Blog
The Four Stages to a Successful Vulnerability Management Program
By Mitch Parker on Wed, 04/20/2022
Have you ever been around someone who is just better at something than you are? Like when you were in grade school and there was this person who was effortless at doing things correctly, like getting high grades? They had great study habits, they arrived on time, they were prepared and confident in the materials that they studied in class, and they...
Datasheet
Tripwire Vulnerability Intelligence
There’s not enough time in the day to investigate every system change and remediate every vulnerability. Ever-evolving capabilities of cyber adversaries—coupled with the dynamic nature of corporate networks— makes security prioritization increasingly difficult. With Tripwire® Enterprise and Tripwire IP360™ managed service offerings, you can minimize the amount of time you spend addressing high...
Datasheet
Calculating the ROI of a Vulnerability Management Program
Return on investment on IT security infrastructure purchases (solutions and products) has traditionally been hard to quantify. However, there are some compelling aspects of securing an organization’s infrastructure that can be identified and quantified. This discipline will continue to evolve as organizations focus on managing and balancing their security expenses and strive to control the...
On-Demand Webinar
How to Protect Against the Ransomware Epidemic
Mon, 08/15/2022
Ransomware has developed from a niche attack to a booming criminal market over the last year because the simple, turn-key business model behind ransomware infections doesn’t require any real technical skill to execute. As a result ransomware will continue to evolve and will continue to escalate for the foreseeable future.
The good news is that there are simple steps you can take today using...
Blog
Vulnerability Scanning vs. Penetration Testing
By Babar Mahmood on Fri, 05/03/2024
In the modern digital landscape, cybersecurity is paramount, making the differentiation between vulnerability scanning and penetration testing essential for safeguarding organizational assets. Vulnerability scanning offers a broad sweep for potential security weaknesses, serving as an early warning system. Penetration testing takes a more targeted...
Blog
Five “W’s” for Vulnerability Management
By Ben Layer on Sun, 12/01/2019
As we wind down 2019, it is a great time to think about your vulnerability management plans for the coming year. The five W’s can help guide our efforts as we resolve to improve our digital security for the coming new year.What Is Vulnerability Management?Vulnerability assessments are useful for detecting security issues within your environment. By...
Blog
Climbing the Vulnerability Management Mountain: Gearing Up and Taking Step One
By Lamar Bailey on Sun, 07/14/2019
As I discussed in the first blog in this series, the purpose of this series is to guide you on your journey up the Vulnerability Management Mountain (VMM). Like climbing a mountain, there is a lot of planning and work required, but when you get to the top, the view is amazing and well worth the journey. For the first phase, let's start by planning...
Blog
What’s New and Changing in the World of Vulnerability Management?
By Lamar Bailey on Sun, 06/23/2019
According to CIS, “Organizations that do not scan for vulnerabilities and proactively address discovered flaws face a significant likelihood of having their computer systems compromised.” While vulnerability management (VM) isn’t new, I’ve seen it evolve a lot over my 22 years in the industry. Here are some big trends:Assets are Diversifying. Fast.The idea of an asset has changed and grown over...
Blog
To Agent or Not to Agent: That Is the Vulnerability Management Question
By Irfahn Khimji on Wed, 02/13/2019
With the evolution of technology comes new approaches to solving problems. Sometimes a new approach fixes the problem; sometimes it creates new ones. The good thing is as folks who work in fast-paced, high-tech environment, we information security professionals are great at quickly analyzing the new technologies and applying them to our daily lives. ....
Blog
Tech-Forward Countermeasures in the Fight Against Identity Theft
By Guest Authors on Thu, 11/17/2022
Technology has expanded the avenues bad actors use to steal identities and sensitive data. However, digital tools are also giving users innovative countermeasures to protect themselves.
Here are seven tactics anyone can use to help prevent identity theft.
1. Leverage Multifactor Authentication
Strong passwords have always been an identity...
Blog
Cyberattacks are targeting smaller healthcare companies and specialty clinics. But why?
By Guest Authors on Mon, 11/28/2022
The healthcare industry has been a favored target for cybercriminals for many years. In the first half of 2022 alone, 324 attacks against healthcare organizations have been reported. Attackers have primarily focused on large hospitals in years past, but there has been a sudden switch to smaller healthcare companies and specialty clinics.
There...
Blog
WEF Report Details Best Practices for Zero Trust Deployment
By Guest Authors on Wed, 11/09/2022
Cybersecurity, like broader technological disciplines, is an ever-changing landscape that industry professionals must adapt to. The zero-trust model of cybersecurity has grown recently as organizations update their security practices to keep pace with, and stay ahead of evolving threats. Zero Trust Network Access (ZTNA) increased by 230% from 2019...
Blog
Vulnerability Management: Just Turn It Off! Part II
Wed, 08/06/2014
Our last post in the “Turn It Off!” blog series discussed some of the most common and yet unnecessary features that can make your environment more vulnerable, including JBoss JMX consoles, server banners and the Apache HTExploit.
These risks are often encountered by our Vulnerability and Exposure Research Team (VERT), even on well-defended networks and many of which have been around for quite...
Blog
Protecting Sensitive Data from Insider Threats in PCI DSS 4.0
By Guest Authors on Tue, 08/08/2023
Safeguarding sensitive data is a huge concern for organizations. One of the biggest challenges they face is the threat posed by insiders who work for the organization. In fact, a report found that 74% of organizations are at least moderately vulnerable to threats from insiders.
This has increased spending towards protecting against insider threats...
Blog
The CIA Debate: Which is the Most Important?
By Anastasios Arampatzis on Mon, 08/21/2023
The Confidentiality, Integrity and Availability (CIA) Triad is a crucial information security model that guides and assesses how an organization manages data during storage, transmission, and processing. Each component of the triad plays a vital role in maintaining information security:
Confidentiality means that data should not be accessed...
Blog
Why No Business in 2023 Can Grow without APIs
By Ross Moore on Tue, 08/22/2023
The Importance of APIs
Businesses of all sizes are increasingly relying on APIs to connect with their customers, partners, and other systems. APIs, or application programming interfaces, are the building blocks of the modern web, and they allow businesses to share data and functionality in a secure and efficient way.
Without APIs, businesses are...
Blog
Tripwire Patch Priority Index for August 2023
By Lane Thames on Fri, 09/08/2023
Tripwire's August 2023 Patch Priority Index (PPI) brings together important vulnerabilities for Microsoft.
First on the patch priority list this month are patches for Microsoft Office, Excel, Visio, Teams, and Outlook. The patches resolve 10 issues including remote code execution, information disclosure, security feature bypass, and spoofing...
Blog
Is a Shift Left Approach Hurting Software and Supply Chain Security?
By Anastasios Arampatzis on Tue, 01/10/2023
As the cyber threat evolves, adversaries are increasingly targeting non-publicly disclosed vulnerabilities in the software supply chain. Attackers are able to stealthily travel between networks because to a vulnerability in the supply chain. To combat this risk, the cybersecurity community must center its efforts on protecting the software...