No Result
View All Result
  • Login
Monday, September 15, 2025
FeeOnlyNews.com
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading
No Result
View All Result
FeeOnlyNews.com
No Result
View All Result
Home Market Analysis

The Real Future Of Proactive Security Isn’t Finding Exposures — It’s Fixing Them

by FeeOnlyNews.com
1 month ago
in Market Analysis
Reading Time: 3 mins read
A A
0
The Real Future Of Proactive Security Isn’t Finding Exposures — It’s Fixing Them
Share on FacebookShare on TwitterShare on LInkedIn


When I joined Forrester in 2022 to cover vulnerability management, I was fortunate to have a front-row seat to the multiple changes happening in this market. These changes included:

Large SecOps and technology companies such as CrowdStrike and Microsoft entering the vulnerability management market to compete with incumbents like Qualys, Rapid7, and Tenable.
Vulnerability risk management solutions incorporating external attack surface discovery and attack path mapping to enhance vulnerability risk scores.
Attack surface management solutions emerging to provide more comprehensive visibility to round out vulnerability management strategies.
Adoption of continuous security testing solutions, such as breach and attack simulation and penetration testing as a service, remaining tepid and trending toward more mature enterprises, with siloed results not tying directly back into the vulnerability management program.
The introduction of the exposure management category in late 2022 with Tenable’s announcement of exposure management.

As I tried to make sense of these shifts, I saw that the future for these markets was ripe with opportunity. But instead of trying to jam all these changes into some new category, I found more utility in breaking them up into their specific applications and use cases. These use cases became core to what I now call modern proactive security programs.

Proactive security can be boiled down to three principles: visibility, prioritization, and remediation. These were the three principles 10 and 20 years ago as well as the principles of today, and they will always be the principles of future programs. So while other analyst firms watching these changes preferred to tie them to new categories, acronyms, and hype cycles (such as continuous threat exposure management, or CTEM), I thought it was much more helpful to address what is happening in the market and how these proactive principles of visibility, prioritization, and remediation can be applied to specific use cases.

And although CTEM, proactive security, and continuous security testing were everywhere at Black Hat last week, some newly created category could dominate the show floor next year.

The Quiet Crisis In Remediation

Only one of these three principles ruled the Black Hat show floor last week: prioritization, with dozens of vendors highlighting continuous security testing and exposure management and unicorns such as Wiz announcing their exposure management solution. While solutions like these are helpful for organizations looking to fine-tune their prioritization strategy, the terms “AI-infused,” “continuous,” “autonomous,” and “automation” have a massive, hushed implication: the potential for prioritization to further bog down the neglected proactive principle of remediation.

If we’re going to leverage AI to mature prioritization strategies in exposure management and continuous security testing, then it’s also necessary to leverage AI to help us remediate so that we can actually address these prioritizations. We also need to prepare for more widespread attack surfaces due to AI and the lower barrier of entry that it has.

If we’re ever going to truly be proactive, we must get faster at remediation. Agentic AI presents opportunities here but is not a silver bullet. We’re still several months, or years, away from full-blown remediation automation, but AI does present some opportunities to help augment the remediation response process by identifying optimal remediations that accumulate through exorbitant vulnerability findings, recommending more tactical response actions, and identifying appropriate remediation owners.

Proactive Security Will Live On

Visibility, prioritization, and remediation will always be the foundation of your proactive program, but orgs still struggle to optimize all three principles in an integrated fashion. Now is the time to prepare your security teams for the future of proactive security by:

Future-proofing budgeting cycles by renaming your vulnerability management budget to proactive security. Proactive security is not just your vulnerability management budget. It encompasses attack surface management, cloud-native application protection platform, and all the offensive security testing you do throughout the year. Rename your budget to align future products and services with what is needed for your visibility, prioritization, and remediation.
Planning for AI to finally make a difference in the most neglected principle: remediation. Security teams are good at finding problems. We’re better than we give ourselves credit for. And our prioritization strategies are much better today than they were three years ago. We’re not just using Common Vulnerability Scoring System anymore; we’re finding better ways to use vectors, threat intelligence, attack paths, and validation through testing. All of these improved prioritizations make no difference if we don’t fix the identified and validated exposures. This is why remediation was a core focus of our recently published Forrester Wave™ on unified vulnerability management.

Learn More At Security & Risk Summit

Want to learn more? I’ll be unpacking a lot more about proactive security during my keynote, “Proactive Security From Fantasy To Framework,” at Forrester’s upcoming Security & Risk Summit in November in Austin. We’ll dissect proactive myths vs. realities and dive deeper into the next frontier of proactive security: proactive response. Check out the full agenda, and hope to see you in Austin!



Source link

Tags: ExposuresFindingFixingfutureIsntProactiveRealSecurity
ShareTweetShare
Previous Post

Why Investing in Index Funds Is Good for Your Retirement

Next Post

Here’s What Drives Boomers, Gen X and Millennials at Work

Related Posts

Global Oil Field Chemicals Market Size, Trends, and Forecast

Global Oil Field Chemicals Market Size, Trends, and Forecast

by FeeOnlyNews.com
September 15, 2025
0

The oil field chemicals market plays a crucial role in the exploration, drilling, production, and refining processes in the oil...

Reintroducing A Classic: The S&R Executive Spotlight

Reintroducing A Classic: The S&R Executive Spotlight

by FeeOnlyNews.com
September 14, 2025
0

As the world moves forward, some things really should stay behind — like eighties shoulder pads, popcorn ceilings, and fondue...

School Is In Session And Attackers Are Grading Your Software Supply Chain Security

School Is In Session And Attackers Are Grading Your Software Supply Chain Security

by FeeOnlyNews.com
September 12, 2025
0

Software supply chain attacks continue to be a top external attack vector for attackers to breach enterprises, government agencies, and...

The Abyss Of The Salesloft-Salesforce Breach May Reach The Challenger Deep

The Abyss Of The Salesloft-Salesforce Breach May Reach The Challenger Deep

by FeeOnlyNews.com
September 12, 2025
0

News has been trickling out since August 20 about a security issue in Salesloft’s Drift product, a marketing and sales...

Rewind And Fast-Forward TV Advertising

Rewind And Fast-Forward TV Advertising

by FeeOnlyNews.com
September 12, 2025
0

TV’s stakeholders — consumers, advertisers, and publishers — are out of sync. Consumers love streaming TV but say they don’t...

Answer Engines Outpace Antitrust Law

Answer Engines Outpace Antitrust Law

by FeeOnlyNews.com
September 12, 2025
0

To remedy Google’s monopoly in search, Judge Amit Mehta ruled that Google merely has to share limited search data with...

Next Post
Here’s What Drives Boomers, Gen X and Millennials at Work

Here’s What Drives Boomers, Gen X and Millennials at Work

*HOT* Band-Aid Flexible Fabric Adhesive Bandages 200-Count only .31 shipped!

*HOT* Band-Aid Flexible Fabric Adhesive Bandages 200-Count only $10.31 shipped!

  • Trending
  • Comments
  • Latest
1 Stock to Buy, 1 Stock to Sell This Week: Walmart, Target

1 Stock to Buy, 1 Stock to Sell This Week: Walmart, Target

August 17, 2025
Of Property Rights, Civil Society, and Shampoo

Of Property Rights, Civil Society, and Shampoo

September 1, 2025
Engine Capital takes a stake in Avantor. Activist sees several ways to create value

Engine Capital takes a stake in Avantor. Activist sees several ways to create value

August 16, 2025
James Galbraith: Crash in Top Economist Hiring Contradicts Elite-Favoring “Skill Biased Technical Change” Theory

James Galbraith: Crash in Top Economist Hiring Contradicts Elite-Favoring “Skill Biased Technical Change” Theory

September 2, 2025
Vanguard reaches .5M SEC settlement

Vanguard reaches $19.5M SEC settlement

August 29, 2025
RBC wealth revenue rises despite recruiting costs

RBC wealth revenue rises despite recruiting costs

August 27, 2025
Elon Musk buys  billion worth of Tesla shares from open market

Elon Musk buys $1 billion worth of Tesla shares from open market

0
These are the tasks Indeed’s new CEO says HR leaders should hand over to AI agents

These are the tasks Indeed’s new CEO says HR leaders should hand over to AI agents

0
How Did America Build the Arsenal of Democracy? (with Brian Potter)

How Did America Build the Arsenal of Democracy? (with Brian Potter)

0
Strategy Adds 525 BTC as Michael Saylor Says Bitcoin Deserves ‘Credit’

Strategy Adds 525 BTC as Michael Saylor Says Bitcoin Deserves ‘Credit’

0
9 Budget Apps That Don’t Sell Your Data (According to Their Policies)

9 Budget Apps That Don’t Sell Your Data (According to Their Policies)

0
Hotstocks KW 37 / 2025: Fokus auf Zyklische Konsumgüter

Hotstocks KW 37 / 2025: Fokus auf Zyklische Konsumgüter

0
These are the tasks Indeed’s new CEO says HR leaders should hand over to AI agents

These are the tasks Indeed’s new CEO says HR leaders should hand over to AI agents

September 15, 2025
Strategy Adds 525 BTC as Michael Saylor Says Bitcoin Deserves ‘Credit’

Strategy Adds 525 BTC as Michael Saylor Says Bitcoin Deserves ‘Credit’

September 15, 2025
Three top execs leave digital bank One Zero

Three top execs leave digital bank One Zero

September 15, 2025
Elon Musk buys  billion worth of Tesla shares from open market

Elon Musk buys $1 billion worth of Tesla shares from open market

September 15, 2025
Hotstocks KW 37 / 2025: Fokus auf Zyklische Konsumgüter

Hotstocks KW 37 / 2025: Fokus auf Zyklische Konsumgüter

September 15, 2025
I’m 35 and finally financially stable — but now my parents want to borrow K for a new roof. What do I do?

I’m 35 and finally financially stable — but now my parents want to borrow $10K for a new roof. What do I do?

September 15, 2025
FeeOnlyNews.com

Get the latest news and follow the coverage of Business & Financial News, Stock Market Updates, Analysis, and more from the trusted sources.

CATEGORIES

  • Business
  • Cryptocurrency
  • Economy
  • Financial Planning
  • Investing
  • Market Analysis
  • Markets
  • Money
  • Personal Finance
  • Startups
  • Stock Market
  • Trading

LATEST UPDATES

  • These are the tasks Indeed’s new CEO says HR leaders should hand over to AI agents
  • Strategy Adds 525 BTC as Michael Saylor Says Bitcoin Deserves ‘Credit’
  • Three top execs leave digital bank One Zero
  • Our Great Privacy Policy
  • Terms of Use, Legal Notices & Disclaimers
  • About Us
  • Contact Us

Copyright © 2022-2024 All Rights Reserved
See articles for original source and related links to external sites.

Welcome Back!

Sign In with Facebook
Sign In with Google
Sign In with Linked In
OR

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading

Copyright © 2022-2024 All Rights Reserved
See articles for original source and related links to external sites.