ThreatIntelligence-IncidentResponse

Building an exposure management program the business trusts


Discover how Tenable’s shift to an AI-driven exposure management program helped Tenable’s CSO, Robert Huber, overcome tool sprawl, unify data silos, mitigate the risk of rapid AI adoption, and shift from presenting granular, technical metrics to communicating business risk that the C-suite and the board can understand.

Key takeaways

  1. Security tool sprawl and data silos make it difficult for CISOs to holistically and accurately assess their organizations’ cyber risk.
  2. An exposure management program consolidates fragmented security data into a single unified view of cyber risk across the entire attack surface. 
  3. Aided by exposure management, CISOs can align security metrics with business priorities and quantify risk for key revenue-generating business units, answering the board’s main question: “Are we secure?”

What is trust in cybersecurity? And more importantly, how do you earn it? Here’s a hint: It’s not easy, especially in this AI era. 

As the Chief Security Officer at Tenable, my mandate is to ensure our organization operates securely, but with the speed required to succeed in a very competitive business environment. In recent years, achieving this delicate balance — an agile yet cyber secure business — had become progressively more difficult, as we grappled with increasingly fragmented data, siloed teams, and security tool sprawl.

In this blog, I’ll explain how exposure management helped my team: 

  • Tackle security tool sprawl
  • Bridge operational and data silos 
  • Take a more proactive approach to security
  • Attain visibility and control over Tenable’s attack surface
  • Continuously and precisely assess our cyber risk posture

The operational impact of security data silos and tool sprawl 

For years, the cybersecurity industry’s answer to every new threat or policy mandate was simple: Buy another tool, which in many — maybe most — organizations resulted in a bad case of tool sprawl. A typical large enterprise might juggle 70 or more security technology vendors, each promising to solve a specific problem. At Tenable, my team manages around 50 different security tools.

We found ourselves in a situation where siloed teams were running siloed tools, with separate views, prioritization criteria, key performance indicators, remediation workflows, and reporting. 

To illustrate this internally, I used to present a visualization of our architecture that I called the “spaghetti chart.” It was a tangled web of inputs from endpoint detection and response (EDR) vendors, bug bounty programs, vulnerability scans, security operation center (SOC) findings, penetration tests, and more. Each tool demanded its own unique workflow. As you can see, the spaghetti chart presented a picture of chaos. It reminded me of Gen. Stanley McChrystal’s quip regarding a spaghetti chart he was presented with during the war in Afghanistan: “When we understand that slide, we’ll have won the war.” Similarly, we could have said: “When we understand that chart, we’ll have eradicated cyber risk.”
 

The consequences of this fragmented approach to security became glaringly apparent during my board presentations. At one board meeting, I arrived with a deck consisting of 45 slides. An exhausting 30 of those slides were packed with metrics, KPIs, and raw data.

My team worked incredibly hard to pull that information together to build a narrative. Yet, I faced a hard truth: many of the business leaders and board members did not understand those metrics. When you present purely operational metrics, like the raw number of vulnerabilities or the number of scanned assets, you lose the C-suite’s attention. Those numbers don’t translate to business impact.

The board’s two core questions about cybersecurity

At the executive leadership and board level, I generally get asked two simple questions.

First: “Are we secure?” I may also get asked a variation, such as: “What’s our exposure?” From my 30 metric-heavy slides, generated from 50-plus tools with their own disparate reporting functions, I had to somehow boil the ocean of data and make a judgment call as to how secure we actually were.

The second question I get asked is: “How do we compare to peers?” As a publicly traded cybersecurity company, we have a strict fiduciary responsibility. The board wants to ensure we are maintaining a reasonable cybersecurity standard of care. Are we doing the things we’re supposed to be doing, that are expected of us by our shareholders, customers, and partners?

My job is to take those 50-plus tools, aggregate all the KPIs, and turn them into a meaningful assessment of Tenable’s cyber exposure that leadership can easily understand. We have multiple lines of business aligned by different products, regions, and services. True cyber risk management means being able to answer questions like: What is the associated revenue tied to each individual line of business, what level of cyber risk does each one face, and how can this risk be most effectively mitigated?

Without business context, you simply cannot prioritize effectively.
 

Tenable One dashboard showing line-of-business cyber risk levels

Tenable One dashboard showing line-of-business cyber risk levels at a hypothetical enterprise 

How siloed security tools create business friction

Unfortunately, the siloed nature of our security architecture created friction not just at the top, but across the entire business. When my team reached out to engineering and IT leaders, we frequently handed them numerous fragmented reports and manual spreadsheets for each security domain, including cloud security, vulnerability management, app security, pen testing, compliance auditing, and more. 

The problem arose when these engineering leaders, who have critical day jobs building and maintaining our products, looked at me and asked: “Bob, what the heck do you want me to do? What do I start with? How do I prioritize that?”

Coordinating reporting, mitigations, and remediations became a massive challenge. It didn’t scale well for my security teams, and it certainly didn’t scale for the receiving engineering teams, whom we hit up every week for their time. 

How AI complicates cyber risk management

And then, our friend AI moved the goalposts again. Every day feels like Groundhog Day: You wake up, and the newest AI capability drops out of the sky. As we ramped our AI adoption internally, our attack surface continued to expand. We knew we needed to manage AI security risks alongside traditional cyber risks. We also knew we needed visibility and context to make informed decisions about which AI security risks we were going to accept so that we could continue to move at the speed of trust. But I knew our old, siloed approach was untenable at the speed we needed to operate.

The turning point: An acquisition and exposure management

To truly unify our risk posture, we fundamentally changed our organizational structure. We evolved our vulnerability management team into an exposure management team. We unified all our security areas into a single foundational exposure management policy. Instead of just managing traditional CVEs, the exposure management policy needed to encompass a wider range of security issues, including misconfigurations and identity weaknesses, across the massive, modern attack surface: identity systems, cloud workloads, AI tools, on-prem assets, the application development pipeline, and more.

Broadening the mandate of the vulnerability management team to encompass all forms of exposure represented a massive operational shift, but notably, it didn’t increase our headcount. Instead, by centralizing our data, other specialized teams, like cloud security and application security, got time back to focus on securely deploying infrastructure rather than chasing down colleagues for patch management. The exposure management team became the centralized “go-get-’em” team across the board. They don’t operate all 50 tools, but they are the ones who triage everything.

I then tasked my exposure management team with solving the fragmentation problem. We wrestled with the issue of “build vs. buy.” Should we dump all of the data from all of our different tools into a giant data store, and try to add analysis, workflow and reporting to that, or should we look for alternative, out-of-the-box solutions that might already exist. 

In the end, we decided not to build it ourselves, largely because building and maintaining a data warehouse is not our core competency, and it can get very expensive, very quickly with infrastructure, data costs, and specialized staff. Instead, we evaluated a bunch of vendors that could help us centralize our risk data with existing SaaS solutions. We chose one specific solution that best fit our integration and workflow requirements. In the end, we ended up acquiring the entire company, Vulcan Cyber, for these same reasons. And today, it is a foundational part of our Tenable One Exposure Management Platform.

As a result of shifting to an exposure management approach and consolidating security data within a single platform, the “spaghetti” chart got transformed into this:
 

A chart illustrating the streamlined results of implementing exposure management and consolidating security data within a single platform.

Bob’s simple metrics

The manifestation of this journey within our own Tenable One platform is what my team lovingly calls, “Bob’s simple metrics.” We instituted a direct visualization using the traffic-light protocol: the colors red, yellow, and green to categorize the level of cyber exposure for each of our lines of business. Red signifies critical risk. Yellow means it needs attention. Green indicates a healthy security posture. We aggressively tagged assets to contextualize them, tying specific infrastructure directly to business units and revenue streams.

We also automated the identification of what I call the “big rocks.” For example, if we can’t patch an asset because of system instability, our platform flags this as a systemic root-cause issue rather than just blindly listing individual vulnerabilities. We now have customized service level agreements (SLAs) tailored by region and business impact, enabling teams to track their performance against these targets effortlessly.

Build business trust with exposure management

The aim of exposure management is to permanently change the conversation security leaders and their teams have with stakeholders. For instance, instead of overwhelming engineering teams with fragmented reports and drowning the board in 30 slides of operational metrics, we now provide a clear, data-driven workflow. We give the business a concise, prioritized list of actions that genuinely reduce risk.

Now is the time for exposure management. It is the only way to operate at machine speed. If you still have to manually schedule a patch window or pivot between 50 different dashboards to figure out your risk posture, you’ve already lost. Legacy vulnerability management is simply not going to work going forward. 

By breaking down security silos and unifying our risk data, we’ve built an exposure management program that the C-suite, the board, and the business can finally trust.

Learn more about the Tenable One Exposure Management Platform



Source link