Qualys unveils VMDR 2.0 with TruRisk™ scores

News Desk -

Share

Qualys, Inc., a pioneer and provider of disruptive cloud-based IT, security, and compliance solutions has announced the release of Qualys Vulnerability Management, Detection, and Response (VMDR) 2.0.

The new cloud-based solution provides unprecedented insights into an organization’s unique risk posture, as well as the ability to orchestrate responses using drag-and-drop workflows.

The doubling of disclosed vulnerabilities in the last five years, the rapid weaponization of vulnerabilities, and the cyber talent shortage have left teams struggling to wade through a mountain of vulnerabilities with no way to fix them all. To cut through the noise and prioritize fixing the most critical vulnerabilities that will reduce risk in their environment, security and IT teams require a new systematic approach.

Qualys VMDR 2.0 provides insight into security and IT teams’ need to focus on vulnerabilities that truly reduce risk. Across a sample size of 2.6 million assets and 74 million detections, Qualys beta customers with the TruRisk capability enabled prioritized 28% critical vulnerabilities. Simultaneously, they were able to reduce risk by an average of 23%, and in some cases by up to 50%.

Cyber risk is becoming part of the business risk equation. Even the most advanced organizations can’t patch all the threats they uncover, which increasingly includes poorly misconfigured services,” said Michelle Abraham, research director at IDC. “Organizations must prioritize efforts that result in the maximum reduction of risk. Qualys’s approach to cyber risk management considers multiple factors like vulnerabilities and misconfigured systems, so organizations can focus on fixes that reduce their overall risk.”

Ins 1 - Qualys - VMDR 2.0 - TruRisk - Techxmedia

Qualys VMDR with TruRisk enables risk-based vulnerability management, providing unprecedented insights into an organization’s unique risk posture and allowing it to prioritize its most critical vulnerabilities across hybrid environments. By providing shared context and the ability to create drag-and-drop workflows to automate time-consuming vulnerability management operational processes such as vulnerability assessment of ephemeral cloud assets, alerting, and prioritization, the solution assists security and IT teams in increasing efficiency and saving time.

“In this era of increasing attacks and board-level attention on cyber resiliency, efficiently managing cyber risk is more important than ever,” said Sumedh Thakar, president and CEO of Qualys. “With VMDR 1.0, we innovated by bringing the four core elements of vulnerability management into a seamless workflow to help organizations efficiently respond to threats. We’re changing the game again with VMDR 2.0 allowing organizations to kickoff remediation workflows for vulnerability management tasks, prioritize remediation on the critical issues that reduce risk, and streamline responses and integrations with ITSM solutions like ServiceNow.” 

Qualys VMDR with TruRisk allows Security and IT teams to:  

Reduce Risk with Holistic Scoring – Quantify risk across the entire attack surface including vulnerabilities, misconfigurations and digital certificates, correlate with business criticality and exploit intelligence from hundreds of sources, including Shodan’s attack surface exposure data. Qualys VMDR with TruRisk automatically de-prioritizes vulnerabilities if compensating controls are in force, tracks risk reduction trends over time, and helps organizations measure and report on the effectiveness of their cybersecurity program across hybrid environments.

Quickly Remediate at Scale – Leverage rule-based integrations between VMDR and ITSM tools such as ServiceNow and JIRA, along with dynamic vulnerability tagging, to automatically assign remediation tickets to prioritized vulnerabilities and bridge the gap between security and IT teams. Orchestrate remediation directly from the ITSM tool to help close vulnerabilities faster and reduce the mean time to remediation. 

Receive Preemptive Attack Alerts – External threat intelligence, from more than 180,000 vulnerabilities and 25 plus threat and exploit intelligence sources, is natively correlated with vulnerabilities and misconfigurations to proactively alert teams on vulnerabilities exploited by malware or those used in an active malicious campaign known to target your industry. 

Automate Operational Workflows – Teams save valuable time and resources with Qualys Qflow technology. They can develop drag and drop visual workflows to automate time-consuming and complex vulnerability management tasks, such as vulnerability assessments for ephemeral cloud assets, alerting for high-profile threats or quarantining high-risk assets.


Leave a reply