Home / Companies / Detectify / Blog / May 2023

May 2023 Summaries

2 posts from Detectify

Filter
Month: Year:
Post Summaries Back to Blog
AppSec teams face challenges in validating and scaling security policies, such as enforcing security headers and removing risky technologies, prompting the launch of Attack Surface Custom Policies within Surface Monitoring. This feature allows for setting, enforcing, and scaling customizable security policies, with a recent update enabling the assignment of severity ratings to policies, aligning them with existing vulnerability management systems. This enhancement aids in prioritizing threats and ensuring breaches are addressed according to established workflows. Additional improvements include the ability to set rules on fingerprinted technologies, helping security teams identify and manage technologies across their attack surface, which is particularly beneficial during modernization or consolidation efforts. Technologies are now grouped by versions to streamline interaction, and the Attack Surface and Vulnerabilities page offers improved functionality for filtering and management. Detectify users can log in to review their attack surface exposure, while new users are encouraged to sign up for access.
May 12, 2023 406 words in the original blog post.
Detectify's inclusion in the 2023 Gartner Competitive Landscape for External Attack Surface Management (EASM) report highlights the evolving role of EASM as a critical component of modern cybersecurity strategies. The report points out that while external asset discovery is a core feature of EASM, it no longer differentiates products due to widespread vendor claims, leading to ambiguity and potential productivity issues. Detectify emphasizes that EASM should seamlessly integrate into existing security infrastructures, offering a more comprehensive solution than traditional Application Security (AppSec) tools. By focusing on rapid vulnerability resolution and integrating with developer workflows via tools like Slack and Jira, Detectify's EASM platform aims to replace outdated AppSec tools, enhance process efficiency, and provide continuous, actionable insights for AppSec and ProdSec teams. The platform's unique features, such as Attack Surface Custom Policies and Groups, empower organizations to manage their digital assets effectively, challenging the notion that EASM is merely an additional expense.
May 05, 2023 906 words in the original blog post.