|
|
|
|
|
by frantic2821
884 days ago
|
|
Is anyone dealing with a large volume of vulnerabilities and getting tired of vulnerability scanners giving mundane results and not explicitly saying what to fix for your environment? We are looking for beta users to try out our MVP; it's all based on open-source too, and we are offering the service for free! There are actual experts with over 20 years of experience who will look through the vulnerabilities and prioritize according to your environment at the end of our MVP to make sure the user doesn't waste more time investigating solutions and can go back to working on their product. Automating is nice, but you do need a human to look through at the end we feel apologies for hijacking your post OP but I am curious if people flocking to such a post would be interested in being beta users for us too |
|
It’s what happens after.
More scanners aren’t what we need because vendors still can’t meaningfully answer the most important questions:
- Is the vulnerability valid based on the environment it was found in? Solve this and you’ll reduce enterprise vulnerabilities by probably 30-40%.
- What are the compensating controls? Identify these automagically and reduce the vuln risk scores based on what controls are found, you will remove another 30% of vuln work for engineering teams
We don’t need any more scanners. We need better asset and vuln management.