All articles

Our view of vulnerability management

To defend your network effectively against threats, risks must be systematically identified and mitigated or eliminated. We call this vulnerability management. When this process is properly established, the organisation stays on top of detecting vulnerabilities in the network. Vulnerabilities can then be resolved more frequently and effectively. Those posing the most immediate risk to the network or organisation must take priority. Vulnerability management must also be applied to websites, online shops and web portals.

Vulnerability management does face several challenges, such as:

  • A large attack surface covering physical and virtual environments in data centres and on cloud platforms.
  • Employees who regularly fall victim to phishing and other social engineering attacks.
  • A tsunami of alerts and vulnerabilities threatening to overwhelm the teams responsible for patching and restoring systems.

More important than solutions to these and other challenges are threat intelligence, mapping and interpreting real cyber threats to the organisation, and establishing the current and desired maturity level. We therefore first determine what is relevant and necessary, then address the associated challenges of vulnerability management.

Threat intelligence: which threats must we protect against?

As threats and attacks become more complex, conventional security measures are increasingly insufficient. To address advanced threats from inside and outside the organisation, it is essential to have the right tools so threats can be identified as early as possible.

Threat Intelligence (TI) helps organisations address these threats. It gives organisations timely visibility of what is happening on the company network and which threats are lurking. This insight is indispensable for setting the right priorities and taking measures. Our Cyber Threat Hunting service was developed specifically for this.

Vulnerability management maturity level

There are five, or actually six, maturity levels in vulnerability management.

Level 0 is exactly what the name suggests: no programme, minimal controls and no mitigation strategy. At level 1, scanning begins for the first time and some mitigation follows the scans. But there is no considered plan for either scanning or mitigation. At level 2, the programme becomes coherent for the first time, with scheduled scans driven by some form of compliance framework and a mitigation plan. At level 3, risk management really begins. We also start prioritising and identifying trends. At level 4, the focus changes. Scanning and patching processes are sufficiently mature, and we now look for actual threats and attackers. In the final phase, level 5, integration with business processes takes place. This is the continuous monitoring cycle so often discussed.

At the first two levels, you are still in the pleasant phase of “blissful ignorance”. Threats do not exist and you have yet to start scanning. Only when the scan results arrive do you first confront the scale of the problem. That scan is our starting point. Below, we explain the maturity levels further, from scanning alone to a complete vulnerability management model that thinks like an attacker.

  1. Scanning: get the basics right

The first step towards a good solution is integrating your business objectives into your vulnerability management programme. Once your business and IT security objectives align, you can establish a joint team. You must ensure you have the people and/or resources to scan for vulnerabilities regularly.

  1. Assessment and compliance: start actively managing vulnerabilities

As with any other business system, you need a repeatable process to produce measurable statistics. Establishing a compliance framework, such as PCI, FISMA or HIPAA, provides the basis for vulnerability scanning and patching. This helps you implement a basic prioritisation framework to process an abundance of data.

  1. Analysis and prioritisation: formalise the process

A vulnerability management programme covering vulnerabilities, prioritisation and patching forms part of a complete ecosystem. These tools allow security or IT departments to enrich data, set priorities and handle an abundance of information. At this stage, vulnerabilities are prioritised to avoid overburdening limited resources and capacity. The statistics focus on improving security rather than merely keeping busy.

  1. Attack management: bring the attacker into view

At this stage, processes and statistics are combined to identify trends in the security situation and improve the process and its execution. Security and IT departments continuously establish processes to manage the vulnerability lifecycle, using risk management processes and tools to measure risks to essential assets. The vulnerability management programme's focus has shifted from patching and matching to taking the attacker's position and targeting threats. Internal or external red teams carry out penetration tests.

  1. Business risk management: focus on business risk and vulnerability

A vulnerability management programme integrates business objectives and essential assets once risks are seen as affecting the entire business. Business owners take responsibility at programme level and routinely decide where security resources should be deployed. All potential threat vectors, mobile, web, network, social, identity and wireless, are integrated into the programme. Tools and processes that measure and prioritise risks are fully integrated with security, IT, operational and business risk management functions.

vulnerability management maturity model

With specialist security tools and additional manual checks by our experts, SECWATCH offers an appropriate vulnerability management process for every organisation.

SECWATCH Security Operations

SECWATCH enables Security Operations to work optimally. We install the right software for your question, tailor the setup to your requirements and align the configuration fully with your working environment. Alongside full ownership of the solution, we offer a choice of flexible service contracts, such as monitoring and escalation or fully managed security services. This allows you to make the most of the tools and our expertise.

Our experts explain the operational and technical aspects of vulnerability management in an accessible way. Contact us for an initial, no-obligation intake to see how our services and solutions could fit your organisation.

 


Back to all articles