{"id":17030,"date":"2020-03-30T13:07:20","date_gmt":"2020-03-30T17:07:20","guid":{"rendered":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/?p=17030"},"modified":"2022-10-14T18:26:49","modified_gmt":"2022-10-14T22:26:49","slug":"new-risksense-srs-extends-inside-out-risk-scoring-to-provide-complete-threat-view","status":"publish","type":"post","link":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/security\/new-risksense-srs-extends-inside-out-risk-scoring-to-provide-complete-threat-view.html","title":{"rendered":"New RiskSense SRS Extends Inside-Out Risk Scoring to Provide Complete Threat View"},"content":{"rendered":"\n<p>One of the biggest challenges to organizations is cybersecurity spending. As many of our loyal readers know from our past reporting &#8211; a determined hacker can always get into a system.<\/p>\n\n\n\n<p>There are however layers of security an organization can put in place to hopefully ensure the hacker gives up and moves on.<\/p>\n\n\n\n<p>On any given day a company can be faced with, DDoS threats, phishing, social engineering\/spear-phishing and so much more.<\/p>\n\n\n\n<p>Even worse &#8211; these threats come from amateurs, hacker entrepreneurs, organized crime, terrorist groups and nation-states.<\/p>\n\n\n\n<p>CSOs have to protect the organization while justifying spend.<\/p>\n\n\n\n<p>This is where tools which score come in. In fact, they are essential.<\/p>\n\n\n\n<p>There is no foolproof tool mind you &#8211; at this point, a number of companies score an organization&#8217;s security. The point is that a score is better than no score.<\/p>\n\n\n\n<p>Every organization should have a sense of how their cybersecurity posture ranks &#8211; compared to other organizations and their peers. By peer, we are talking about companies in the same geographic area, company size and industry. In addition, we would also group companies which are customer-facing.<\/p>\n\n\n\n<p>For example, those which take a large number of credit cards.<\/p>\n\n\n\n<p>NIST suggests organizations work with peers to ensure you know what they are dealing with. It is likely what they see will be coming to you in the future.<\/p>\n\n\n\n<p>The point is hackers are smart enough to go after vulnerabilities in related industries.<\/p>\n\n\n\n<p>This is why you want to have the best cybersecurity posture in your space.<\/p>\n\n\n\n<p>To help, <a href=\"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/?s=risksense\">RiskSense <\/a>just introduced Full Spectrum RBVM (Risk-based Vulnerability Management) that automatically discovers, analyzes, scores, and prioritizes both internal and external-facing security threat exposure across an organization\u2019s IT infrastructure and applications. The cloud-delivered RiskSense solution now combines RBVM with RiskSense SRS (Security Rating Service) to provide 360-degree visibility that eliminates security gaps and enables security teams to measure, prioritize, and control both inside-out and outside-in risks from one integrated console.<\/p>\n\n\n\n<p>Last December we reported on the company&#8217;s <a href=\"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/security\/risksense-cybersecurity-predictions.html\">cybersecurity predictions for 2020<\/a>. These predictions have proven to be accurate so far &#8211; especially their first one&#8230; Ransomware. This problem has gotten far worse thanks to the Covid-19 Coronavirus which has forced employers to send workers home to work on computers that don&#8217;t have the same security protections as those in the office. Moreover, they can be shared by others in the household who do not have cybersecurity education.<\/p>\n\n\n\n<p>\u201cIn our opinion, there are two unique features of the RiskSense platform for\nIT management,\u201d said Dr. Alea Fairchild, Director, Constantia Institute. \u201cThe\nfirst is its ability to contextualize the threat landscape to highlight\npriorities and position the current security posture of the company. And the\nother is to compare the situation of the company to others in its industry to\nbenchmark within the industry domain how effectively their cybersecurity\nefforts have been deployed. It puts the security team in more of an offensive\n(vs. defensive) mode towards its cybersecurity efforts and outcomes.\u201d<\/p>\n\n\n\n<p>The new RiskSense SRS capabilities, which are fully integrated with the\nRiskSense platform, require nothing more than a second-level domain name\n(yourcompany.com, for example) to start performing a continuous, independent,\nquantitative discovery and analysis of all internet-accessible assets. It\ngenerates an external RiskSense Security Score, or xRS3, across key security\ncomponents including network security, application security, patching cadence,\nemail security, DNS security, and IP reputation. A benchmarking comparison is\nalso provided, which allows organizations to compare their cybersecurity\nposture against those of industry peers.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"803\" height=\"648\" src=\"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-content\/uploads\/2019\/12\/Srinivas-Mukkamala.png\" alt=\"\" class=\"wp-image-15919\" srcset=\"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-content\/uploads\/2019\/12\/Srinivas-Mukkamala.png 803w, https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-content\/uploads\/2019\/12\/Srinivas-Mukkamala-768x620.png 768w\" sizes=\"(max-width: 803px) 100vw, 803px\" \/><figcaption> Dr. Srinivas Mukkamala, CEO of RiskSense. <\/figcaption><\/figure>\n\n\n\n<p>\u201cBy providing an \u2018outside-in\u2019 perspective into an organization&#8217;s\ncybersecurity posture, RiskSense SRS extends our existing \u2018inside-out\u2019 approach\nto vulnerability management and remediation prioritization,\u201d said Dr. Srinivas\nMukkamala, CEO of RiskSense. \u201cSRS provides a quantified \u2018hacker\u2019s view\u2019, that\nautomatically discovers threats in internet-facing infrastructure including\nundocumented and misconfigured systems, externally accessible databases, as\nwell as exposed cloud, container, and SaaS apps.\u201d<\/p>\n\n\n\n<p>Each xRS3 score takes into account observed security best practices, past\nincidents, security weaknesses on externally-accessible assets, information\nleakage, and activity on the Dark Web to reflect an organization\u2019s overall\nsecurity stance. These scores facilitate initial benchmarking and ongoing\nmeasurement, meaningful prioritization of vulnerabilities and prioritized\nremediation activities, as well as a comparison with industry peers. The\nRiskSense platform helps users quickly orchestrate remediation actions; asset\ngrouping, ticket assignment, details and workflows for handling risk\nacceptance, false positives, and validation options that track the corrective\nactions and measurements to confidently know when vulnerabilities have been\nsuccessfully resolved.<\/p>\n\n\n\n<p>Risk scoring is a competitive space but tens of millions of companies still haven&#8217;t performed such analysis and they still need education on why this is important for them to do. Hopefully, the increased activity by vendors means companies will learn that the only way to be sure they are cyber secure is to benchmark against other, similar organizations with the goal being to lead the pack.<\/p>\n\n\n\n<p><strong>See the ONLY cybersecurity companies that\u00a0<a href=\"https:\/\/www.itexpo.com\/east\/exhibitor-list.aspx\">matter\u00a0<\/a>at  the\u00a0<\/strong><a href=\"http:\/\/www.itexpo.com\/\"><strong>ITEXPO<\/strong><\/a><strong>\u00a0#TECHSUPERSHOW<\/strong>. See video below for more.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>This Event has been&nbsp;<a href=\"https:\/\/www.itexpo.com\/east\/testimonials.aspx\">called the&nbsp;<strong>BEST SHOW in 5 YEARS<\/strong>&nbsp;and the&nbsp;<strong>Best TECHNOLOGY EVENT of 2020<\/strong><\/a>.<\/p><\/blockquote>\n\n\n\n<p>2020 participants included: Amazon, Cisco, Google, IBM, ClearlyIP, Avaya, Vonage, 8\u00d78, Comcast Business, BlueJeans, CoreDial, Dell, Edify, Epygi, FreeSWITCH, Grandstream, Granite,&nbsp;Intrado, Frontier Business, Fujitsu, Jenne, West, Konftel, Intelisys, Martello, NetSapiens, OOMA, Oracle, OpenVox, Peerless Network, Phone Sentry, Phone.com, Poly, QuestBlue, RingByName, Sangoma, SingTel, SkySwitch, Spracht, Spectrum, Sprint, Tallac, Tech Data, Telarus, TCG, Teledynamics, Teli, Telinta, Telispire, Telstra, TransNexus, Unified Office, Vital PBX, VoIP Supply, Voxbone, VoIP.MS, Windstream, XCALY, XORCOM, Yealink, Yubox, and ZYCOO.&nbsp;<a href=\"https:\/\/www.itexpo.com\/east\/exhibitor-list.aspx\"><strong>Full List.<\/strong><\/a><\/p>\n\n\n\n<p><strong>Join 8K others with $25B+ in IT buying power who plan 2021 budgets! Including 3,500+ resellers!<\/strong><\/p>\n\n\n\n<p>A unique experience with a collocated&nbsp;<a href=\"http:\/\/www.futureofworkexpo.com\/\">Future of Work Expo<\/a>,&nbsp;<a href=\"http:\/\/www.sdwanexpo.com\/\">SD-WAN Expo<\/a>,&nbsp;and&nbsp;<a href=\"http:\/\/www.mspexpo.com\/\">MSP Expo<\/a>\u2026<\/p>\n\n\n\n<p>June 22-25, 2021, Miami\u00a0<a href=\"https:\/\/www.itexpo.com\/east\/registration.aspx\">Register now<\/a>\u00a0and you could win a Tesla on Feb 12th.<\/p>\n\n\n\n<figure class=\"wp-block-embed-youtube wp-block-embed is-type-video is-provider-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"ITEXPO 2020 Intro 2\" width=\"500\" height=\"281\" src=\"https:\/\/www.youtube.com\/embed\/sZ8nZlOb5Hg?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>One of the biggest challenges to organizations is cybersecurity spending. As many of our loyal readers know from our past reporting &#8211; a determined hacker can always get into a system. There are however layers of security an organization can put in place to hopefully ensure the hacker gives up and moves on. On any<\/p>\n","protected":false},"author":44,"featured_media":15918,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[156],"tags":[1796,300,2171,2623],"post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/posts\/17030"}],"collection":[{"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/users\/44"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/comments?post=17030"}],"version-history":[{"count":5,"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/posts\/17030\/revisions"}],"predecessor-version":[{"id":17035,"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/posts\/17030\/revisions\/17035"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/media\/15918"}],"wp:attachment":[{"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/media?parent=17030"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/categories?post=17030"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/tags?post=17030"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}