mnemonic security podcast

Exposure Management

mnemonic

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 34:42

In this episode of the mnemonic security podcast, Robby is joined by Bernard Montel, EMEA Technical Director & Security Strategist at Tenable, to break down the evolution of vulnerability management into exposure management. 

Bernard explains how security has shifted from traditional vulnerability scanning to a broader approach that considers misconfigurations, attack paths, and identity risks. They discuss why most breaches stem from a toxic combination of exposures, the growing complexity of cloud security, and how organisations can prioritise real risks instead of drowning in vulnerability lists. Plus, how AI is changing the game for both defenders and attackers.

Send us Fan Mail

Speaker

Welcome to the mnemonic security podcast.

Robby Peralta

This infamous attack surface of members will forever grow into the future of cloud, virtual devices, and integration with AI systems. Scanners will tell us everything that needs to be fixed. We won't have a chance to get to half of it. And somehow we need to figure out what to do first. It may not sound complicated, but explain to me why there are so many vendors working to solve this problem. You know, exposure management, vulnerability monitoring, attack surface management, risk-based prioritization, or continuous threat exposure assessments, whatever you want to call it, at the end of the day, it's all about one thing: understanding where you're weak before someone else does. Today's guest has a few opinions on how to go about doing that. Bernard Montel, welcome to the podcast.

Bernard Montel

Hello. I'm very excited.

Robby Peralta

Would you mind saying it in the beautiful French language?

Bernard Montel

Uh Bernard Montel. So Montel is easy. Bernard sometimes have people calling me a Bernard, uh Bernard, um Bernard, and that's the way we say it's in French.

Robby Peralta

Lovely to have you here. Are you joining us from France today?

Bernard Montel

Yes, I'm based in Paris right now, the French office uh of Tenable, center of Paris.

Robby Peralta

Nice, nice. Said you said tenable. How long have you been there?

Bernard Montel

More than three years. Uh, I've joined in September 2021.

Robby Peralta

Cool. And before that?

Bernard Montel

Bernard Montel

I spend many years in another company called RSA, where I have learned a lot of technologies and I've been CTO of uh RSA in EMEA and then Tenable. Cool.

Robby Peralta

You have a hard task today. So if I think of vulnerability management, you have like vulnerability scanning, you have attack surface management, you have continuous, what do they call that? Security posture management. You have the new one from Gardner, which is CTEM continuous threat exposure management. And then you have like this whole world of security validation, right? So it's like testing of vulnerabilities. And yeah, I could just go on and on and on and on. Do you share the same view of the market that it's just so many things and it's impossible to understand?

Bernard Montel

There are many things, but it's not impossible. Let's try to explain, okay, and try to simplify what those many acronyms are getting there and the evolution as well. So if we step back for one minute, all all kinds of attacks are using two ways to compromise the system: an existing vulnerability or misconfiguration. Nothing else. If we try to understand in more details from the technical standpoint, obviously you can spend hours to go, oh, this is a misconfiguration on that layer, the operating system, network identity, and so on. But at the end of the day, an attacker is looking after existing vulnerability that I can exploit or mistake and misconfiguration that someone has left the door open. And all of the names you mentioned are attached to that first pillar. Try to prevent reducing the attack surface, put the level down, closing the doors of an existing set of systems. But I didn't mention one of them. I didn't mention vulnerability management, I didn't mention assessment, I didn't mention scanners, anything. Just to explain to you what the entire industry from a preventive standpoint is trying to do, and that's first pillar.

Robby Peralta

So I've obviously just been heavily influenced by marketing then and all these different terms. But does that mean that none of those things I just mentioned, they all have their own role in that story and the prevention, correct?

Bernard Montel

They have different roles, but we also need to think about evolution. Okay. So 20 years ago we had networks and devices attached to a local network. And that's, for example, how Table has been created. Scanning those networks, scanning those devices, and to find if there is no vulnerability. For that, you need a scanner. So the scanner still exists today, and that was exactly how everyone started. Try to understand and discover those vulnerabilities, respectively, in the network and the devices. Vulnerability scanning. We still use a scanner, that's a very low-level kind of technology that is very needed, and we're still relying on those kinds of technologies for discovering vulnerabilities within a network and attached devices that still exist. But that is what we call vulnerability assessment. You check a scanner. Like when you go in the airport, you go in, you ring, you have something that is definitely something which is not good for the security, like a vulnerability, and then you're scanned. Okay? So that's the first step. Then because that was growing, we need to go to manage the result of those cards. What is more important? Should I arrest everyone? No. Perhaps that guy has a gun. That guy has just some little metal of whatever. It's different, you know. So then we need to orchestrate the priorities, and we do that by risk. And we call that risk-based vulnerability management, RBVM, another API. Okay? And then to do another analogy, or you do screenshots, photographs, once every whatever, once every week. But what's happening in between? So you have to do that continuously, like a movie. And that's the difference between looking after the vulnerability once per month, or once per quarter, looking after the vulnerability all the time, continuously. And then the attack surface has also evolved. We're not having only network and devices into a physical network back in 1999. Okay. That was when I started. You know, we only had a plug to plug the network. Today we are using cloud, we're using a lot of technologies, and then those devices are virtual, they are hosted everywhere. And that is a challenge of that evolution of vulnerability management. And today that's why we talk about exposure management. What is your exposure? Am I exposed by such kind of attacks? Where are my devices? Some of them are still there, still using uh physical devices, but some of them are completely virtual. So we need to be able to manage everything. We need to be able to have that full view, and that is what we call today exposure management. Just an evolution of vulnerability management.

Robby Peralta

Of the incident response cases that we've dealt with over the past year that that used over 100 hours. So, like the bigger cases, most of the incidents were caused by vulnerabilities in security products and or vulnerabilities in internet-facing appliances and misconfigurations was one of them. What does those three things have to do with what you just said? Or is there a connection there? Because I feel like a scanner doesn't really like scan a security product, you know?

Bernard Montel

And that's why we know the industry has evolved from vulnerability management to exposure management. You know, exposure management is really to be able to have that global view where vulnerability management is only looking at scanning and standing at just a list of stuff to patch, okay? Try to simplify or oversimplify. But that's the reality. Now you mentioned three elements. We call that a toxic combination. Okay. When you have that capacity to view everything from an exposure standpoint, you know exactly your attack surface, then you can detect misconfiguration and vulnerability and potentially some service which is exposed together. Okay. Now that is a combination which is in fact aligning a potential attack pass for an attacker. Okay. If you only manage just a list of scan results in one hand, if you only manage, for example, misconfigurations on the other hand by another team, and if you manage, for example, the identity and the and the access for the cloud, for example, by another team, you won't be able to have that. You won't be able to link those three exposures together. Okay. And they are linked. If you have a service which is exposed in the cloud, you have a vulnerability attached to that service because any kind of service, even if they are hosted into a cloud provider, need to be updated, need to be upgraded, need to be patched. So you don't do that. And in the meantime, someone has deployed that service with by default identity and access, which means that you have been granted with an admin access. For you, you'd be super happy with that. But for the attackers as well. Okay. Now, if we combine and can have those three elements into one place, that toxic combination is attached today to a practice called exposure management. We're not talking about vulnerability management only. We're talking about those three exposures together. We call that, we we even call that toxic cloud trilogy, which is the three, but it could be four, it could be five, you know, it could be even more. But that is definitely something we're looking after today, based on the fact that uh the attack surface has become much more complex.

Robby Peralta

So I understand why it's so complex for a company to deal with this, because there's just so many things that uh they have to deal with in different teams managing it, right? Like, and I feel like that toxic combination, is that supposed to bubble up in the SOC before it's actually a thing? Like, how are we supposed to operationalize these things to Yeah?

Bernard Montel

That's a very, very interesting question. SOC has been designed for detecting incident, okay? So they are there for finding if you are under attack or you've been under attack. They are in the second category that I described at the beginning: prevention, detection, respond, they are in the detection part. They're looking after signals of people already in your network. So ideally, they would love to have that toxic combination popping up in advance, not after. Okay. So the SOC is now evolving to consume exposure management services based on technologies and platforms to be getting that as much as they can proactively. Okay. And that is what happened today for very mature security operations center, a very mature organization, that they really want to be proactive and not only running after an alert. Okay. That's sometimes a little bit too late. Makes sense? That's interesting.

Robby Peralta

Yeah, of course. And uh it's interesting to hear your perspective on it, because I work for like a SOC company, right? So what do you think the SOC's job is then these days? If you should be doing because if you're doing the prevention part right, the SOC won't have that much to deal with, right?

Bernard Montel

Definitely. So our goal at Tenable is to help the SOC reducing the attack surface, reducing that complexity you just mentioned before. Everything is growing. We have more and more assets, more and more data, and it's hosted partially on-prem, partially in a cloud. And that is representing a huge complexity. When we move to the cloud, when organizations move to the cloud, they thought it was simpler. No, no. Finally, it's more complex. That is quite complex for the SOC. So the SOC has more and more challenges to be able to detect all of those elements everywhere they are. Think about serverless, think about identities which are created in the fly, think about celebrities identity, think about all of those complexity that has been introduced for simplicity for the business. But for the SOC, it would a nightmare, you know, it's growing all the time. Our job is to help them to reduce the reduce the attack surface. That doesn't mean that we will reduce the infrastructure. The infrastructure is growing and having more and more complexity. But if we can help reducing the scope for the SOC, then they would be in a better position. Because then we can ensure that those doors and windows have been closed, we close the misconfiguration, we close the vulnerabilities, only the ones which are very risky and very important, not all of them, is impossible. You know, it's like if I have someone that I hired for checking in my building before I'm leaving the 30 floors, one by one, check one by it's impossible. Okay, so we have to only close those doors which are giving access to the very important business critical applications. And if you do that for the SOC, the SOC would be super happy that we detect for them attack path. Now, obviously, you have those people trying to test the pen testers and the simulation tools. They are in between. You know, they are trying to help validating what we highlighted. Hey, we found some doors open. Send someone to try to find out if you can go in. Yeah, you can or he cannot. Okay. Now the SOC needs to get that information from us. A list of attack paths, which is now validated, currently open, because potentially someone has already exploited it. And that is exactly what they need to define and detect.

Robby Peralta

And Tenable's always been a cornerstone of this area, right? So is is what you're saying, is your product now gone from going from like scanning clients and servers to scanning cloud infrastructure and running attack path uh analysis? Like, is that all going on before it reaches anybody these days?

Bernard Montel

So that's exactly the goal. I mean, again, the CTEM framework you mentioned is very clear on that. It's a process. There are people, there are also technologies covering those parallels. We just discussed about we at Tenable want to be able to help our the organizations, our partners and our customers to have that holistic capacity and view. Okay. Now, clearly, this the entire industry, the analysts, whatever they are, Gartner, IDC, and some others, Forrester, are saying that exposure management, it's an evolution of vulnerability management. It's not rocket science, you know, it's not like a revolution. It's an evolution. We started to find only vulnerabilities at that square, you know, based on networked devices. And because the infrastructure has evolved, we evolved as well. We have now capacity to find misconfiguration and vulnerabilities in OT systems, in IT scanners, on cloud systems, any kind of multi-cloud infrastructure as a service, and also identities, because you know, at the end of the day, the identity is the last control to giving you access to a specific application or specific services or device. By bringing those four elements, you know, IT, OT, identity, and cloud, we are covering 99% of the attack surface. By having that view and capacity, we can then correlate those information into one place and make the link between. The fact that this asset can communicate with hundreds machines. If this one is compromised, we have a compromise of hundreds. Those are the key elements we are offering to understand the exposure. And that is exposure management. That is the evolution of vulnerability management into a broader way, into this full attack surface that we want to be able to handle.

Robby Peralta

The story itself sounds lovely, right? But usually when I'm talking with the client about like this area that we're speaking of, they have they just get this list of like billions of things they have to fix and they have to sort, yet they use Excel. They have to do a lot of work just to figure out what they're supposed to patch and why not. So your goal is that they enable the analytics layer to help them make these decisions, or like what are people missing?

Bernard Montel

A very good point. I mean, we only have one goal. Obviously finding those exposures, but helping our customers to take the right decision at the right time, which is prioritization. Okay. And that is a more challenging part. And you're right on the fact that most of them, where they've been into the classical vulnerability management approach, they still have that super long list to patch. And if they are driven only by a compliance approach, this is just something they have today, every day, they have to patch and patch and patch and everything and because if it is only compliance driven. Now, we're talking about security here. Compliance is one part. We're talking about security. Security should be risk-based. Prioritization should be risk-based. How do we take decisions? Number one, uh from the risk of the technology itself. You know, if that is super risky, highly exploited, easy to exploit, remember log for share, okay? A big bang because it was so easy to exploit, that has been discovered by gamers, you know. They were doing Minecraft and they found you know vulnerability that can be super easy to exploit. So that is one part, the technology. But the seventh part is obviously the business risk. What is the impact? If that block shell was attached to a dummy data lab, we don't care about it right now. We have to prioritize on what is super important from a business standpoint, what is the impact of the business. Exposure management is that, you know, it's not just having aggregating data. Aggregating data is just a needed layer for doing it. But that's not the purpose itself, you know. The use case of aggregating data is super important. We need to have as much data as possible. But what is important is a context. If we don't have the context, this data, this device compared to this one, what is the more important one to fix and patch first? If we don't know, we have to feature both of them. If we know that's super important from the risk standpoint, from a business risk, from an IT risk, and for cyber risk altogether, then we can help our customers to take decisions.

Robby Peralta

Does that mean if you're because if you're always just focusing on what's important here now, which of course you cannot argue with what you just said, right? Risk-based approach using the technology, whatnot, doesn't that does that mean that we're always going to be in a situation where we just have, I don't know, 75% of the infrastructure that needs to be patched? Like always? Like is that just like the new norm these days?

Bernard Montel

Only 3% of the vulnerabilities are exploited. The challenge is to find those 3%. Okay. Not all of the vulnerabilities are exploited. And depends on the studies between 3 and 5% or 8%. It depends. Okay. But globally, we have a few amounts of vulnerabilities which are exploited. And most of the attacks are using known vulnerabilities which are there for months and even years. And sometimes we see some ransomware groups targeting a group of organizations using a vulnerability where the patch exists for two years. So that is exactly what we need to do. So that's why I say to you, yes, sometimes you know, we leave those devices unpatched, but they do not represent a risk for the company. That doesn't mean that we don't we don't have to patch them at all. Okay, but we from a from a priority standpoint is what should I do now? And that's the answer we need to be good to give.

Robby Peralta

The 3% that actually do get uh exploited, right? It just reminds me of C VSS score or CVS score, whatever. Uh isn't it part of that score supposed to be like the possibility there or the chances actually get exploited? What's so hard about using that?

Bernard Montel

So the CVSS score is a technical part of a vulnerability. How much that's technically speaking, that represents a risk. Is it easy to exploit, but it doesn't represent the rest of a risk? We at Tenable have developed a data science-based algorithm called VPR, vulnerability prioritization rating, which is based on that specific vulnerability, we create a score using a hundred vectors where we will combine exactly what you said. What about if that specific vulnerability, technically speaking, very risky? C VSS score eight, nine, ten, no one has exploited it before. Okay, you can argue could be that I'd be the first organization. Uh that is possible, okay, but globally, if that's never been exploited by a huge amount of attackers, there are very, very, very few chances that that exploit will come and start. And if there is a case, we will also change the VPR score. We'll update it. Oh, we've seen some exploit. The score is increasing. Okay. The threat intelligence plus the C VSS score plus many other vectors we are using to balance the vulnerability itself. Is that vulnerability attached to a critical asset? Because we also are tagging assets to know if they are or not critical for your infrastructure. This is something we don't know. You know. We can tag the asset because we see that that asset is using a public IP address, meaning that this asset is exposed. One of the three elements of the cloud toxic three login. We know that. This is exposed asset. The risk is higher. Obviously, it's higher when it is exposed and it is not exposed. Makes sense. But that is the VPR element. CVSS score is a fixed technical risk of a specific vulnerability.

Robby Peralta

Am I right to assume that actually to operate operationalize this in an effective manner, that you don't really need the SOC? It should be, it could be somebody that's working in like a cloud, I don't know, an architect or like who would be the ideal receiver of tenable.

Bernard Montel

The ideal receiver would be an organization which is mature enough uh to do not only doing vulnerability assessment or even vulnerability management, having that comprehensive capacity to um is mature enough to understand that they need that to be collected together and then running a capacity to um detect exposure in advance before the SOC is involved, even. Okay. So we we're seeing more and more um vulnerability operations center, VOC. I don't like this VOC terminology, to be honest with you, because VOC is attached to vulnerabilities. So it looks like it's narrowed to the first element that I just described, which is just a CVE. Um more and more some some services are running, moving from VOC to EMS, exposure management services. And they are running proactively, as I said, you know, this preventive approach. And they could be attached to the same organization than the SOC. Hey, you have two tips. You know, one is try to find the doors open, the other one is try to find if there is someone uh, you know, already in and having some compromise systems. You know, the SOC is already established. But also from an analogous perspective, the SOC has evolved in the past 15 years, you know. The SOC started with sim collating logs and collitting logs only from network and security devices. And then we started to collect the logs from operating systems, applications, and cloud. And then the logs were not enough. We needed endpoint, then came out EDR, okay, and then orchestration, and then SecOps on top of it, and information risk management, and that is a mature SOC. If you look at what we do here as exposure management, this is exactly the same evolution. We started with VM or VA, vulnerability assessment, was not enough. You need to have a risk-based approach. We need to have you know more and more sources, you know, identity, OT, and cloud. And now we need to have orchestration, the capacity to see everything, and to have workflows attached to it as well. So that is exactly the evolution of exposure management compared to SOC. They could merge, and I think into one big umbrella of SecOps, for example, um, and then having two teams. Um, but it could be as well two different kinds of uh teams, uh, like the one coming from VM, the other one coming from the detection part, and they can work together.

Robby Peralta

It reminds me of a term that I heard from another guest that was uh he called it risk hunting. You're like going around looking for risk.

Bernard Montel

Attack path analysis is definitely a super tool for hunters because we highlight those attack paths. I don't think that will be it could be good also for the people managing the fact that they need to close and patch and change the configuration to reduce that the risk. That's for sure. So there is in one hand the classical buddies we are used to work with, which is again the people managing vulnerabilities or managing identities and misconfiguration. They have to close those paths, that's for sure. But before closing them, it could be good to make some hunting. So I would call my buddies in and and my guys within the incident response team. Send me one or two engineers. I want to know if that attack pass has already been exploited without any alert, because sometimes it could be that it's been exploited with low signal kind of behavior and activities.

Robby Peralta

And it'd be really cool if you could just chat with your uh tenable LLM and be like, hey, how could I detect this? Or what should my what should my friends look for for this attack pass in the page? By the way, that's what we do.

Bernard Montel

I mean, uh when when we have three or four uh implementation of the LLM. So one is really explaining the attack pass. Yeah. This is uh a machine which is exposed and then you know, which is based on Windows, blah, blah, blah, blah, blah, and that everything is explained. And we then can click on a button saying, what do you recommend? And then the AI will create a set of tasks to be recommended to reduce the attack pass. And that set of tasks can just send to an incident response team, say, Hey, do you have any rec correlation rules there in your SOC? Have you already implemented the detection capacity of that kind of path or not? And that could be one way to also improve the SOC. On the other way is definitely, hey, can you just find um try to try to do some hunting on your uh SOC database and then find whatever signal on the events? We don't have any event at Tenable. We are not looking after collecting any uh kind of information from an event standpoint, meaning uh whether SOC is doing or as a SIEM is doing.

Robby Peralta

Yeah, interesting. It makes me uh very comfortable knowing that we're partners of Tenable hearing this. It sounds like you have a good strategy. Uh but I looked at the market and there's just so many other players in this space. And like, yeah, you have like Rapid Seven and people that have always been there, but there's also like a bunch of like small startups that are doing sort of like really smart internet scanning. I'm thinking of like uh Grey Noise, for example.

Bernard Montel

Like uh they're not are they competing with you or like where do those um it's you know there are certainly some great startups out there, and I've certainly having some stuff potentially we don't have, okay, but at the end of the day, it's not having hundreds of startups you you buy the tools from, and then you have a huge challenge to use them. And most of the time you're using 20 or 30 percent of the tools itself. Now they're looking after a partner, they're looking after someone they can rely on, they can cover as much as we can. I'm sure that there are potentially some stuff we do not cover, okay, but we want to be able to do it. We have the capacity to collect the data, create the data, store the data, and be the partner, having the capacity to give as much information as possible. So, back to your question. Certainly there would be some nice, shiny startup doing some stuff. What is important today is what the customer wants. The customer wants to have someone that can help them in their journey, meaning that from VM to exposure management, and they have some steps. Not all of them are on the same steps, they have different maturity level. That's why what we are today.

Robby Peralta

Great answer. I'm buying it. But last question for you today. Uh, what do you think the future of this vulnerability or space? Like, where do you say going?

Bernard Montel

So that's a very good question. Who knows the future? Uh, but we have some some ideas. Um the thing is, um, people are using cloud and they are using more and more AI information. Okay, so the data which is stored in the cloud is uh consumed by LLM engines or by a Gen AI engine, you know, uh trained by the company or the organization itself, their own LLM engine, or by public engine that finally you left the door open and then you're consuming your data. Okay? So you need to be able to have that visibility, including the AI systems, running into an organization. Uh we've we've done a study that um on nine million of assets, we found one million having AI tubes running. Okay, which is huge. And even myself, when I've seen that study internally, I was challenging the people, you know, say one million is huge. You say yes. Look, you upgrade a specific system, and visual conference system, and now they have a companion, AI-based. You are using uh whatever uh system you're using for email, AI, and so on and so on and so on. So we have AI everywhere. We also have AI packages used by developers. We have, you know, your own LLM engine because you want to test it. You want to have your own LLM engine and everywhere and everywhere. And where are those stuff running most of the time? In the cloud. If you combine cloud and AI, this is clearly one of the trends. If I would be in CISO, I will go to some conferences, understand what's happened there, understand the threats, understand what's happened from a trend perspective, but also from a reality perspective. We've seen, and that was not the case a year before, attackers using AI. If they are starting, there is a group of ransomware that Checkpoint has discovered based in Algeria, and they were developing malware only by AI. So, how we've seen so how the researcher has seen it, because you know, when you do reverse engineering, you get the code. Uh, attackers are not using comments on a code. They don't put a comment, you know. When you are a developer, you put a comment because you want to give your code to another team, and then the team needs to understand the code you've done. Attackers, you know, never do that. They don't want that anyone else understand the code. But if you are using an LLM for generating your code, the LLM put comments. Okay? And then this group, ransomware groups, I don't remember the name. I think it's uh funk something, you can find it. Um we can smile about it, but at the end of the day, what what we need to learn is AI is used by attackers. Okay, so meaning that um, you know, we defender need to understand how AI is used within our systems and specifically the the AI, which is currently most of the time host in the cloud. Interesting.

Robby Peralta

And I know the developers for uh ransomware groups, those are actually the guys that they're the most important people for the ransomware organization. So I've been told, because there's not that many of them in a growing trees, but now they have an AI for that. So Mr. Montel, thank you so much. I'm gonna go buy some tenable stocks, and I will uh look forward to uh seeing seeing how you progress in this AI future of ours. Yeah, thank you very much. And again, I love your background and I want to play with them, but um more than welcome. I was very, very pleased to have that conversation with you. Uh very you know engaging conversation. As you can see, I'm very passionated by uh that domain as well. Not just the guitar, but also the sport management in the intelligible domain. Uh but um I hope we will see each other very soon in person. Um but I really appreciate it. Likewise, Mr Montel. Have a good one. Ciao.

Bernard Montel

Thanks. Bye.

Robby Peralta

Well, that's all for today, folks. Thank you for tuning in to the Mnemonic Security Podcast. If you have any concepts or ideas that you'd like us to discuss on future episodes, please feel free to hit me up on LinkedIn or to send us a mail to podcast at mnemonic.nl. Thank you for listening. We'll see you next time.