Vulnerabilities, CVEs and the attack surface

Listen as Stephen Pritchard, security and technology journalist at Security Insights, talks with Tod Beardsley, VP of Security Research at runZero, about vulnerabilities, CVEs, and the attack surface.

About the episode

The way we measure security threats is changing. As security has become a board-level priority, cybersecurity teams need to think in terms of risk.

But where does that leave vulnerability scores? Are venerable systems such as CVSS, and the CVEs that underpin them, still relevant?

Or could a focus on vulnerability scores be a distraction from the real threats?

The truth, as ever, lies somewhere in between. Vulnerability scores are still a very useful way of categorising risks within an application, and sharing that information. What they cannot do is map those exploits to an organisation’s network, or their own workflows, security measures or even, their business priorities.

That, though, is the CISO’s job. And, as our guest for this episode points out, today’s much more expansive and flexible networks really demand a cultural shift in how we think about the attack surface, and how we defend it.

Meet Our Speakers

todb

VP of Security Research, runZero

Subscribe Now

Get the latest news and expert insights delivered in your inbox.

Welcome to the club! Your subscription to our newsletter is successful.


Related Resources

Podcasts
Only a third of KEV vulnerabilities are truly critical; are you prioritizing the wrong ones?
Discover how KEVology and the KEV Collider help defenders cut through the noise by enriching KEV data with exploit scores, timelines, & real-world...
Podcasts
Filtering the KEV was really hard … until now! (Risky Biz Interview)
Casey Ellis chats with Todd Beardsley about KEVology — an analysis of the CISA KEV. KEVology helps you identify the vulnerabilities most relevant...
Podcasts
The dangers of white label devices (Error Code Podcast)
Rob King, Director of Applied Security Research, explores white-labeled surveillance and IoT hardware, why some vendors are banned by governments,...
Podcasts
Lessons from the front lines of cybersecurity with HD Moore (Keep Austin Secure)
In this episode of Keep Austin Secure, Elliot Fielding sat down with HD Moore, Founder & CEO of runZero and it lived up to the hype.

See Results in Minutes

See & secure your total attack surface. Even the unknowns & unmanageable.