Vulnerability Programs Must Regain Trust To Inspire Action


It’s perhaps no secret that vulnerability programs remain inefficient and ineffective. It’s why my most often requested client inquiries are about how to prioritize vulnerability remediation and improve patching. It’s clear based on my conversations with clients in those inquiries that vulnerability teams are overwhelmed with how to calculate the risk of vulnerabilities and misconfigurations while operations teams are frustrated with an increasing volume of unrealistic remediation and mitigation deadlines. There’s a growing disconnect between those two teams. How did we get to this point, and how can vulnerability teams regain the trust they once had?

Let’s look at a specific example to better understand how this disconnect has developed. In 2017, Spectre and Meltdown processor vulnerabilities consumed security teams for weeks. Researchers even developed those nifty marketing graphics that made them seem scarier than they really were. Five years later, there have been no reported known breaches due to these vulnerabilities. All three Common Vulnerabilities and Exposures (CVEs) comprising the vulnerabilities were issued a Common Vulnerability Scoring System (CVSS) score of 5.6 due to its difficulty to exploit. Mitigating chip vulnerabilities is very challenging, and when teams hurriedly implemented mitigations system, performance suffered drastically. This is a great example of how VRM teams have lost trust from other internal stakeholders. That trust must now be regained.

Enterprise environments are increasingly complex. Security and risk professionals have been forced to rely on CVSS scores for prioritization. These methods led to creating service-level agreements (SLAs) based on CVSS. Since CVSS was never intended to provide risk prioritization within each enterprise’s unique environment, this has led to goal misalignment. SLAs such as “Patch all critical CVSS scores within 30 days” do not weigh the business context of asset criticality, whether exploits are published and active for that vulnerability, and if there are compensating controls that can protect against that exploit. Vulnerability and operations pros also need to weigh the impact on customer and employee experience if systems go down for patching and rebooting, versus the likelihood (and more significant impact) of that system being down due to a realized exploit causing a breach.

In November, I’ll be presenting a session entitled “Reinvent Your Vulnerability Management Program To Regain Trust” at Forrester’s Security & Risk event in Washington, D.C. This talk will cover methods to prioritize vulnerability remediation and redefine service levels so we can extend the olive branch to operations teams that have grown increasingly skeptical of the VRM team’s ongoing flood of (often inaccurate) vulnerability predictions. I look forward to sharing with you all the strategies, controversies, and communication methods that are necessary to rebuild this trust.

Learn more about the Security & Risk event, and review the agenda here.



Source link

Related articles

How To Prepare EA AutoRobot IQ7 | Technique Tester | Symbols & TimeFrames Analysis.. – Buying and selling Programs – 3 January 2026

First-Time Set up Information – EA Quantum IQ7 (All Platforms) For first-time set up of all EA Quantum IQ7 merchandise, please observe the...

Fender Presents Up Its First Wi-fi Headphones, With Emphasis on Battery Life

Fender Audio is unveiling its first wi-fi headphones at CES 2026 subsequent week, and the battery life is so lengthy they may outlast the four-day occasion itself. The Combine headphones boast 100 hours of...

Tether simply purchased 8,888 Bitcoin, exposing a mechanical revenue engine turning T-Payments into automated crypto demand

Tether purchased 8,888 Bitcoin in This fall 2025, lifting its holdings above 96,000 BTC, in line with a put up by CEO Paolo Ardoino.The acquisition extends a technique Tether has tied to working...

Ethereum Value Prediction 2026 As Vitalik Buterin Unveils New Scaling Roadmap

Ethereum value because the 12 months 2026 begins has rallied previous $3,100, marking a robust restoration. The 5% acquire pushed ETH to $3,122, its highest stage in weeks.  This improve...

The 2026 inventory market is wanting so much just like the bifurcated market of 2025

Dealer Peter Tuchman wears "2026" glasses as merchants work on the ground of the New York Inventory Trade on the opening bell on Dec. 31, 2025.Timothy A. Clary | Afp | Getty PhotosThe...
spot_img

Latest articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

WP2Social Auto Publish Powered By : XYZScripts.com