Closing the Loop: Detecting Vulnerabilities is Great, but Risk Only Decreases After Remediation

Share and earn Cybytes
Facebook Twitter LinkedIn Email

Patching is only effective if it is timely and thorough. But, timely and thorough patch management remains an elusive goal.

We know about vulnerabilities and patches in general directly from vendor bulletins and from organizations like CERT and DHS. And our vulnerability scanners stridently report the specific systems missing these patches. Yet months go by and systems are still unpatched. Why is this?

In this on-demand webinar, we will explore the answers to this question and the solutions. Here’s a few of the points we’ll delve into:

Organizationally there’s often a lack of clear lines of authority and accountability. The infosec team says “you need to install all these patches”. The server admins say “it’s on our list” or “it’s stuck with the change control board”. And there’s no arbiter.Lack of automationLack of integration between vulnerability management, patch management, change control and ticketing systemsInability to identify all of the different systems that are in the environmentIneffective prioritization, resulting in the wrong things being worked on.

Then we’ll share insights from organizations that have overcome these problems. We will look at how they are structured. Who is accountable. How authority and responsibility flows. How stability and security priorities are balanced.

Finally, Justin Buchanan will show how the technology side can be addressed through automation and integration with InsightVM.

Register for our on-demand webinar!

Share this post and earn Cybytes
Facebook Twitter LinkedIn Email
About Rapid7
Rapid7 (NASDAQ:RPD) powers the practice of SecOps by delivering shared visibility, analytics, and automation that unites security, IT, and DevOps teams. The Rapid7 Insight platform empowers these teams to jointly manage and reduce risk, detect and contain attackers, and analyze and optimize operations. Rapid7 technology, services, and research drive vulnerability management, application security, incident detection and response, and log management for more than 7,000 organizations across more than 120 countries, including 52% of the Fortune 100.
Promoted Content
30-Day Trial: UBA-Powered SIEM with Rapid7's InsightIDR
Rapid7 InsightIDR delivers trust and confidence: you can trust that any suspicious behavior is being detected, and have confidence that with the full context, you can quickly remediate. From working hand-in-hand with security teams, we understand how painful it is to triage, false-positive, vague alerts and jump between siloed tools, each monitoring a bit of the network. InsightIDR combines SIEM, UBA, and EDR capabilities to unify your existing network & security stack. By correlating the millions of events your organization generates daily to the exact users and assets behind them, you can reliably detect attacks and expose risky behavior - all in real-time.

Our Revolution

We believe Cyber Security training should be free, for everyone, FOREVER. Everyone, everywhere, deserves the OPPORTUNITY to learn, begin and grow a career in this fascinating field. Therefore, Cybrary is a free community where people, companies and training come together to give everyone the ability to collaborate in an open source way that is revolutionizing the cyber security educational experience.

Cybrary On The Go

Get the Cybrary app for Android for online and offline viewing of our lessons.

Get it on Google Play

Support Cybrary

Donate Here to Get This Month's Donor Badge

Skip to toolbar

We recommend always using caution when following any link

Are you sure you want to continue?