SecurityBrief Australia - Technology news for CISOs & cybersecurity decision-makers
Story image
New Qualys solution enables better vulnerability management
Thu, 9th Jun 2022
FYI, this story is more than a year old

Qualys has unveiled Qualys Vulnerability Management, Detection and Response (VMDR) 2.0. The new cloud-based solution gives insights into an organisation's risk posture along with the ability to use drag and drop workflows to orchestrate responses, the company states.

The doubling of disclosed vulnerabilities over the last five years, the speed at which vulnerabilities are weaponised and the cyber talent shortage have left teams struggling to make their way through vulnerabilities with no way to fix them all.

According to Qualys, security and IT teams need a new systematic approach to cut through the noise and prioritise fixing the most critical vulnerabilities that will reduce risk in their environment.

Qualys VMDR 2.0 is designed to provide insight for security and IT teams who need to focus on the vulnerabilities that genuinely reduce risk.

Qualys beta customers with the TruRisk capability enabled prioritised on average 28% fewer critical vulnerabilities across a sample size of 2.6 million assets and 74 million detections, the company states. Simultaneously, they were able to reduce risk on average by 23% and in some cases as high as 50%, the company states.

IDC research director Michelle Abraham says, "Cyber risk is becoming part of the business risk equation. Even the most advanced organisations can't patch all the threats they uncover, which increasingly includes poorly misconfigured services.

"Organisations must prioritise efforts that result in the maximum reduction of risk. Qualys' approach to cyber risk management considers multiple factors like vulnerabilities and misconfigured systems, so organisations can focus on fixes that reduce their overall risk."

Qualys VMDR with TruRisk solution helps security and IT teams increase efficiency and save time by providing shared context and the ability to create drag and drop workflows to automate time-consuming vulnerability management operational processes, including vulnerability assessment of ephemeral cloud assets, alerting and prioritisation.

Qualys VMDR with TruRisk allows Security and IT teams to:

  • Reduce risk with holistic scoring: Quantify risk across the entire attack surface including vulnerabilities, misconfigurations and digital certificates, correlate with business criticality and exploit intelligence from hundreds of sources, including Shodan's attack surface exposure data. Qualys VMDR with TruRisk automatically de-prioritises vulnerabilities if compensating controls are in force, tracks risk reduction trends over time and helps organisations measure and report on the effectiveness of their cybersecurity programme across hybrid environments.
  • Quickly remediate at scale: Leverage rule-based integrations between VMDR and ITSM tools such as ServiceNow and JIRA, along with dynamic vulnerability tagging, to automatically assign remediation tickets to prioritise vulnerabilities and bridge the gap between security and IT teams. Orchestrate remediation directly from the ITSM tool to help close vulnerabilities faster and reduce the mean time to remediation.
  • Receive preemptive attack alerts: External threat intelligence, from more than 180,000 vulnerabilities and 25 plus threat and exploit intelligence sources, is natively correlated with vulnerabilities and misconfigurations to proactively alert teams on vulnerabilities exploited by malware or those used in an active malicious campaign known to target your industry.
  • Automate operational workflows: Teams save time and resources with Qualys Qflow technology. They can develop drag and drop visual workflows to automate time-consuming and complex vulnerability management tasks, such as vulnerability assessments for ephemeral cloud assets, alerting for high-profile threats or quarantining high-risk assets.

Qualys president and CEO Sumedh Thakar says, “In this era of increasing attacks and board-level attention on cyber resiliency, efficiently managing cyber risk is more important than ever.

"With VMDR 1.0, we innovated by bringing the four core elements of vulnerability management into a seamless workflow to help organisations efficiently respond to threats.

"We're changing the game again with VMDR 2.0 allowing organisations to kickoff remediation workflows for vulnerability management tasks, prioritise remediation on the critical issues that reduce risk and streamline responses and integrations with ITSM solutions like ServiceNow.