Vulnerability management needs an update for the AI era | TechTarget

https://www.techtarget.com/rms/onlineimages/clock-time19.jpg

Organizations must rethink long-held assumptions about patch management and change how they prioritize, remediate and manage cyber-risk, especially in the age of AI.

Since 2019, the average time between vulnerability disclosure and confirmed exploitation has collapsed from months and weeks to mere hours. CISOs and their teams have far less time to assess risk, prioritize remediation and protect critical assets. CVSS scores, never a great measure of real-world risk on their own, are even less meaningful without additional metrics such as exploitability and asset criticality.

More than just patch deployment

Today, vulnerability management is less about simply deploying patches and more about continuously identifying and reducing the exposures attackers are most likely to exploit.

"Organizations should stop treating vulnerability management as a closed loop ending in a patch," said Nicole Carignan, senior vice president of security and AI strategy and field CISO at Darktrace.

Instead, security leaders must prioritize their...

Copyright of this story solely belongs to techtarget.com. To see the full text click HERE

Read more