custom white shadow vectorcustom white shadow vector

Vulnerability Prioritisation

Vulnerability Prioritisation

We’ve all spent countless hours working through long lists of vulnerabilities trying to work out which we should tackle first. Therein lies the problem. It’s often a broken process, and the process itself ties us up in knots. 

We all know that in order to minimise alert fatigue and decrease false positives, successful vulnerability prioritisation must start channeling resources toward the specific vulnerabilities posing the greatest regulatory, financial, and operational risks.

The question is how do you get there? Let’s take a step back.

To perform effective vulnerability prioritization, you have to ask the following ten questions:

  1. What does the total threat landscape look like for my organisation?
  2. What is our risk appetite?
  3. Do we truly understand the criticality of our assets across the business?
  4. How do we address the unknown unknowns? 
  5. Do I have a systematic process of evaluating the threat intelligence feeds against my digital estate?
  6. Is my discovery process working to detect vulnerabilities on the assets deemed to be at higher risk levels?
  7. Is my scoring process customisable, so I can directly match my knowledge of the real underlying business risks with vulnerability risk from potential attacks? Relying on someone’s vulnerability score isn’t going to work.
  8. Can I clearly identify the vulnerabilities, at each stage of the attack, along with the verifiable code to prove the attack vector?
  9. Do I have the proper metrics so I can build management reporting for OKRs and Key Risk Indicators that actually make sense for the business.
  10. Does my process result in demonstrable risk reduction? Can I prove that?

Let’s look at how VerifiedThreat can help with the questions as defined above. Let’s look at the following key stages of vulnerability prioritization, and map each one.

Key Stages of Vulnerability Prioritisation

Stage

Objective

Primary Inputs

Typical Output

Threat Intelligence Correlation

Identify the scope of the threats

Intel feeds, CVE, KVE databases, MITRE ATT&CK FRAMEWORK data, open source data, EuRepoC, VCDB, Ransomware.live

Exploitability status by e.g.MITRE ATT&CK Type 

Asset Discovery 

Identify the scope of the assets along with the business criticality

Assets lists, cloud asset tools, procurement data, external tools

Asset list API with its own

Business Context Enrichment and criticality tagging

Add business and technical context

Asset criticality, internet exposure, data classification

Enriched findings

Enriched continual vulnerability assessments

Determine active threat relevance according to the discovery and threat intelligence

Orchestrated VerifiedThreat agents, exploit feeds, malware telemetry

Exploitability status

Risk Scoring

Customise your risk according to the known asset criticality priority

Business risk appetite, business impact, exploitability

Ranked vulnerabilities known criticality x exploitability

Validation

Confirm the vulnerability assessment or attack vector

Use automated agents, access to the code, logs, re-test and automated revalidation 

Critical findings, methodology, threat data all prioritized automatically 

Remediation Planning

Assign actions and owners

Change windows, maintenance schedules

Remediation backlog

Metrics and Reporting

Measure programme performance

Custom Key Risk Indicators and OKRs. 

Custom Gen AI Executive dashboards

Threat Intelligence Correlation

Scoping the total threat landscape is perhaps the most effective way of trying to predict and thus prevent risk. Many of the threat intelligence sevices has real-time feeds and regularly process data on the latest attacks. In reality there are very few zero day totally novel attack vectors, and when they are discovered, they rarely stay unexposed by the threat intelligence community for long. Typically attackers make marginal improvement gains on existing methods - for example adding GenAI to phishing attacks to make the messaging seem more realistic. 

Ensure your vulnerability prioritization matches the incoming threat landscape, and that your vulnerability tooling has inbuilt threat intelligence feeds that help bridge the gap.

VerifiedThreat makes this easier, with our partnership with Cyjax, we’re able to show the incoming threats across the entire attack landscape all referenced according to the MITRE ATT&CK framework ID.

Without prioritisation, teams often spend significant time patching e.g. low-impact systems while attackers target actively exploited vulnerabilities on critical assets. Dynamically matching up the incoming threat intelligence with smart agent based vulnerability assessments ensures that you are truly scoping the entire attack surface, and the red team simulation hits the target areas exposed by the threat intelligence. In the screenshot above, all the threat data is shown in blue, and where it overalps with a known vulnerability is marked in red or orange according to the vulnerability and asset criticality. 

Now we can be sure the threat intelligence is correlated to our own unqiue platform and tech stack. This is extremely difficult to do, and very time consuming. Sidelining this vital scoping step is a critical mistake. Many organizations that do have threat intelligence struggle to assimilate the knowledge and communicate the risks to the wider risk owners, and knowledge tends to sit in silo’s. 

Asset Discovery

A typical enterprise may identify tens of thousands of vulnerabilities each month. Many are low-risk configuration issues, while a small percentage represent immediate compromise paths. 

Prioritisation enables us to:

  • Have a thorough discovery process that's actually looking at the assets you are deploying live - not the assets you’ve purchased or the assets you think you are running is vital here.
  • Map the assets to criticality and show the risk profile of the asset. 
  • Use the API to ensure a full asset register is maintained with the continuous scanning to ensure rigorous inventory control. 

Business Context Enrichment and Criticality Tagging

Crucial to the business is the ability to quickly and easily add the business context and criticality. VerifiedThreat automatically does assign an asset priority score, according to the context of the asset. However, the business will have much better insight into the actual use of the asset, and the cascading tagging allows companies to quickly tag the asset according to the correct business priority, and have it managed through the life of the asset. 

The tagging is completely flexible, allowing you to e.g. report on for example, the testing environment, or production only, or produce reports by risk owner, or asset class. 

Enriched continual vulnerability assessments

Now that we’ve got our threat intelligence properly scoped and the asset discovery aligned with our business risk, it’s time to add the enrichments into our continual vulnerability assessments. The orchestrated agents are focused on the higher risk threats on the assets we’ve already identified as key. This allows us to concentrate our red team simulation on the precise areas that we care about. The enriched data is automatically pulled into the risk register and shows the entire attack surface by risk. Now we’ve got a good handle on the overall risk surface and the priority of our vulnerabilities. As we go through the formal stages of accepting, mitigating or remediating the risk, the latest risk changes are automatically reflected in the reporting.

Risk Scoring

You can only score what you can easily measure, and unfortunately that often means missing the wood from the trees. VerifiedThreat allows for custom scoring, using the enriched asset criticality scores to drive the overall risk scoring. This allows the business to ensure the scoring is reflecting by the actual underlying asset criticality. Each attack type can be rolled into an overall Key Risk Indicator and OKRs can be quickly built showing the progress to actually reducing the overall risks that have been identified as a priority by the business.

Validation

We’re called VerifiedThreat for a reason! We provide the evidential proof of each threat so it can be quickly and easily validated. Each vulnerability includes the backup threat intelligence, the exact attack vector with the vulnerabilties at each stage of the attack chain, and the evidential proof of the vulnerabilty so that it can be re-run, or checked in the logs. 

Remediation Planning

Once we’ve understood the exact nature of the vulnerability, the risk register and the data view can be shared with the wider team. The red team has all the details of the simulation and can sandbox and reproduce the exploit. The blue team is kept fully informed, and can check the progress of the remediation from the risk ledger. 

Metrics and Reporting

Although VerifiedThreat has a wide range of metrics and reporting that meets the needs of most customers we’ve also included a prompt based LLM which allows you to completely customise the reporting. If you’re after the ultimate in customisation, this option allows you to have the most flexibility and ensures you can automate even the branding and styling of your existing corporate reports.

custom vectorstar

Engage with our Team

Schedule your Demo Below

We're committed to your success!