Tired of ads? Enjoy an ad-free experience by signing up.
  • Insights
    This article was written by a TIA community member. Insights pieces undergo the same rigorous editorial process that newsroom-produced articles have.
Darric Hor ยท ยท 3 min read

3 ways startups can face seemingly perpetual cyber threats

hacker

Photo credit: Pixabay.

Everyone has their own way of prioritizing tasks. The low-priority items are often put off indefinitely simply because there are no available resources or time to tackle them. This may be in some way effective in life and business, but it is dangerous when managing cybersecurity threats.

The recent Verizon Breach Investigations report shows that the top 10 vulnerabilities accounted for 85 percent of successful exploit traffic. The remaining 15 percent was attributed to more than 900 common vulnerabilities and exposures. Clearly, if you merely follow a priority strategy, staying focused only on the top 10 vulnerabilities without effectively detecting the risks to your network and managing them, you may be leaving your network critically exposed.

The irony is that the vast majority of these vulnerabilities can easily be resolved either by a simple patch or some basic coding best practicesโ€”assuming you have identified the risk, of course.

To break the high-priority habit, here are the three best practices for ensuring a comprehensive vulnerability management program that will help your startup successfully navigate the increasingly dense, diverse, and dangerous world of cybersecurity threats.

1. Develop context

Context is key when it comes to understanding the nature of a problem and making the most effective response decision. If someone shouts, โ€œFire,โ€ youโ€™ll need more information (Whereโ€™s the fire? How big is it? How quickly is it spreading? Is anyone in danger or hurt?) before deciding whether you should run toward the fire to help, run away from it to protect yourself, call the fire department, or grab an extinguisher.

The same is true of vulnerabilities. Once we know the number of vulnerabilities, the severity level, and how long the vulnerability has been inside your system, responding effectively still requires answers to additional questions: Which assets might be affected? Where are they on my network? Is a patch available? If so, when can it be deployed? If not, can the risk be mitigated through the real-time protection offered by a firewall or intrusion prevention system?

Only by knowing the context can you ensure you will make the right response decision.

2. Make sure data is consumable and actionable

Everyone likes data that is clear and can be acted on immediately. But not everyone finds such data.

We know from experience that startups typically have a laundry list of vulnerabilities in a spreadsheet which is sent to various stakeholders. It is also assumed that each new scan report gets opened. This almost guarantees vulnerability management failure. It is nearly impossible to use such a document to accurately assess the risks and coordinate with the operations team to remediate high-risk vulnerabilities. This is like having hundreds of โ€œurgentโ€ emails to address by end of day where we are left with the problem of how to figure out which is crucial and which can wait.

How can entrepreneurs decide which vulnerabilities to prioritize when they all pose a risk to the organization?

To mitigate this, vulnerability scan outputs must be in a form that is easily consumed by both the security and operations teams. It must include details such as the severity level and age of the vulnerability, and the information also needs to be actionable. This requires creating a fast, automated (and thereby repeatable) process connecting a high-risk vulnerability to its remediation.

3. Increase your vulnerability intelligence

As you improve your ability to develop context and respond to vulnerabilities based on actionable data, your overall level of โ€œvulnerability intelligenceโ€ goes up, enabling you to make even better security decisions. It also allows you to continuously adapt your vulnerability management approach as threats evolve to accelerate the discovery-to-remediation timeline and reduce overall risk.

Vulnerabilities will continue to increase and attackers will continue on their two-pronged approach of looking for low-hanging fruits. Even as attackers evolve their strategies, it is critical to have a sound vulnerability management strategy based on comprehensive, up-to-date scan data and the ability to see the threat context quickly and easily. This is the only way you can avoid the โ€œpriority trapโ€ and be sure you are making the right decisions in mitigating both the most common current threats that can lead to a significant security incident.

Stay ahead in Asiaโ€™s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

๐Ÿ„ For casual readers / ๐Ÿ‘ถ Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

โŒ›Sign up in 20s. No payment details needed.

๐Ÿ“– For learners / ๐Ÿ‘ Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.

Community Writer

Darric Hor

I am responsible for managing and growing BMCโ€™s business portfolio across ASEAN. I have >20 years experience in the technology industry and >10 years in senior management roles in SEA.