Digital transformation initiatives and the adoption of cloud, mobile, and remote work models have eviscerated the traditional security perimeter. Enterprise assets are distributed across the cloud, endpoints, mobile, and personally owned devices and expanded the attack surface in the process. Organizations are increasingly vulnerable to attack via unknown and unmanaged Internet-facing assets.
These factors are driving the need for organizations to bolster visibility of all of the assets in their digital ecosystem. CISOs are increasingly calling for their teams to not just continually monitor externally observable cyber risks such as misconfigurations, vulnerabilities, unpatched systems, open ports, and third-party exposures through which threat actors can launch attacks. They're also seeking ways to contextualize these voluminous exposures with other quantifiable risk factors like geographical risk, business criticality of systems observed, and physical safety risks from OT/ICS systems.
Fundamentally, the push toward this kind of visibility through exposure management is all about prioritizing risk management activities. But the real-time views also provide a valuable governance measuring stick. When leveraged well, exposure management can also become a boon for security benchmarking—both internally and against industry peers.
Benchmarking Basics
With cybercriminals constantly scanning for and exploiting publicly exposed systems and misconfigurations it has become imperative for infosec teams to have the same visibility over their external facing IT estate that attackers have. Without understanding the extent of external exposure organizations, it is no longer possible for organizations to accurately quantify and manage cyber risks.
Such quantification also gives infosec teams a way to measure security posture improvements over time and to identify gaps and areas for improvement. It allows security decision makers to compare their organization's security posture against industry peers and provide empirical evidence of the need for investments in areas where they might be lagging behind others.
Peer benchmarking is one way to demonstrate due diligence to standard security practices especially for organizations covered by industry regulations such as the PCI data security standard. Cyber insurers too often use benchmarking for making policy pricing decisions and risk evaluations.
Cyber exposure visibility and management are essential for organizations to understand and proactively manage their cyber risks, says Mike Eisenberg, vice president of strategy, privacy and risk at Coalfire. It provides a real-time view of vulnerabilities and threats, thereby allowing organizations to proactively prioritize risks and enhance resilience.
"While traditional asset visibility focuses on asset identification, exposure management delves deeper into the potential impact of threats," Eisenberg says. "Comparing an organization's security posture with industry peers, even when benchmark data is challenging to obtain, provides valuable insights."
Benchmarking gives a CISO a way to strategically present to executive leadership and the board the organization's cybersecurity position and areas for further growth.