Enterprise Security Weekly (Video)

Vulnerability Management is Dead! - Rickard Carlsson - ESW #257


Listen Later

Modern tech stacks are becoming increasingly complex puzzles of components built in-house and sourced from third-party vendors. With DNS at the center of the infrastructure, and staging and production being sometimes just minutes apart, scanning for CVEs is not enough to stay on top of web threats. There are lots of critical things traditional app scanners won’t catch, like dangling DNS records, subdomain takeover and open S3 buckets. To keep their growing attack surface secure, companies need to combine crowdsourced vulnerability detection with solutions that detect outliers and anomalies in their software - before these become an attack vector. In this episode we’ll discuss:

- Why hunting for vulnerabilities is no longer enough to stay on top of threats

- Vulnerability Management vs Attack Surface Management

- How security teams can adapt their vulnerability management process to modern dev cycles.

 

Segment Resources:

More insights on how to secure your external attack surface: https://detectify.com/resources

Free trial of Detectify's attack surface management solutions: https://detectify.com/product/surface-monitoring

https://detectify.com/product/application-scanning

 

This segment is sponsored by Detectify. Visit https://securityweekly.com/detectify to learn more about them!

 

Visit https://www.securityweekly.com/esw for all the latest episodes!

Show Notes: https://securityweekly.com/esw257

...more
View all episodesView all episodes
Download on the App Store

Enterprise Security Weekly (Video)By Security Weekly Productions

  • 4.7
  • 4.7
  • 4.7
  • 4.7
  • 4.7

4.7

3 ratings


More shows like Enterprise Security Weekly (Video)

View all
Security Weekly Podcast Network (Video) by Security Weekly

Security Weekly Podcast Network (Video)

35 Listeners

Risky Business by Patrick Gray

Risky Business

360 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

628 Listeners

Grumpy Old Geeks by Jason DeFillippo & Brian Schulmeister with Dave Bittner

Grumpy Old Geeks

6,025 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,014 Listeners

Security Weekly News (Video) by Security Weekly Productions

Security Weekly News (Video)

5 Listeners

Paul's Security Weekly (Audio) by Security Weekly Productions

Paul's Security Weekly (Audio)

16 Listeners

The Daily by The New York Times

The Daily

111,114 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

7,855 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

167 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

187 Listeners

Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

Defense in Depth

78 Listeners

Paul's Security Weekly (Video) by Security Weekly Productions

Paul's Security Weekly (Video)

2 Listeners

Cloud Security Podcast by Cloud Security Podcast Team

Cloud Security Podcast

57 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

117 Listeners