The evolution of vulnerability management

Issue 3 2022 Information Security

Almost every category of cyberattack increased over the course of 2021. The number of encrypted threats spiked by 167%, ransomware rose by 105%, and intrusion attempts climbed by 11%. Cyber economy research giant Cybersecurity Ventures expects global cybercrime costs to grow by 15% per year, reaching $10.5 trillion USD by 2025.


Patrick Evans.

Despite this, a PWC survey of security and technology executives last year showed that only 55% of cybercrime victims believed they were ‘well prepared’ to address these breaches — and 45% weren’t.

Proactive threat intelligence

In today’s world, ‘well prepared’ will never mean ‘invulnerable’. Faced with such a rapidly evolving threat landscape, it’s virtually impossible to address every risk. In fact, The Cyber Security Intelligence Agency reports that only 50% of organisations are remediating fewer than 15.5% of their vulnerabilities monthly, says Patrick Evans, CEO of specialist cybersecurity solutions provider SLVA Cybersecurity. “IT managers are suffering from vulnerability fatigue. They’re caught in an infinite loop of testing and patching, draining resources and accumulating costs, often getting attacked through a vulnerability they were unaware of. Organisations must start moving away from trying to fix all vulnerabilities to focus on those that matter.”

Gartner’s Top 10 Security Projects for 2020-2021 report recommends risk-based vulnerability management: “Don’t try to patch everything; focus on vulnerabilities that are actually exploitable. Go beyond a bulk assessment of threats and use threat intelligence, attacker activity, and internal asset criticality to understand real organisational risks better.”

The use of vulnerability scanners is no longer sufficient, often overwhelming security specialists with the volume of vulnerabilities to remediate. “Not all detected vulnerabilities require immediate action,” says Evans. “Context is important. It’s not uncommon for organisations that take security seriously to use tools like vulnerability management, vulnerability prioritisation, breach and attack simulation, and pen testing, providing multiple vulnerability ratings that remain siloed. To be truly effective, a single, more comprehensive risk console is needed.”

New landscape, new solutions

An effective, comprehensive strategy today leverages threat intelligence and threat actor landscape to assign a tailored risk score to identified vulnerabilities.

To bring such a solution to local shores, SLVA Cybersecurity recently became the distribution partner and reseller for HivePro in South Africa. “With HivePro, security teams get a view of all their current approaches and where the top 15 percent of vulnerabilities lie so that they can prioritise those threats. Importantly, this happens on a continuous and evolving basis,” says Evans.

HivePro’s Uni5 uses the current known vulnerabilities and threats to provide a unified view of the true vulnerability risk in an organisation. It is the only vulnerability prioritisation technology that contextualises risk by checking the efficacy of an organisation’s compensatory controls, providing actionable intelligence for rapid vulnerability remediation.

Users see a combination of asset criticality, external threat context, internal compensatory control, and patch intelligence to proactively reduce their attack surface before it gets exploited.

Uni5 uses four different groups for risk scoring: The first shows severe risks that could affect the organisation’s most critical assets and require immediate patching, the second group contains moderate threats to critical assets, the third shows high risks to non-critical assets and, lastly, moderate risks to non-critical assets.

Uni5 also orchestrates patch and configuration management to fix vulnerabilities, taking threat priorities into account. “These strategies are the way forward for organisations looking to take their threat intelligence to the next level. Perfection might not be possible in today’s ever-changing threat landscape, but proactive protection is,” says Evans.

As HivePro’s local distribution partner, SLVA Cybersecurity provides a zero-cost proof of value to clients, providing an immediate snapshot of the top 15% of vulnerabilities that will place the business at risk. MSSPs, service providers and resellers can also partner with SLVA Cybersecurity to provide this solution to their clients.

Find out more at https://slva-cs.com/




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Want effective Attack Surface Management? Think like an attacker.
Information Security
Effective ASM requires companies to think like attackers, anticipate risks, and act decisively to reduce exposure by knowing their environment, deploying a structured approach, leveraging capable tools, and addressing both internal and external risks.

Read more...
The growing role of hybrid backup
Infrastructure Information Security
As Africa’s digital economy rapidly grows, businesses across the continent are facing the challenge of securing data in an environment characterised by evolving cyberthreats, unreliable connectivity and diverse regulatory frameworks.

Read more...
POPIA non-compliance puts municipalities at risk
Information Security Government and Parastatal (Industry)
Digital responsibility must go beyond POPIA compliance to recognising that privacy and service delivery are fundamentally linked. Despite this, only 51 out of 257 municipalities submitted their mandatory data protection and access to information reports in 2024.

Read more...
Choicejacking bypasses smartphone charging security
News & Events Information Security
Choicejacking is a new cyberthreat that bypasses smartphone charging security defences to confirm, without the victim’s input or consent, that the victim wishes to connect in data-transfer mode.

Read more...
Most wanted malware
News & Events Information Security
Check Point Software Technologies unveiled its Global Threat Index for June 2025, highlighting a surge in new and evolving threats. Eight African countries are among the most targeted as malware leaders AsyncRAT and FakeUpdates expand.

Read more...
Welcome to the new cyber battleground
Information Security
The Iran-Israel conflict is rapidly redefining modern warfare, pushing the boundaries of cyber capabilities and creating a new, borderless digital battlefield. Fortinet’s CISO, Dr Carl Windsor, offers a critical, in-depth analysis of the escalating tactics and global implications in his latest report.

Read more...
African industries may overestimate cyber defences
Information Security
] A significant perception gap exists in security awareness training: 68% of leaders believe training is tailored to roles, yet only a third of employees feel adequately trained. Many organisations only conduct annual or biannual generic training that may not effectively change behaviour.

Read more...
SMARTpod talks to Sophos and Phishield
SMART Security Solutions Technews Publishing Sophos Videos Information Security News & Events
SMARTpod recently spoke with Pieter Nel, Sales Director for SADC at Sophos, and Sarel Lamprecht, MD at Phishield, about ransomware and their new cyber insurance partnership.

Read more...
Cybersecurity and insurance partnership for sub-Saharan Africa
Sophos News & Events Information Security Security Services & Risk Management
Sophos and Phishield Announce first-of-its-kind cybersecurity and insurance partnership for sub-Saharan Africa. The SMARTpod podcast, discussing the deal and the state of ransomware in South Africa and globally, is now also available.

Read more...
Highest increase in global cyberattacks in two years
Information Security News & Events
Check Point Global Research released new data on Q2 2024 cyber-attack trends, noting a 30% global increase in Q2 2024, with Africa experiencing the highest average weekly per organisation.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.