The Importance of Asset Context in Attack Surface Management.


This is the last of the four blogs (Help, I can’t see! A Primer for Attack Surface Management Blog Series, The Main Components of an Attack Surface Management (ASM) Strategy, and Understanding your Attack Surface: Different Approaches to Asset Discovery) covering the foundational elements of Attack Surface Management (ASM), and this topic covers one of the main drivers for ASM and why companies are investing in it, the context it delivers to inform better security decision making.

Read more…
Source: Rapid7


Sign up for our Newsletter


Related:

  • DHS Announces $18.2 Million In First-Ever Tribal Cybersecurity Grant Program Awards

    July 1, 2024

    WASHINGTON — Today, the Department of Homeland Security (DHS), through the Federal Emergency Management Agency (FEMA) and the Cybersecurity and Infrastructure Security Agency (CISA), announced more than $18.2 million in Tribal Cybersecurity Grant Program (TCGP) awards to assist Tribal Nations with managing and reducing systemic cyber risk and threats. These are the first-ever Tribal Cybersecurity Grants ...

  • 2024 U.S. Federal Elections: The Insider Threat

    June 28, 2024

    The Federal Bureau of Investigation (FBI), in coordination with the Department of Homeland Security’s (DHS) Office of Intelligence and Analysis (I&A), the Cybersecurity and Infrastructure Security Agency (CISA), and the U.S. Election Assistance Commission (EAC) prepared this overview to help partners defend against insider threat concerns that could materialize during the 2024 election cycle. For years, ...

  • Critical Vulnerability in Fortra FileCatalyst Workflow

    June 27, 2024

    Fortra has released a security update addressing a critical vulnerability found in FileCatalyst Workflow. FileCatalyst is an accelerated file transfer software solution that allows the transfer of large files over remote networks. CVE-2024-5276 is an SQL Injection vulnerability with a CVSSv3 score of 9.8 (critical), which if exploited could allow an unauthenticated attacker to modify or ...

  • Stopping Chinese cyberattacks is officially now the biggest priority for US security forces

    June 25, 2024

    The US Department of Homeland Security (DHS) has shuffled its priorities to place battling the “cyber and other threats posed by the People’s Republic of China” at the top of the list, at least until the end of 2025. China has been conducting numerous cyber attacks against US infrastructure, particularly focussing on internet-facing endpoints within water ...

  • U.S. Department of Homeland Security Bolsters Indo-Pacific Maritime Cybersecurity through Partnership with Indonesia

    June 18, 2024

    WASHINGTON – From June 10-13, the U.S. Department of Homeland Security (DHS) partnered with the Government of Indonesia under U.S. Department of State International Narcotics and Law Enforcement and U.S. Department of Defense Threat Reduction Agency programs to enhance the security and resilience of the international maritime transportation system. This reflects a joint commitment by both ...

  • Analysis of user password strength

    June 18, 2024

    The processing power of computers keeps growing, helping users to solve increasingly complex problems faster. A side effect is that passwords that were impossible to guess just a few years ago can be cracked by hackers within mere seconds in 2024. For example, the RTX 4090 GPU is capable of guessing an eight-character password consisting of ...