This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Do We Need To Remediate Them All?

Download resources

About this session

Todd Dow, a Cisco sales engineer who came from Kenna Security and is a former CISO, makes the case for risk-based vulnerability management. The numbers: breaches took 197 days to identify and 69 to contain, 57 percent of victims were hit through a vulnerability with an available patch, a third knew they were exposed, and most IT teams can only remediate about 10 percent of findings per cycle. Using CIS Control 3 as the reference process, he shows why CVSS and scanner scores prioritise poorly: more than three quarters of CVEs have no published exploit and under 2 percent are seen exploited in the wild, so a CVSS 7-and-up policy floods teams with false positives while missing half of what attackers use. He walks through the intelligence that tracks a vulnerability's life (NVD, early social chatter, Exploit DB, Metasploit, zero-day feeds) and a maturity path from full inventory to a shared risk score, IT alignment and dashboards. A long Q&A covers asset weighting, building your own model, SLAs, chained mediums and blame when the unprioritised one is exploited.

Do CVSS scores, news headlines, proprietary vendor ratings and intelligence feeds have you feeling analysis paralysis when it comes to vulnerability remediation? In this talk, we'll look at the factors to take into consideration when weighing enterprise risk and we'll talk about how to realize effective risk reduction with efficient remediation efforts.

Key takeaways

  • Accept that IT can remediate roughly 10 percent of findings per cycle and prioritise by likelihood of exploitation in the wild rather than by CVSS or scanner severity.
  • Get full asset inventory and scan coverage first; treat systems too fragile to scan as your weakest points and isolate them with compensating controls.
  • Feed exploit intelligence (Exploit DB, Metasploit, GitHub, dark web and social chatter, zero-day feeds) into the vulnerability list, since early chatter volume predicts how serious a CVE becomes.
  • Combine an asset priority weighting with vulnerability impact and likelihood to produce a single risk score that IT and security share, then drive that score down over time on common dashboards.
  • Introduce remediation SLAs only once the program is under control; start with low-hanging fruit such as OS security updates, then add due dates and tighten them gradually.

Speakers

Todd Dow
Todd Dow
Technical Security Solutions Specialist · CISCO
Todd Dow is a Technical Security Solutions Specialist at Cisco. He is also a writer, speaker, geek, CF fundraiser and founder of InfoSec Hamilton. Todd’s family, baseball, infosec & devops are a few of his favourite things. Todd has spoken at… Read moreRead less

Todd Dow is a Technical Security Solutions Specialist at Cisco. He is also a writer, speaker, geek, CF fundraiser and founder of InfoSec Hamilton. Todd’s family, baseball, infosec & devops are a few of his favourite things. Todd has spoken at numerous industry events including Sector and the International Association of Privacy Professionals (IAPP). Todd has over 20 years of experience in the cybersecurity field performing penetration tests, providing security architecture and compliance consulting and creating, developing and leading high performing security teams - this included working as the CISO at two organizations: First Ontario Credit Union and ArcelorMittal Dofasco. Todd maintains CISSP, CISA and PMP credentials and he has also earned an Hon BA in Philosophy and Religious Studies from the University of Toronto.

Resources

Tags

More from GoSec 2022

Also from Todd Dow

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.