deploy. That fits the System 2 definition well. The more your organization has to engage in System 2 rather than System 1 patching, the slower and shallower those remediation timelines will appear. Like normal decisions, we can’t do everything via System 1…some assets need that extra System 2 treatment. But problems (and/or delays) arise when there’s a mismatch between the system used and the decision (remediation) scenario.

    My takeaway for vulnerability management programs? Use System 1 patching as much as possible and System 2 patching only where necessary.

    See all the analysis leading up to this conclusion in the full post: cyentia.com/patching-fast-and-

    #patchmanagement #vulnerabilitymanagement #vulnerabilityassessment #vulnerabilities #exposuremanagement #riskmanagement #cyberriskmanagement #remediation #cve #appsec #appsecurity #secops #securityoperations #cybersecurity #infosec #infosecurity

  18. Excerpt from my latest Cyentia Institute blog post, “Patching, Fast and Slow”:

    There are many ways one could measure how quickly vulnerabilities are patched. Most go with a simple average, but such point statistics are a poor representation of what’s really happening with remediation timeframes. Our favored method for this is survival analysis. I won’t get into the methodology here other than to say it tracks the “death” (remediation) of vulnerabilities over time to produce a curve that looks like the ones below comparing remediation speed among sectors.

    The lesson? Get remediation strategy advice from your investment firm rather than your insurer, perhaps? We could ask a bunch of other questions about why certain organizations or industries struggle more than others to address vulnerabilities…but this isn’t that post. But I do suspect the “system” guiding the patching strategies of these organizations makes a big difference in the shape of their remediation curves.

    You may have caught the title of this post being a reference to Daniel Kahneman’s book “Thinking, Fast and Slow.” That was partly because it’s catchy and fits the topic. But I also think there’s a parallel to be drawn from one of the main points of that book. Kahneman describes two basic types of thinking that drive human decision-making:

    System 1: Fast, automatic, frequent, emotional, stereotypic, unconscious

    System 2: Slow, effortful, infrequent, logical, calculating, conscious

    Maybe you see where I’m headed here. I’m not saying we can boil all patching down to just two different approaches. But my experience and research support the notion that there are two broad systems at play. Many assets lend themselves to automated, fast deployment of patches without much additional preparation or evaluation (e.g., newer versions of Windows and OSX). Those fall under System 1 patching.

    Other assets require manual intervention, testing, risk evaluation, or additional effort to deploy. That fits the System 2 definition well. The more your organization has to engage in System 2 rather than System 1 patching, the slower and shallower those remediation timelines will appear. Like normal decisions, we can’t do everything via System 1…some assets need that extra System 2 treatment. But problems (and/or delays) arise when there’s a mismatch between the system used and the decision (remediation) scenario.

    My takeaway for vulnerability management programs? Use System 1 patching as much as possible and System 2 patching only where necessary.

    See all the analysis leading up to this conclusion in the full post: cyentia.com/patching-fast-and-

    #patchmanagement #vulnerabilitymanagement #vulnerabilityassessment #vulnerabilities #exposuremanagement #riskmanagement #cyberriskmanagement #remediation #cve #appsec #appsecurity #secops #securityoperations #cybersecurity #infosec #infosecurity