Suddenly, I'm in vulnerability management

My greatest recent professional achievement is probably the fact that my manager now confidently sends me on rescue missions to clients who, for whatever reason, aren’t entirely happy with my company’s work anymore — believing that I can turn things around. Writing it down like that makes it sound a bit like a suicide mission leading straight to burnout, but it’s actually harmless. I’m good at dealing with people and communicating, and that’s what these missions are all about.

Interestingly, the latest of these stories has thrown me into an area of IT security that I previously had almost no contact with: vulnerability management. As a reminder, my mainstay is Log Management / SIEM. However, since I don’t work with the vulnerability scanner itself but rather with its results, I don’t need specific technical knowledge for this; I basically just have to communicate, once again. My input is a massive spreadsheet of open vulnerabilities spat out by the scanner; my output consists of emails and phone calls to those responsible for critical vulnerabilities.

My first lessons from this are as follows:

  • There is very little point in putting resources into designing a prioritisation process for new vulnerabilities as long as there are two-year-old open critical vulnerabilities in the network.
  • Running vulnerability management in a large organisation with regulatory requirements without comprehensive automation is futile and a waste of resources.
  • If you haven’t documented the vulnerability management process end-to-end, you can’t even begin with automation.
  • As with any process relevant to IT security: if an Excel spreadsheet plays a central role, there is a lack of suitable tools.
  • Without collecting and evaluating metrics, you don’t even know if the current process can keep up with new vulnerabilities at all.
  • I doubt whether it is actually relevant for the assessment of a vulnerability whether an exploit already exists for it.

The organisation where I’m deployed changed its vulnerability management shortly before I joined the project and drastically shortened the timeframes for applying patches. The reason for this is the scaremongering surrounding Anthropic’s “Mythos” model, which is allegedly able to find vulnerabilities and develop exploits for them at breakneck speed. The prospect of exploits becoming available faster has moved the organisation to shorten the patch cycle. Still — in my view, automating the vulnerability management processes is even more important for that. We’ll see if I can convince the client of that.