Skip to main content
Page header background image

Other Events

2023 CISOExecnet Breakfast Roundtable – Visibility of Our Assets and the Attack Surface

CISO Executive Network


Date: December 12, 2023
Time:
8:00 a.m. - 12:00 p.m. ET
Location: Virtual
Contact:
Bill Sieglein, CISO Executive Network, bill@cisoexecnet.com


Traditional vulnerability management seems outdated yet we are still trying our best to get all critical vulns patched. Does attack surface management offer a better way for us to close the real gaps for our company? Is it all marketing hype or is there a real difference?

Come hear what your peers think about attack surface management and its connection to the vulnerability management program.

Can you articulate your attack surface? Are you managing the risk to your assets & attack surface sufficiently?

Security Controls Covered: CAASM, SIEM, MDR, Exposure Management, Breach & Attack Simulation, Vulnerability Management, Threat Management, Continuous Scanning, Patch Management, Pen testing, Red/Blue/Purple Teaming, Deception

Asset and Attack Surface Management generally takes into account the continuous discovery, inventory, classification, and monitoring of an organization’s IT assets. The attack surface is made up of all the points of access that an unauthorized person could use to enter the system. In this model the view of your resources is from the attacker’s perspective. In this series, we will look at how we can gain visibility into our assets and attack surface so we can put in place a better layered structure of defense and control. We will look at this model through a risk-management perspective.

Topics likely to be part of this discussion include:

  • Knowing your assets and attack surface
  • Visibility into all assets
  • Threat management informing vulnerability management
  • Exposure management concept
  • Continuous checking of our layered defenses and control structure
  • Red-Blue-Purple team exercises
  • Reporting our exposure based on risk to upper management and the board
  • Playing offense and the role of threat hunting in managing our attack surface
  • Using deception to understand our gaps
  • Pulling it all together into a real dashboard
  • How to roll this into risk management models for reporting
  • OT/IoT

Sponsored by SICURA

Services