39:51Scanning Isn’t Enough: Measuring true risk with a Risk-Based Vulnerability Management program
Download resourcesAbout this session
Nathan Wenzler, chief security strategist at Tenable, argues that most organisations assess vulnerabilities rather than manage them: periodic unauthenticated scans, raw CSV or PDF reports, and a boil-the-ocean patch list ranked by CVSS. Using the Nintendo-cartridge myth and the curse of knowledge, he warns against clinging to familiar habits. His maturity model moves from legacy scanning to risk-based vulnerability management, which covers every asset type including web apps, containers and OT and prioritises by threat intelligence and asset criticality, and finally to cyber exposure management, where technical risk is joined to business context such as SLAs, cyber insurance and asset value. He cites McKinsey's finding that prioritisation alone cut risk by 7.5 times at no added cost and Gartner's link between risk-based approaches and fewer breaches. Tenable's vulnerability priority rating, built from about 150 data points, is illustrated with the Windows flaw abused by Sodinokibi ransomware, an Oracle bug whose threat faded, and a Linux kernel flaw scored before its CVSS existed. He closes on new metrics: risk trends by business unit, SLA attainment, peer benchmarks and gamification.
The threat landscape isn't just changing at blinding speeds, it's expanding into areas and devices that many never considered before. Vulnerability Management (VM) tools have been around for many years, but like
any other security function, have had to adapt to account for the scope and scale of the devices security teams are protecting. In this discussion, we'll take a look at some of the challenges security teams are facing when trying to mitigate vulnerabilities across every type of asset out there. We'll also discuss how a risk-based approach to prioritization of vulnerabilities is a real force multiplier for security programs versus traditional VM methodologies. Finally, we'll review a data science driven model for assigning risk, that,
even as the threat landscape changes, demonstrates how these approaches can be brought together to answer the right kinds of questions your leaders are asking which will improve your overall security posture and encourage a stronger security culture in your organization.
Key takeaways
- Stop reporting patch counts; report risk reduction by business unit, SLA attainment and peer benchmarks, and let friendly competition between teams drive remediation.
- Prioritise on exploitability and active threat activity layered on asset criticality; only a small fraction of the thousands of yearly CVEs have working exploits.
- Extend assessment beyond servers and workstations to web applications, containers, cloud and OT, and validate that a patch plus its configuration change actually removed the risk.
- Assign an owner to every asset and agree the remediation path with them; many fixes are configuration, code or compensating controls rather than a patch.
- Integrate scanner data with SIEM, endpoint, ITSM and finance or legal records (insurance coverage, policy requirements) to build a business-level view of exposure.

