March 8, 2021

Is it time for evolution of Vulnerability Management?

Is it time for evolution of Vulnerability Management?

We all know that vulnerability is a weakness in any type of system which can be exploited by hackers to achieve their objectives.

If we investigate any organization, each vulnerability could be affecting multiple devices which could be in tens, or hundreds or more. On top of that we must look for newly disclosed vulnerabilities as well. Since 2017, 300+ vulnerabilities are being disclosed every week. This makes, the remediation task a top priority, as longer it takes to fix a vulnerability the stronger are the chances of getting breached if the hackers start to exploit those.

As per a research, 39% of breach victims knew that they were vulnerable to hackers before they were breached and 60% of organizations were breached for a vulnerability which had a patch available.

The challenge faced by most of the organizations is not about HOW to patch the systems, but rather WHAT to patch first. If we look into the risk scoring system used by most of the Vulnerability Assessment and Management solutions, it is the traditional Common Vulnerability Scoring System (CVSS).

When it comes to remediation, most of the organizations focus on Critical and High severity first and then focus on others. However, what is the context of these vulnerabilities for any organization? CVSS is a global risk score for any organization around the world, which is independent of the industry sector and the location of the industry. And might not be the answer for it.

According to a study, out of the total open-source vulnerabilities published in 2019, 15% were scored Critical and 41% were scored High by CVSS V3.x scoring system. If over half of the vulnerabilities are scored as Critical or High severity, then prioritizing them for remediation becomes an inefficient process as it lacks a business context and leads to longer patch cycles. Not all vulnerabilities have an exploit available and not all are attractive to hackers.

If there are 10,000 vulnerabilities in an organization and out of those 3,000 are of Critical or High Severity, then we need to contextualize the risk score for them to prioritize which vulnerability needs to be patched first based on the context specific to the organization.

Now the question is, how it can be done? The answer is Vulnerability Intelligence! Threat Intelligence consumption from vulnerability perspective. Context around vulnerabilities should be gathered using Threat Intelligence to prioritize the vulnerabilities on an organization level. This will help in identifying the true risk score a vulnerability possess in an organization.

As per Gartner’s report on Top 10 Security Projects for 2020-2021: Risk based vulnerability Management is ranked number 2, it says: “Don’t try to patch everything; focus on vulnerabilities that are actually exploitable. Go beyond a bulk assessment of threats and use threat intelligence, attacker activity and internal asset criticality to provide a better view of real organizational risk.”

By using the power of Machine Learning and Vulnerability Intelligence HivePro Uni5 can do Risk Based Prioritization, Patch Prioritization, Threat and Attacks Prediction and more.

For more information on HivePro Uni5, click here.

“Don’t try to patch everything; focus on vulnerabilities that are actually exploitable. Go beyond a bulk assessment of threats and use threat intelligence, attacker activity and internal asset criticality to provide a better view of real organizational risk.”

Gartner Report on Top 10 Security Projects for 2020-2021

References:

https://www.servicenow.com/content/dam/servicenow-assets/public/en-us/doc-type/resource-center/infographic/gaps-in-vulnerability-response-infographic.pdf

https://www.whitesourcesoftware.com/open-source-vulnerability-management-report

https://www.gartner.com/smarterwithgartner/gartner-top-security-projects-for-2020-2021

https://info.cyr3con.ai/hubfs/AF-CYR3CON-DOC1-How%20Your%20Vulnerability%20Management%20Teams%20Can%20Do%20More%20With%20Less.pdf

https://www.blueliv.com/cyber-security-and-cyber-threat-intelligence-blog-blueliv/why-threat-intelligence-is-central-to-effective-vulnerability-prioritization

Author: Pulkit Saxena

Recent Resources

Dive into our library of resources for expert insights, guides, and in-depth analysis on maximizing Uni5 Xposure’s capabilities
Enterprise security team mapping identity attack surface exposure

Identity Attack Surface Management: Enterprise Guide

Learn what identity attack surface management covers, where access risk hides, and how teams can evaluate discovery, prioritization, and remediation.
Read More
Enterprise security team evaluating vulnerability assessment coverage and remediation workflows

Vulnerability Assessment Platform: Enterprise Guide

Learn how to evaluate a vulnerability assessment platform for enterprise coverage, threat context, validation, reporting, and remediation workflows.
Read More
Azure security posture management and CTEM dashboard

Azure Security Posture Management: Complete CTEM Guide

Request a Hive Pro demo to strengthen Azure security posture management with CTEM, threat intelligence, validation, and unified cloud exposure insights.
Read More
Security team analyzing dark web threat intelligence

Dark Web Threat Intelligence for Exposure Management

Request a demo to see how dark web threat intelligence helps prioritize urgent exposures, track active exploits, and guide faster remediation.
Read More
Security team reviewing connected attack paths across multiple cloud environments

Multi-Cloud Exposure Management: Practical Guide

Schedule a Hive Pro demo. See how multi-cloud exposure management helps prioritize active threats and validate the attack paths that matter most.
Read More
Continuous AWS security vulnerability management network visualization

AWS Security Vulnerability Management: Best Practices Guide

Schedule a free consultation. Master AWS security vulnerability management. Use our comprehensive guide to native scanning, CTEM, and exposure reduction.
Read More

What’s new on Hive Pro?

Get through updates and upcoming events, and more directly in your inbox

Reduce real exposure. Not just vulnerability volume.