Vulnerability management needs an update for the AI era

<p>Organizations must rethink long-held assumptions about patch management and change how they prioritize, remediate and manage cyber-risk, especially in the age of AI.</p>
<p>Since 2019, the average time between vulnerability disclosure and confirmed exploitation has <a target="_blank" href="https://www.sans.org/press/announcements/emergency-strategy-briefing-ai-driven-vulnerability-discovery-compresses-exploit-timelines" rel="noopener">collapsed</a> from months and weeks to mere hours. CISOs and their teams have far less time to assess risk, prioritize remediation and protect critical assets. CVSS scores, never a great measure of real-world risk on their own, are even less meaningful without additional metrics such as exploitability and asset criticality.</p>
<section class="section main-article-chapter" data-menu-title="More than just patch deployment">
<h2 class="section-title"><i class="icon" data-icon="1"></i>More than just patch deployment</h2>
<p>Today, vulnerability management is less about <a href="https://www.techtarget.com/searchenterprisedesktop/definition/patch-management">simply deploying patches</a> and more about continuously identifying and reducing the exposures attackers are most likely to exploit.</p>
<p>"Organizations should stop treating vulnerability management as a closed loop ending in a patch," said Nicole Carignan, senior vice president of security and AI strategy and field CISO at Darktrace.</p>
<p>Instead, security leaders must prioritize their responses based on exploitability, exposure, asset criticality and the organization's ability to detect and&nbsp;contain&nbsp;exploitation if patching is delayed. "They need to know where they are exposed, what normal behavior looks like, whether they can&nbsp;identify&nbsp;out-of-place activity and autonomously respond or&nbsp;contain it&nbsp;before it becomes a larger incident," she said.</p>
</section>
<section class="section main-article-chapter" data-menu-title="Follow the feds">
<h2 class="section-title"><i class="icon" data-icon="1"></i>Follow the feds</h2>
<p>The shift is already underway within U.S. federal civilian executive branch agencies. CISA recently issued <a href="https://www.techtarget.com/searchsecurity/news/366644336/What-CISAs-new-remediation-directive-means-for-CISOs">binding operational directive 26-04</a> as a response to new challenges stemming from AI-driven vulnerability discovery and exploit development. The ruling effectively replaces traditional severity-driven patch management with a risk-based model that requires agencies to consider factors such as active exploitation, internet exposure, exploit automation potential and attack impact.</p>
<p>The directive also requires agencies to remediate the highest-risk vulnerabilities within three days; lower-priority threats can be deferred. Significantly, as part of the mandate, federal agencies must conduct a full forensic triage after remediating high-priority vulnerabilities to determine whether their systems are already compromised.</p>
<p>The directive reflects a broader recognition that technical severity alone is no longer an adequate guide for remediation decisions. Instead, organizations increasingly need to weigh a vulnerability's likelihood of exploitation alongside the potential operational and <a href="https://www.techtarget.com/searchsecurity/feature/Why-effective-cybersecurity-is-important-for-businesses">business impact</a> of a successful attack.</p>
</section>
<section class="section main-article-chapter" data-menu-title="Put CVSS in context">
<h2 class="section-title"><i class="icon" data-icon="1"></i>Put CVSS in context</h2>
<p>Even as vulnerability management tactics evolve, CVSS can still help companies prioritize risk initially, said Jeffrey Wheatman, senior vice president and cyber-risk strategist at Black Kite. But additional context will be vital, especially metrics such as the likelihood that a vulnerability will be exploited in the next 30 days — as measured by the <a href="https://www.techtarget.com/searchsecurity/opinion/Key-capabilities-for-effective-cyber-risk-management">Exploit Prediction Scoring System</a>. When making patching decisions, organizations need to gather context about the potential operational and financial impact of a specific vulnerability in their environment.</p>
<blockquote class="main-article-pullquote">
<div class="main-article-pullquote-inner">
<figure>
Architect your program as patch intelligence, not patch management.
</figure>
<figcaption>
<strong>Jeffrey Wheatman, senior vice president and cyber-risk strategist, Black Kite</strong>
</figcaption>
<i class="icon" data-icon="z"></i>
</div>
</blockquote>
<p>Given the sheer velocity of AI-driven vulnerability discovery, organizations should shift from a "patch it all" mentality to a "patch what can cause damage right now" approach, Wheatman said. "Create remediation tiers with appropriate targets, not one

[…]
Content was trimmed to protect the source. Please visit the original article for the full text.

This article has been indexed from Search Security Resources and Information from TechTarget

Read the original article: