Story image

Too many 'critical' vulnerabilities to patch? Tenable opts for a different approach

18 Apr 2019

Tenable is hedging all of its security bets on the power of predictive, as the company announced general available of its Predictive Prioritisation solution within Tenable.io.

The solution claims that helps organisations reduce their business risk by focusing on the top 3% of security vulnerabilities that are most likely to be exploited.

The entire process of prioritising vulnerabilities with the Common Vulnerability Scoring System, otherwise known as CVSS, is often limited. The majority of vulnerabilities rated by the system are ‘high’ or ‘critical’, which can lead to an overload of high-priority vulnerabilities – a challenge for security teams.

Additionally, according to the National Vulnerability Database there were 16,500 new vulnerabilities disclosed in 2018 alone. Only a small subset had a public exploit available and even fewer were actually leveraged by attackers.

Tenable decided to take a different approach to vulnerability prioritisation. Predictive Prioritisation addresses this industry-wide problem by re-prioritising vulnerabilities based on the probability they will be leveraged in an attack. 

''The release of Predictive Prioritisation across Tenable's Cyber Exposure platform is the latest phase of our mission to redefine vulnerability management for the digital era. We're helping customers solve one of the most difficult challenges in the industry today,'' says Tenable’s cofounder and chief technology officer, Renaud Deraison.

“Predictive prioritisation flips the advantage back to cyber defenders by telling them where they're exposed, to what extent and which vulnerabilities to focus on first. These are all critical components of an effective Cyber Exposure strategy.''

Tenable.io now automatically displays a Vulnerability Priority Rating (VPR) that indicates the remediation priority of each flaw, along with VPR Key Drivers, which provide enhanced context into how scores are calculated. Both features are dynamic and change with the threat landscape, arming security teams with actionable insight into their true level of business risk.

This latest release follows the general availability of Predictive Prioritisation in Tenable.sc (formerly SecurityCenter), making Tenable's Cyber Exposure platform the only one to provide predictive capabilities for on-premises and cloud deployments.

Tenable was recently named a March 2019 Gartner Peer Insights Customers’ Choice for Vulnerability Assessment (VA). 

“Thank you to all the customers who took the time to share their experiences working with Tenable, and for trusting us to help them accelerate their Cyber Exposure journeys to reduce their cybersecurity risk,” says Tenable cofounder Jack Huffard.

“At Tenable, our customers are at the heart of what we do, so we’re delighted to be recognised as a Customers’ Choice.”

What the future of fibre looks like in NZ
The Commerce Commission has released its emerging views paper on the rules, requirements and processes which will underpin the new regulatory regime for New Zealand’s fibre networks.
Gen Z confidence in the economy is on the decline
Businesses need to work hard to improve their reputations.
Why NZ businesses have less than two years to adopt digital before disruption hits
Research found that digital disruption is already impacting two-thirds of New Zealand organisations.
Dell EMC launches interactive AI Experience Zones
The AI Experience Zones are designed to educate visitors about how to start, identify, and implement an AI project.
What NZ can learn from the Baltimore cyberattack
“Businesses must control physical access to their computers and secure their networks."
Infratil seeks clearance to acquire up to 50% stake in Vodafone NZ
The commission will give clearance to a proposed merger if they are satisfied that the merger is unlikely to have the effect of substantially lessening competition in a market.
Hands-on review: MiniTool Power Data Recovery Software
I came across a wee gem of advice when researching the world of data recovery. As soon as you get that sinking feeling and realise you’ve lost a file, stop using your computer.
Deepfakes the 'next wave of concern' - but can law really stomp it out?
Enforcing the existing law will be difficult enough, and it is not clear that any new law would be able to do better. Overseas attempts to draft law for deepfakes have been seriously criticised.