Introduction:
Vulnerability management is a critical cybersecurity program that most organizations struggle with. The Ponemon Institute conducted a study that found 56% of cyber-attack victims were breached due to an unpatched vulnerability. Forty percent of the victims knew they were vulnerable before being compromised. This blog series will provide the information needed to build a world-class vulnerability program. Whether you're managing an existing vulnerability program and want to improve its quality and efficiency, or you're new to cybersecurity. You are trying to gain the skills to land a job. This series covers everything from cyber risk and how it should be used in a vulnerability management program to how vulnerability management interfaces with business units outside of cybersecurity and how to build a board-ready presentation with key performance indicators (KPIs) that measure success.
What is Vulnerability Management?
Vulnerability Management, according to ServiceNow, is defined as "processes, tools, and strategies of identifying, evaluating, treating, and reporting on security vulnerabilities and misconfigurations within an organization's software and systems." While this definition is accurate, it needs to highlight the complexity of the task. Vulnerability management includes many nuances and sub-processes. As a vulnerability management practitioner, you must understand the following concepts:
- Cybersecurity risk
- Common Vulnerabilities and Exposures (CVEs)
- The National Vulnerability Database (NVD)
- The Cybersecurity & Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV)
- The Common Vulnerability Scoring System (CVSS) and Stakeholder-Specific Vulnerability Categorization (SSVC)
- Asset Management and Configuration Management Databases (CMDB)
- What a vulnerability scanner is and the data it provides
- Details of patch management processes
- What is configuration management, and how does it relate to vulnerability management?
- What compensating controls are and how to use them when patching isn't an option
- Why application testing is a critical part of the vulnerability management process
- How to build a vulnerability report and relevant key performance indicators (KPIs)
As you can see, vulnerability management is a complex problem. According to the Ponemon Institute, vulnerability management is so complex that 74% of organizations cannot effectively prioritize vulnerabilities. When organizations fail to prioritize vulnerabilities, it leads to disastrous results. Vulnerability Management is a program comprising many processes and stakeholders and is something you can master.
Why is Vulnerability Management Important?
According to IBM, the average data breach cost in 2023 was USD 4.45 million. Fifty-six percent of cyber-attack victims stated they were breached due to an unpatched vulnerability. A comprehensive vulnerability management program is critical to protecting an organization from cyber-attack. Building a vulnerability program may not seem more complicated than any other cybersecurity initiative to the untrained eye, but that couldn't be farther from the truth. Vulnerability Management must be treated with care because it interfaces with many different areas of an organization.
For example, many organizations need help building a complete asset management database. Vulnerability management programs have dependencies on content found in those databases. Teams responsible for vulnerability management coordinate with patch management groups to schedule patch deployments. Finally, vulnerability teams rescan to validate that the patches have been successfully installed and the vulnerability mitigated. The Asset Management and Patch Management articles will dive deeper into these topics.
Vulnerability Management Complexity
Is vulnerability management really this complicated? Let us share a real-life experience where we worked with one of the world's most prestigious hospitals. The organization owned tens of thousands of servers, over 250,000 workstations, and medical devices. The organization could not prioritize which of its 39 million vulnerabilities presented the most significant risk. Due to a lack of prioritization, patching teams were not as effective as they could be in applying the patches that eliminated the most important risks to the business. Application teams had too many applications to test after patching and needed help accomplishing their tasks within the permitted timeframe.
A "big four" consulting firm told the customer that they could supply them with 27 contractors for three years at a price of 39 million dollars. Those contractors would work through the organization's backlog of vulnerabilities. The customer's goals were resolved for a small fraction of the cost using the approach found in this series.
Vulnerability management plays a critical role in defending an organization and connects with many areas within the organization. Because of these facts, designing and operating a vulnerability management program is critically important.
Vulnerability Management is Important to a Cybersecurity Job Seeker
If you're a cybersecurity job seeker, the information contained in this series is essential for you.
In our experience, few organizations have internal penetration testers and even fewer of them run their own security operations centers (SOCs). However, many organizations have vulnerability management analysts. If you are trying to break into the cybersecurity job field, applying to jobs that more businesses hire for improves your chances of receiving a job offer. In addition, according to salary.com, the average pay for a person with vulnerability management skills is $141,000 annually. What is Vulnerability Management?