As cyber risk leaders are called to balance the responsibility of managing risk in the face of both broader attack surfaces and increased regulatory and budgetary scrutiny, prioritization of work is everything. Cybersecurity resources are finite, while the vulnerabilities and threats just keep growing. The best way for modern security programs to keep up is by directing resources to the risks that matter most to their specific organizations.
This is a fundamental truth of cybersecurity, one that has driven Bitsight’s effort to provide customers with insights that contextualize traditional security telemetry with business risk indicators. And it’s why Bitsight is investing in deeper cyber threat intelligence (CTI) with our recent acquisition of Cybersixgill. CTI isn’t just a tactical tool for day-to-day security operations—it can also provide crucial, contextual understanding about how adversaries target, exploit, and impact organizations and, as a result, can help refine risk management priorities.
Combine threat context from CTI with business context from your own attack surface, and I believe cybersecurity teams can level up their cyber risk prioritization practices in five crucial areas.
1. Vulnerability management
Vulnerability management has been a notorious source of cybersecurity noise and information overload for decades. CISOs need a better way for their teams to prioritize which vulnerabilities to fix first than simple CVE ratings, which only offer clues as to how severe the flaw itself is, without taking into account how the underlying software is being used. One of the first steps of prioritizing vulnerability response is contextualizing which assets are involved and what those assets mean to the business. The highest value assets to critical business functions clearly deserve the swiftest mitigation.
But even with vulnerabilities whittled down in that fashion, how many of those are actually likely to be targeted by threat actors? According to Gartner, only about 6% of all known vulnerabilities will be exploited—but which 6% will that be? CTI can offer crucial data to focus on the likeliest flaws.
CTI refines the view of risk by adding contextual data about the tactics, techniques, and procedures (TTPs) observed by threats in the wild. This information can drive important context about the likelihood that a vulnerability will be exploited based on how it exists within specific software, assets, and business types. This is a particular specialty of Cybersixgill, which over the past several years has developed a proprietary Dynamic Vulnerability Exploit (DVE) that helps prioritize vulnerabilities based on risk context and likelihood of exploitation. This is a game-changer for risk leaders who want to focus on the flaws that pose the greatest risk specific to their infrastructure and their business.
2. Attack surface management
Vulnerability management is actually a subset of a broader challenge: understanding and securing the full attack surface. Attack surface management (ASM) helps organizations identify all assets, both known and unknown, and assess every potential vector attackers could exploit. This includes not just software vulnerabilities, but also misconfigurations, exposed credentials, geographic risk, and other forms of digital exposure.
The combination of Cybersixgill and Bitsight addresses this challenge head-on. Together, they not only map an organization’s internal asset landscape and its business context but also provide visibility into how those assets appear to external threat actors. This dual perspective, inside-out and outside-in, is critical to understanding which exposures matter.
CTI adds vital context by highlighting which exposures are actively being discussed, targeted, or monetized in criminal forums, such as the dark web. That intelligence gives security teams a powerful early warning system and enables faster, more informed action. Even better, this threat data can be seamlessly integrated into existing security stacks, making it actionable across the organization, from the SOC to the C-suite.