#exposuremanagement — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #exposuremanagement, aggregated by home.social.
-
📢 Don't miss runZero's Rob King on the latest episode of the Nexus podcast.
Rob and host Michael Mimoso discuss the challenges of protecting #OT environments and why traditional mitigations and tools often fall short in converged networks.
🎧 Listen today: https://www.runzero.com/resources/ot-asset-exposures-mitigations
-
AI is turning the digital battlefield into a high-speed chess match—attackers and defenders are now playing with algorithms. Can your data stand up to 2025’s AI-driven cyber threats?
#aiincybersecurity
#exposuremanagement
#cyberattacks2025
#cloudsecurity
#supplychainsecurity -
Why effective exposure management is key to cybersecurity [Q&A] #QandA #CyberSecurity #ExposureManagement
https://betanews.com/2025/08/11/why-effective-exposure-management-is-key-to-cybersecurity-qa/
-
Reach Security Raises $10 Million for Exposure Management Solution https://www.securityweek.com/reach-security-raises-10-million-for-exposure-management-solution/ #CybersecurityFunding #exposuremanagement #ReachSecurity #funding #drift
-
Reach Security Raises $10 Million for Exposure Management Solution https://www.securityweek.com/reach-security-raises-10-million-for-exposure-management-solution/ #CybersecurityFunding #exposuremanagement #ReachSecurity #funding #drift
-
Validation is an Increasingly Critical Element of Cloud Security – Source: securityboulevard.com https://ciso2ciso.com/validation-is-an-increasingly-critical-element-of-cloud-security-source-securityboulevard-com/ #continuousthreatexposuremanagement #SecurityBoulevard(Original) #rssfeedpostgeneratorecho #exposuremanagement #cloudenvironments #CyberSecurityNews #SecurityBoulevard #CloudValidation #CloudExposures #SocialFacebook #SocialLinkedIn #CloudSecurity #Cybersecurity #SocialX #CTEM
-
80% of All Security Exposures Come from Active Directory Accounts https://thecyberexpress.com/active-directory-exposures-on-a-high/ #ActiveDirectoryExposures #credentialharvesting #TheCyberExpressNews #ExposureManagement #CybersecurityNews #CredentialAttacks #domaincredentials #Misconfigurations #SecurityExposures #Misconfiguration #Vulnerabilities #Activedirectory #TheCyberExpress #FirewallDaily #ADExposures #dumping #relay #AD
-
Tomorrow (Thurs, July 20) I'm hosting a webinar to share key findings from several years' worth of published research on vulnerability remediation. We have 8 data-packed reports to cover in ~30 minutes. To accomplish that, I've chosen two representative charts from each report - which was TOUGH!
Register here and let me know how you think I did: https://us02web.zoom.us/webinar/register/7316732996513/WN_FHnATAyWTzG_lsjH3PkbLQ#/registration
#vulnerability #vulnerabilities #devops #devsecops #vulnerabilitymanagement #vulnerability #vulnerabilityassessment #vulnerabilityscanning #exposuremanagement #remediation #cyberriskmanagement #informationsecurity #infosec #appsec #applicationsecurity #appsecurity
-
Excerpt from my latest Cyentia Institute blog post, “Patching, Fast and Slow”:
There are many ways one could measure how quickly vulnerabilities are patched. Most go with a simple average, but such point statistics are a poor representation of what’s really happening with remediation timeframes. Our favored method for this is survival analysis. I won’t get into the methodology here other than to say it tracks the “death” (remediation) of vulnerabilities over time to produce a curve that looks like the ones below comparing remediation speed among sectors.
The lesson? Get remediation strategy advice from your investment firm rather than your insurer, perhaps? We could ask a bunch of other questions about why certain organizations or industries struggle more than others to address vulnerabilities…but this isn’t that post. But I do suspect the “system” guiding the patching strategies of these organizations makes a big difference in the shape of their remediation curves.
You may have caught the title of this post being a reference to Daniel Kahneman’s book “Thinking, Fast and Slow.” That was partly because it’s catchy and fits the topic. But I also think there’s a parallel to be drawn from one of the main points of that book. Kahneman describes two basic types of thinking that drive human decision-making:
System 1: Fast, automatic, frequent, emotional, stereotypic, unconscious
System 2: Slow, effortful, infrequent, logical, calculating, conscious
Maybe you see where I’m headed here. I’m not saying we can boil all patching down to just two different approaches. But my experience and research support the notion that there are two broad systems at play. Many assets lend themselves to automated, fast deployment of patches without much additional preparation or evaluation (e.g., newer versions of Windows and OSX). Those fall under System 1 patching.
Other assets require manual intervention, testing, risk evaluation, or additional effort to deploy. That fits the System 2 definition well. The more your organization has to engage in System 2 rather than System 1 patching, the slower and shallower those remediation timelines will appear. Like normal decisions, we can’t do everything via System 1…some assets need that extra System 2 treatment. But problems (and/or delays) arise when there’s a mismatch between the system used and the decision (remediation) scenario.
My takeaway for vulnerability management programs? Use System 1 patching as much as possible and System 2 patching only where necessary.
See all the analysis leading up to this conclusion in the full post: https://www.cyentia.com/patching-fast-and-slow/
#patchmanagement #vulnerabilitymanagement #vulnerabilityassessment #vulnerabilities #exposuremanagement #riskmanagement #cyberriskmanagement #remediation #cve #appsec #appsecurity #secops #securityoperations #cybersecurity #infosec #infosecurity