Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Tenable Blog

Subscribe

Stop the Presses: Media Coverage as a Prioritization Metric for Vulnerability Management

We wondered whether mainstream media coverage of vulnerabilities changed how companies perform vulnerability management. So we asked them. Here’s what we learned.

In technical circles, vulnerabilities have always been news. More often now though, vulnerabilities are mainstream news. They are regularly covered in business outlets read by company leaders who may not otherwise get involved in the nitty gritty of vulnerability management. 

2018 was a big year for vulnerabilities in the media. Starting off immediately with Meltdown and Spectre in January, it felt like the coverage never stopped. Seeing this, we wondered whether and how this coverage changed the way companies were doing vulnerability management. So we asked them. Through the course of doing broad-scope interviews with CISOs and security analysts, we were sure to ask about their experiences with vulnerabilities in the news.

We asked interviewees “Has news coverage of vulnerabilities impacted your work? If so, how?” 

Most of them had experienced some sort of disruption to their normal operations because of vulnerability news coverage. The top two examples given were the speculative execution vulnerabilities, Meltdown and Spectre, and Struts2. The full report, Headline Vulnerabilities: How Media Coverage Shapes the Perception of Risk, contains details on strategies, tactics, and challenges that developed while responding to these incidents. Our key findings were that: 

  • High-profile vulnerabilities are not just a concern for security teams. These vulnerabilities, whether or not technically critical, can pose serious reputational risks and require relationship management with customers, partners, regulators and other key stakeholders. 
  • Media coverage is not an objective metric for determining the true criticality of a vulnerability, particularly in the context of a specific enterprise. The role of the media is to investigate and report on stories, not conduct risk analysis. They will report on vulnerabilities that are interesting, but not necessarily critical. 
  • However, media coverage may still influence holistic risk evaluations. While security teams are aware that media coverage is not an ideal measure of technical risk, they need to discuss their risk evaluation process with others. They also need to accept that the overall risk presented by a lower-severity vulnerability might require action.
  • Part of the role of a security team is to manage perceived risk and to advise key stakeholders, especially senior decision-makers, and enable a measured response to vulnerabilities based on contextualization, rather than hype. CISOs must be armed with vulnerability data in the proper context in order to properly convey their organizations’ Cyber Exposure to business leaders and invest resources appropriately to reduce risk.

However, there is another angle not covered in the report that I would like to discuss: it isn’t just the coverage in the business press that can impact how vulnerability management gets done. Security teams are tracking a much wider set of channels than their executives are for vulnerabilities. While security teams aren’t using this coverage as a single source of vulnerability intelligence, it can be used as a metric (combined with others) for prioritization. Let’s examine that aspect of the vulnerability media landscape. 

Vulnerability media landscape

While the Headline Vulnerabilities report focuses mainly on how organizations respond to major media coverage, stories that reach the level of the New York Times and broadcast news, the vulnerability media landscape covers a lot more than just those stories. While the pressure to perform is highest when the executive leadership or board of directors becomes aware of a vulnerability, security teams often use media coverage as a metric for severity. Media coverage typically will increase the priority of a vulnerability and this is particularly true once attacks are observed in the wild. For instance, Atlassian published an advisory for vulnerabilities in Confluence Server back on March 20, including a fix for CVE-2019-3396. However, it wasn’t until proof-of-concept (PoC) code and exploitation of this vulnerability became public that media outlets picked up on it. While it may not push it to the top of the pile, media coverage does act as an additional data point for prioritization.

Tenable’s Security Response Team (SRT) tracks vulnerabilities in the news (and other sources) and, since the beginning of 2019, nearly every noteworthy vulnerability disclosed has been covered by the media. That creates a lot of noise for security teams to manage. Media coverage is becoming less useful as a metric because the media landscape is changing. 

Reflecting on the changes to the media landscape, Ryan Seguin, research engineer on the SRT said, "I think over the last five years you've had a perfect storm of factors in the industry. The first major impact on vulnerability media coverage was Heartbleed in 2014, and the second being Twitter becoming the de facto method of communication for researchers. Heartbleed certainly wasn't the first vulnerability to get a catchy name, but in my anecdotal experience, its publication created a sort of vulnerability research gold rush. Since 2014, researchers are increasingly dedicated to being the next person to discover the perfect vulnerability worthy of a great writeup and a dazzling web page. In addition to getting your name out in the world and building your credibility, bug bounty programs have also become more lucrative, and more organized.” This shift in how researchers publicize their work to compete for attention has driven media outlets to deliver the high volume, noisy news cycles we are seeing.

The vulnerabilities and tactics discussed in the report align with the theme of boardroom interest that has maintained popularity in cybersecurity for the last few years. How do security teams not only react to, but capitalize on the increased attention from C-levels and boards? Especially in 2018, that attention turned toward vulnerability management. Whether this attention is triggered by a story in the business press or a technical outlet like Bleeping Computer, security teams need to be able to articulate the risks posed by vulnerabilities in terms that allow key stakeholders to make the best decisions.

Watch: Expert Panel Discusses Headline Vulnerabilities Report at Edge 2019

Update, June 4, 2019: We discussed the report's findings in an Expert Panel session during Tenable's Edge 2019 user conference, May 21-23 in Atlanta. The session was moderated by Paul Roberts, Publisher and Editor in Chief of The Security Ledger, and featured myself along with: Kevin Kerr, CISO, Oak Ridge National Laboratory; Greg Kyrytschenko, Head of Security Services, Guardian; and Ramin Lamei, Senior Director, Information Security Officer, Global Payments. Watch the full session below:

Learn more:

Related Articles

Cybersecurity News You Can Use

Enter your email and never miss timely alerts and security guidance from the experts at Tenable.

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy.

Your Tenable Vulnerability Management trial also includes Tenable Lumin and Tenable Web App Scanning.

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

100 assets

Choose Your Subscription Option:

Buy Now

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy.

Your Tenable Vulnerability Management trial also includes Tenable Lumin and Tenable Web App Scanning.

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

100 assets

Choose Your Subscription Option:

Buy Now

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy.

Your Tenable Vulnerability Management trial also includes Tenable Lumin and Tenable Web App Scanning.

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

100 assets

Choose Your Subscription Option:

Buy Now

Try Tenable Web App Scanning

Enjoy full access to our latest web application scanning offering designed for modern applications as part of the Tenable One Exposure Management platform. Safely scan your entire online portfolio for vulnerabilities with a high degree of accuracy without heavy manual effort or disruption to critical web applications. Sign up now.

Your Tenable Web App Scanning trial also includes Tenable Vulnerability Management and Tenable Lumin.

Buy Tenable Web App Scanning

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

5 FQDNs

$3,578

Buy Now

Try Tenable Lumin

Visualize and explore your exposure management, track risk reduction over time and benchmark against your peers with Tenable Lumin.

Your Tenable Lumin trial also includes Tenable Vulnerability Management and Tenable Web App Scanning.

Buy Tenable Lumin

Contact a Sales Representative to see how Tenable Lumin can help you gain insight across your entire organization and manage cyber risk.

Try Tenable Nessus Professional Free

FREE FOR 7 DAYS

Tenable Nessus is the most comprehensive vulnerability scanner on the market today.

NEW - Tenable Nessus Expert
Now Available

Nessus Expert adds even more features, including external attack surface scanning, and the ability to add domains and scan cloud infrastructure. Click here to Try Nessus Expert.

Fill out the form below to continue with a Nessus Pro Trial.

Buy Tenable Nessus Professional

Tenable Nessus is the most comprehensive vulnerability scanner on the market today. Tenable Nessus Professional will help automate the vulnerability scanning process, save time in your compliance cycles and allow you to engage your IT team.

Buy a multi-year license and save. Add Advanced Support for access to phone, community and chat support 24 hours a day, 365 days a year.

Select Your License

Buy a multi-year license and save.

Add Support and Training

Try Tenable Nessus Expert Free

FREE FOR 7 DAYS

Built for the modern attack surface, Nessus Expert enables you to see more and protect your organization from vulnerabilities from IT to the cloud.

Already have Tenable Nessus Professional?
Upgrade to Nessus Expert free for 7 days.

Buy Tenable Nessus Expert

Built for the modern attack surface, Nessus Expert enables you to see more and protect your organization from vulnerabilities from IT to the cloud.

Select Your License

Buy a multi-year license and save more.

Add Support and Training