The Problem with CVSS Scores and What It Means for Vulnerability Management Programs

Posted by Tal Morgenstern on May 2, 2019 8:38:33 AM

The number of vulnerabilities uncovered daily has long exceeded what security teams can possibly address. The key to success in vulnerability management no longer lies in patching everything, but rather in making judgment calls and deciding which vulnerabilities to address and which to ignore.

Read More

Topics: vulnerability remediation, vulnerabilities

Vulnerability Remediation in the CI/CD Pipeline - Not Just a Coding Issue

Posted by Roy Horev on Apr 4, 2019 7:27:24 AM

Vulnerability remediation was once considered a straightforward process. Scanning software identified potential vulnerabilities and notified the system administrator, who took over from there. “Vulnerability” was seen as a coding issue, so manually checking and patching code became the standard method of remediation despite being slow and not always effective.

Read More

Topics: vulnerability remediation

3 Ways Vulnerability Remediation Intelligence Increases Security and Efficiency

Posted by Tal Morgenstern on Mar 28, 2019 10:14:09 AM

Enterprises face new security threats daily. In 2017-18 alone, over 30,000 new vulnerabilities were reported. Trying to adapt to this new reality has become a tremendous challenge for security teams everywhere. Handling the influx of these new security threats has become an endless task, requiring manual, time-consuming work.

Read More

Topics: vulnerability remediation, vulnerabilities

Why Your Vulnerability Management Processes Isn't Working

Posted by Tal Morgenstern on Mar 21, 2019 7:49:31 AM

It’s the question that plagues every CISO: “Have I done enough?”

First, you’ve convinced your partners in the boardroom that vulnerabilities are a serious matter and increased your security budget. Then, you've managed to create a collaborative relationship between IT and security teams, coordinating code scans and implementing patches. But every now and then it’s important to zoom out at make sure you’re not missing the security forest for the vulnerability trees.

Read More

Topics: vulnerability remediation, vulnerabilities

How can Enterprises Stop Failing their Vulnerability Management Teams?

Posted by Roy Horev on Mar 7, 2019 8:33:55 AM

Everyone knows that CISOs are losing sleep over the dangers that vulnerabilities could potentially cause their businesses, and with good reason. But the problem goes beyond the continuous growth in vulnerabilities.

Read More

Topics: vulnerability remediation, vulnerabilities, DevSecOps

Why Response is the Most Difficult Part of Vulnerability Management

Posted by Roy Horev on Feb 21, 2019 10:15:00 AM

“If it were easy, everyone would do it.”

With the never-ending headlines of major breaches caused by vulnerabilities, it’s clear that vulnerability management isn’t easy. According to the Ponemon Institute, the average total cost of a breach in 2018 ranged from between  2-7 million dollars, depending on the number of compromised records.

Read More

Topics: vulnerability remediation, vulnerabilities

Saving Time and Money with Vulnerability Remediation at Scale

Posted by Roy Horev on Feb 7, 2019 7:21:06 AM

Security and IT teams are currently fighting a flood of software vulnerabilities. In 2018 alone, a record 16,555 were reported. Of these, thousands affected every cloud-native SaaS or enterprise company. Some of these vulnerabilities were only potentially dangerous, but others affected tens of thousands of customers.

Read More

Topics: vulnerability remediation, vulnerabilities

Vulnerability Management Worst Practices

Posted by Tal Morgenstern on Jan 3, 2019 7:09:18 AM

Knowing what NOT to do can sometimes be just as helpful as knowing the right thing to do. Oftentimes, CISOs and Vulnerability Managers have plans and practices in place that can actually be making matters worse by focusing on the wrong things. Let’s review some of these mistakes so you can avoid them in your own organization.

Read More

Topics: vulnerability remediation, vulnerabilities

Vulnerability Remediation: Don't Let the Cure be Worse than the Disease

Posted by Tal Morgenstern on Dec 13, 2018 9:45:06 AM

By now, everybody knows that vulnerabilities that aren't remediated properly could pose a serious threat to the enterprises environment.The data breach experienced by Equifax last year exemplifies the impacts that can occur to a business that fails to remediate. However, we cannot ignore the other side of the coin – when remediation steps ARE applied they can cause significant damage and downtime in their own right.

Read More

Topics: vulnerability remediation

The Staggering Growth in Vulnerability Disclosures, 2010 - 2018

Posted by Tal Morgenstern on Dec 5, 2018 10:11:58 AM

With the end of the year, it’s prime time to reflect on vulnerability trends since the start of the decade.

Read More

Topics: vulnerability remediation, vulnerabilities