Home / Companies / Detectify / Blog / February 2022

February 2022 Summaries

2 posts from Detectify

Filter
Month: Year:
Post Summaries Back to Blog
External Attack Surface Management (EASM) has emerged as a crucial defensive strategy in cybersecurity, responding to the challenge of managing the vast and often unrecognized external attack surfaces of organizations. Traditional gate-based security measures are no longer sufficient for safeguarding these surfaces, which include internet-facing systems such as mobile devices, web applications, and cloud infrastructure. EASM programs help organizations monitor and protect these assets by identifying potential vulnerabilities, assessing risks, prioritizing threats, and implementing remediation actions. This approach is vital for keeping pace with the rapid adoption of cloud technologies and digital transformations. EASM emphasizes the importance of integrating both technology and human expertise, encouraging security awareness across the organization, and continuously iterating on processes to address evolving threats. A successful EASM framework can enhance other security initiatives, such as vulnerability management and threat intelligence, by providing comprehensive and proactive protection against cyber threats.
Feb 23, 2022 1,170 words in the original blog post.
Detectify's security tool seeks to simplify the understanding and management of security through visualizations and dynamic Threat Scores, which reflect the severity of vulnerabilities based on the CVSS version 3.1. This scoring system emphasizes measuring severity rather than risk and introduces a critical severity level for vulnerabilities scoring between 9 and 10. CVSS v3.1 aims to provide a comprehensive assessment by accounting for specific circumstances and configurations, such as network architecture, which can alter the perceived risk level of a vulnerability. Detectify categorizes vulnerabilities into Low, Medium, High, and Critical levels to help prioritize security efforts, with each level indicating the urgency and potential impact of the vulnerabilities present. The tool integrates CVSS scoring to offer a more precise evaluation of security issues, encouraging users to address vulnerabilities, especially those of High and Critical severity, promptly. The Common Vulnerability Enumeration (CVE) is also mentioned as a unique identifier for vulnerabilities, with CVSS providing a severity indication for each CVE.
Feb 14, 2022 1,050 words in the original blog post.