Cisco closed its Kenna Security acquisition this week, and the networking and security giant will “immediately” begin integrating Kenna’s risk-based vulnerability management technology with its SecureX platform, according to Gee Rittenhouse, SVP and GM of Cisco’s Security Business Group.
This means Cisco security customers can expect to see new capabilities in their products by the end of the calendar year.
Rittenhouse and Karim Toubba, Kenna Security’s former CEO, sat down with SDxCentral to discuss how Kenna fits into Cisco’s larger security strategy, and why looking at customers’ infrastructure “through the lens of risk,” as Toubba calls it, to prioritize vulnerability management is important to security and IT teams alike.
Kenna Security’s Risk-Based Vulnerability ManagementKenna pioneered risk-based vulnerability management about 10 years ago with its platform that uses real-time threat and exploit intelligence to prioritize an organization’s vulnerabilities and help it better manage risk. This eases tensions between the two teams because it tells security professionals which threats are most likely to be exploited — and, as such, which ones the team should mitigate first — and it tells IT exactly what to patch and when.
This is important because companies’ security tools identify way more vulnerabilities than they can possibly mitigate, and the majority of these probably won’t emerge as real threats, Toubba said. “Our largest customer historically had leveraged technology to enumerate somewhere north of 200 million vulnerabilities and findings,” he said. “So it became very clear to us at the beginning that there was no way organizations were going to be able to fix all of those issues.”
In fact, only about 3% to 5% of an organizations’ vulnerabilities are actually susceptible to an attack, Toubba added. “The name of the game is precision,” he said.
Today, its platform protects more than 14 million assets and manages more than 12.7 billion vulnerabilities for customers including Royal Bank of Canada, HSBC, Quest Diagnostics, Mattel and Deloitte. Additionally, Kenna integrates with all major industry vulnerability assessment platforms.
Why Cisco Bought KennaCisco bought Kenna to advance its security strategy, which is to reduce security complexity in its customers’ environments, Rittenhouse added.
“We normally focus on more of the integration and automation components of simplifying security. But we recognize there are additional complexities in the environment as you start to gain visibility and add that visibility in real time,” he explained. “The amount of information that you receive around potential vulnerabilities and potential lines of attack is overwhelming, just like the number of threats, and alarms, and events on the automation side. We want to get ahead of that and help reduce the overall risk of the enterprise before these things happen.”
Cisco’s answer to this, of course, is its SecureX platform. It’s a cloud-native security platform that integrates Cisco’s network, endpoint, cloud, and application security products, as well as threat intelligence from Cisco Talos. The platform also connects to third-party security tools for investigations, and it provides extended detection and response (XDR) capabilities.
Integrating Kenna’s technology with SecureX will allow customers to create scorecards for security controls and threat response performance.
“If you are a SecureX customer, when we complete the integration, you'll have the benefit of understanding and pulling in vulnerability data into your real estate through SecureX, understanding the risk of those vulnerabilities, and then ultimately using that data to better help your security operations people respond,” Toubba said. “If you are a Kenna customer, you’ll continue to be able to use the platform, and then be able to upsell or add to it the SecureX platform. One of the many things that SecureX does that we don’t do is the ability to automate and orchestrate.”
Premium SecureX Likely Coming SoonA year after its debut, more than 7,000 businesses use SecureX, according to Cisco, and it is now included with every Cisco security product. However, in the lead up to this year’s RSA security conference, Cisco executives teased a “premium version” of SecureX in the future. This version will include additional security features, and several of those will likely come from Kenna Security.
“It does look like Kenna would be part of a premium offer, but there may be certain elements of Kenna that we include in the freemium version to provide that immediate customer value, particularly along the lines of simplicity, and then have many capabilities in the premium offer around orchestration, around risk prioritization, and around visibility” Rittenhouse said. “We’re still working through those particular details.”
Comments