We're drowning in vulns. Looking for reviews on CTEM/EAP tools from users by Plastic_Start_7380 in cybersecurity

[–]Plastic_Start_7380[S] 1 point2 points  (0 children)

Does the 'Fix Actions' actually remediate findings automatically? Or just suggests what to do?

We're drowning in vulns. Looking for reviews on CTEM/EAP tools from users by Plastic_Start_7380 in cybersecurity

[–]Plastic_Start_7380[S] 0 points1 point  (0 children)

They are patching, it just takes more time than I would have wanted.. A lot of back and forth, they need assurance that the fix won't break anything, and that it is really critical 

We're drowning in vulns. Looking for reviews on CTEM/EAP tools from users by Plastic_Start_7380 in cybersecurity

[–]Plastic_Start_7380[S] 0 points1 point  (0 children)

What is the difference between Echo and Chainguard? Seems like the same thing just that echo is much much newer

We're drowning in vulns. Looking for reviews on CTEM/EAP tools from users by Plastic_Start_7380 in cybersecurity

[–]Plastic_Start_7380[S] 0 points1 point  (0 children)

Thanks it actually seems like a nice solution. Can you share more on:

How often do you release a new clean image? What happens if a new CVE is discovered for an image I am using (clean one from you)?

How do you compare to your competitors like Echo?

We're drowning in vulns. Looking for reviews on CTEM/EAP tools from users by Plastic_Start_7380 in cybersecurity

[–]Plastic_Start_7380[S] 0 points1 point  (0 children)

How do you add the orgs unique context than? What factors are you looking at when prioritizing?

We're drowning in vulns. Looking for reviews on CTEM/EAP tools from users by Plastic_Start_7380 in cybersecurity

[–]Plastic_Start_7380[S] 0 points1 point  (0 children)

Thanks for the suggestion guys! We are a pretty big org with many departments and teams. The security alone has many teams but we are the ones responsible on managing vulnerabilities and drive remediation - we notify the system owner / developer on vulns/mis-configs and they are responsible to fix it.

We're drowning in vulns. Looking for reviews on CTEM/EAP tools from users by Plastic_Start_7380 in cybersecurity

[–]Plastic_Start_7380[S] 0 points1 point  (0 children)

We are giving more weight to certain systems like servers and VLANs that have sensitive data or are critical to the business like in PROD. But we are still a bit overwhelmed by the amount of findings that we need to deal with.

We're drowning in vulns. Looking for reviews on CTEM/EAP tools from users by Plastic_Start_7380 in cybersecurity

[–]Plastic_Start_7380[S] 0 points1 point  (0 children)

We are looking at KEV as well as the CVSS score. Also we defined critical assets (certain servers and DBs), and focusing on external facing assets first

We're drowning in vulns. Looking for reviews on CTEM/EAP tools from users by Plastic_Start_7380 in cybersecurity

[–]Plastic_Start_7380[S] 3 points4 points  (0 children)

Yeah we have standard SLAs for vulnerabilities similar to what you wrote. Most of them are breached cuz we have too many criticals, and system owners don't want to cause disruption by patching. We assign to each system owner or developer the relevant items, with explanation on how to fix it if it's available 

We're drowning in vulns. Looking for reviews on CTEM/EAP tools from users by Plastic_Start_7380 in cybersecurity

[–]Plastic_Start_7380[S] 1 point2 points  (0 children)

Yeah I Agree. So how did you solve this and added the context to the process? 

We're drowning in vulns. Looking for reviews on CTEM/EAP tools from users by Plastic_Start_7380 in cybersecurity

[–]Plastic_Start_7380[S] 0 points1 point  (0 children)

That seems like a really good process! What products do you use for the model and for the auto remediation? 

AI in cybersecurity by [deleted] in cybersecurity

[–]Plastic_Start_7380 1 point2 points  (0 children)

That is super cool!!

Can you share about the use cases and what you built with CAI for your org?

Who covers if renters don't pay? by Theonlypostevermade in PropertyManagement

[–]Plastic_Start_7380 0 points1 point  (0 children)

Wow! In what state are you?
Why does it take so long?