Video: The State of Threat Management: Exploring Current and Future Trends of Cyber Risk Exposure Management | Duration: 1792s | Summary: The State of Threat Management: Exploring Current and Future Trends of Cyber Risk Exposure Management | Chapters: Welcome and Introduction (6.96s), Speaker Introductions (76.975s), The Exposure Gap (185.06s), Data to Intelligence (342.54s), Prioritization Bottleneck (474.4s), Evidence-Based Prioritization (581.405s), Tool Integration Challenges (735.74s), Organizational Readiness (873.98s), AI Automation Gap (1110.485s), AI Value and CTEM Maturity (1339.3s), Geographic Trends (1564.17s), Global Risk Quantification (1641.11s), Closing Remarks (1719.61s)
Transcript for "The State of Threat Management: Exploring Current and Future Trends of Cyber Risk Exposure Management":
Alright. Hello, and welcome, everyone. Welcome to today's session, the state of threat management, findings and discussions around current and future trends of cyber risk exposure management. That is a mouthful, I know. My name is Adam, and I'm gonna be moderating today's session. But really quick before we get started, a couple of quick housekeeping items to go over. First of all, this session is being recorded, and anyone who registered will receive an on demand version of the recording after the session is concluded. If you have any questions for our speakers today, you can ask them by clicking on the q and a tab, which is on the right hand side of your screen. We have some time planned for q and a at the end of the session, so we're gonna try our best to get to to all the questions asked by the audience. There's also a docs tab on the right hand side of your screen next to q and a. Here's where you can access our state of threat management report, which we're going to be discussing a lot today. And so, today, I am thrilled to be joined by two speakers, Pierre Louique, and Chris Novak. So without any further ado, I'll bring them on stage to introduce them. Chris, over to you first. Sure. My pleasure. Thanks, thanks for having me on. I'm Chris Novak. I'm a cybersecurity executive and advisor with, more than twenty five years of experience, helping large enterprises and government agencies manage, you know, various different types of complex cyber risk. I previously led Verizon's global cybersecurity solutions organization and spent a lot of my career working at kind of the intersection of threat intelligence and security operations, as well as executive risk management. Another big part of my cyber journey I I can never forget is, working on the Verizon data breach report. Having had the opportunity to be, an executive sponsor and author from the the very first edition in 2008 through this year's 2026 edition. So, some of you may, may know me from some of my work and and speaking there. And today, I'm cofounder of Quadrum Advisors, where we help enterprises address their most important cybersecurity challenges through, you know, senior level advisory services with a particular focus on emerging areas such as AI, cloud, quantum, operational technology, and then obviously, very importantly, modern threat and exposure management. And I'd say kind of our key constituents and clients are typically, you know, c suite and boards of directors. Over to Piel. Hey, Adam. Hey, Chris. It's a bit difficult to go after you. I don't have a CV that doesn't impressively with Chris. But I'm a senior product marketing manager here at Filigram, and I worked on the state of threat management reports. So, of course, it doesn't match the the content that you worked on before. But, nevertheless, we're really happy to have you here and, and jump into this, into this presentation. So I'll get started here, because today, we're talking about exactly this report, the independent report that we just released at Filigram. We call the state of threat management. It's the first of its kind. And for those who have not read it already, we commissioned the survey because, you know, although there's plenty of research out there on threat intelligence exposure management, risk quantification, and separately, nobody had really looked at the convergence we're seeing across all of those different subjects towards, like, you know, the this concept of the unified threat management, or what Gartner calls c 10 and what it means, of course, for this future of cyber defense. And that's exactly why we wanted to have you here, Chris, to bring your years of expertise in this space to help us make sense and apply a bit of practical context to what we found. So it's not just numbers and statistics on the screen or on a page. So, obviously, we don't have time to go through the whole reports. So consider. this just a snapshot of some of the key findings, which is structured into four chapters just like you'll see in the reports. So what I'll do is just walk through, a few of the top level statistics from each chapter. And then, Chris, we can get your take on those and and check if it tracks through what you're seeing, if any of it is surprising to you, and what it might mean for for the industry as a whole. How does that sound? good. Great. Sounds perfect. Amazing. So let's jump straight into the first section. So the first chapter is about a very interesting paradox that we've uncovered. We call it the exposure gap. And it's not new, but it was great to start getting the data around it. So we know that organizations, they run on average about six tools just to assess cyber risk today. And 99% of sub teams use threat intelligence. It's near universal. Everybody agrees. It's also not a big surprise. We did uncover, though, that they use on average about 14 feeds and nine of those being open source. So tools, intelligence, data, it's it's all there, but yet 59% do not have a fully consolidated view of cyber risk. And to reinforce this point, more than half do not have threat intel fully integrated and operationalized. More than 60% struggle to identify exploitable vulnerabilities, and more than 90% struggle to maintain an accurate view of their attack surface. So it seems like tool adoption and having threat intelligence isn't necessarily solving all the problems that we thought it would. So organizations are still at risk today. So, Chris, here is a first question for you. Why do you think this gap exists? If teams have all the right tooling and they have the threat intelligence, why are they still struggling to consolidate and leverage their data to to try to be more resilient? Yeah. And I think, you know, first, I I wanna commend you guys on the report that you produced. I I very much enjoyed reading it, so I I just wanted to throw that out there. But, you know, I think, Kenneth, to answer your question, I think, you know, the the mistake that a lot of organizations make, I think, is equating collection with intelligence and intelligence with action. Most large security organizations have no shortage of data. And, you know, I know from my time at Verizon and before, you know, people would kind of almost brag about the the quantity of inputs that they had and, you know, they have vulnerability data, they have asset data, telemetry from the SOC, multiple threat feeds, and often, you know, very capable point products in a lot of different areas. And the problem is that each of those sources tends to arrive with its own data model, scoring system, workflow, and and definition of priority. And the analyst kinda ended up being kind of the the integration layer in the middle. And so, yes, you know, sometimes more tooling can actually make the visibility problem worse when it produces more disconnected views instead of kind of a common operating picture or model there. I've seen this repeatedly over the years, you know, teams can point to that enormous amount of information, but they still struggle to answer, you know, kind of what I would consider to be the very basic question of, you know, which of these issues is most likely to matter to us, and what should we do about it right now today? And I'd say kind of the important evolution is from aggregating all of these feeds to creating a threat informed decision system. Intelligence needs to be normalized, correlated with the organization's, you know, environment and business context, and then carried into the security workflows where somebody can actually act on it. And so I'd say that's kind of why I think the the market is moving more toward connected threat management platforms rather than another collection of just a lot of dashboards. The goal isn't to, in my opinion, to see more. It's to turn what you already know into better, faster decisions. Thanks a lot, Chris. And, actually, let's stay on this point because we're gonna go straight to our next chapter because you're starting to discuss something that we actually uncovered in this second chapter of the report. So it's a great continuation because this part is about driving the point that visibility, as you said, isn't actually the core issue that much anymore. So right off the bat, 84% of our respondents in the report say that rising threat volume and sophistication made it harder to spot what needs immediate attention. And 97% struggle to determine if an exposure is actually exploitable, and 82% say that manual processes make it harder to prioritize. And so the consequence is that more than eight out of 10 say that attacks they face exploit risks that were already known, just never prioritized. Right? So like you said, like, you have the visibility, but you're not actually acting on it. And that's real exposure. That's real risk. And even if you wanna quantify in ROI perspective, analysts lose about 42% of the week, so that's about seventeen hours a week, just chasing risks that end up, you know, not mattering to to the to the stock team in the end. So this is what we mean by this part of the report, which we call the prioritization bottleneck, that we have a great visibility but not the greatest of, prioritization or operationalization of this data. And the cost then is waste of time and real exposure. So to continue onto what you were saying just now, Chris, if teams can't even confirm what's exploitable, is the concept of prioritization, right, more guesswork and process right now? And the follow-up question would be, has it always been this way, or is prioritization or the authorization of data a newer problem that you know, in the cybersecurity space? Sure. So I'd say prioritization has always been a problem, but the scale of the problem is, I think, very different today. Historically, we could get away with, I'd say, kind of fairly crude proxies, you know, severity scores, criticality labels, maybe a list of Internet facing systems because the volume of data was smaller, and there was more analyst capacity to apply judgment manually. Today, there are simply too many exposures, too many environmental changes, and too many threat signals for that model to scale, especially when you consider the way the landscape has changed with everything as it relates to potential AI, you know, helping us identify I say helping us, but, you know, identifying new potential vulnerabilities and exposures out there. You know, one might argue that the the scale of the challenge is growing maybe exponentially and and obviously, you know, trying to scale the response or the defense with people that that doesn't work. Right? Scaling the the machine and the AI on the offense, trying to scale the the defense of the people that doesn't work. So if prioritization means looking at severity score and deciding what feels important, then, yes, there is still a lot of guesswork. Mature prioritization should be, in my opinion, evidence based. I want to know, is this relevant to adversaries that actually target organizations like mine? Is the exposure reachable? Is it exploitable in my environment? What asset or business process sits behind it, and do my existing controls actually interrupt the attack path? These are things where I feel like organizations are are really just kinda starting to come to grips with how much more that can change their defensive posture. And that is where threat informed exposure management becomes, you know, really, really powerful. You are combining intelligence with the reality of your own environment and then validating assumptions rather than simply ranking findings. And that shift is from kinda this could be bad to we have evidence this matters to us. And that is much better that's a much better basis for deciding where, you know, scarce security resources should go, how you should evaluate budget. And then also in the world that I'm in with talking to the c suite and the board of directors all the time, this is something you can also then use to help bubble up how it is you're addressing the concerns in a more, you know, proactive and a prioritized manner. Thanks a lot, Chris. And that makes a lot of sense. And, you know, one aspect of this also is when we looked at this data, it wasn't always sure if tooling process was the issue. Right? It's just a more general concept that seems to be missing. And so this is why I wanna jump into this third chapter, right, which we called validate to assess readiness. And this part of the story continues exactly what we're saying, but now through the lens of tools or the use of tools today to do, the operationalization and prioritization, for example, of data. And, again, straight off the bat, you know that 31% say that having too many tools negatively impacts attack surface visibility, and 47% face real barriers just integrating tools that they already own, which is, in line to what you were you were saying just now. And what's more is we found data in the reports that reinforces this by saying that integration with existing platform is now the number one purchase factor for new exposure management tools at forty two percent across all the different potential factors. And so this is also reflected in how teams validate risk. 82% agree that periodic assessments alone can't keep up with changing environments, and 94% agree that having proactive security posture depends on integrating threat intelligence with exposure managements. So a picture start to form that you started discussing just now of how teams have plenty of tools, but they still can't prioritize. And it's likely because those tools still sit a little bit in a silo instead of building one picture of risk. So, Chris, you've really you've been to all those big events. Right? You've been to RSA. You've been to Blackheads and all these big events. And needless to say, in the exposure management space, it's getting a bit crowded. We're not lacking in vendors. Right? I mean, there's so many of them. But the data suggests that teams, they aren't just shopping for more tools or capabilities anymore. They're trying to get what they already have to talk to each other and reduce friction. So my question now is from your experience, is this type of, you know, what we can call tools pro, is it a real blocker in cybersecurity? And does this mean that in order to drive effective CTEM or continuous threat exposure management, teams will need to consolidate their tools and processes? And I'm talking about CTI, risk quantification, exposure validation, and etcetera etcetera. Sure. Yeah. So I'd say tool sprawl is absolutely a real issue, but I would be careful with the word consolidation. I don't think that the answer is that every enterprise and every enterprise should just throw away, you know, best of breed products and buy, you know, one enormous monolithic suite. The more important consolidation is at the data context and workflow layer. I'd say a mature CTEM process should be able to move continuously from what are adversaries doing, to what does that mean for my environment, to which exposures are realistically exploitable, to whether my controls can stop them, to what needs to be remediated, and and how do we go about doing that. And if every stage requires a different analyst to export a spreadsheet, reinterpret the data, and manually hand it to the next team, you don't really have continuous exposure management. And I think that kinda gets to the heart of what you were saying around, you know, tool sprawl in a lot of places where I've seen it. That's ultimately how that workflow happens, and it's it's extraordinarily, inefficient. So I think the winning kind of platform model is all about what I'd kind of say is connective tissue. You know, it should normalize and operationalize threat intelligence. It should integrate broadly with the security stack, bring validation results back into the same decision context, and support remediation without forcing the enterprise into a closed ecosystem. You know, that's one reason the the open integrated architecture that I know Filigram pursues is, you know, I'd say very directionally compelling addressing different parts of the life cycle, but the real value comes from connecting those parts into one threat informed operating model. I'm I'm very big on the threat informed operating model, very big on the threat informed decision making. Thanks a lot. And I have a follow-up question to this, Chris, because and this is not necessarily in the report. This is an additional question, right, because it's very interesting what you're saying that, you know but the thing is that consolidate consolidating tools, it often also means consolidating teams, right, the people who use the tools. And we know in the past, you know, security teams have always been rather, you know, let's say, disconnected in the larger SOC operations. So do you think SOC teams are actually ready for this consolidation of tools at an organizational level? The people, I mean, not just the tools. So I'd say that's probably the harder part. Organizational change, you know, typically is one of the most difficult things for for enterprises to do. Most enterprises are still, I'd say, organized around discipline. So you've got, you know, threat intelligence, vulnerability management, red team, SOC, incident response, GRC. Those teams often have different tools, different metrics, different leaders, different budgets. CTEM cuts kinda horizontally across all of them. So organizations don't necessarily need a a reorg chart, I'd say, you know, on day one, but they need to kinda have some type of, I'd say, kinda shared decision rights and shared outcomes. Who owns the exposure after it's been identified? Who decides what it is that's important? Who validates it? Who accepts or remediates the risk? And how do the results feed back into the intelligence and detection programs? So I'm not necessarily advocating for massive reorgs. I think it becomes much more about kind of almost like a shared operating model across the groups. Technology can create the common workspace and say automate the handoffs, which I think is enormously valuable and it speaks to, you know, the conversation we were just having a moment ago around, you know, also driving better efficiency, but leadership still has to define the operating model. The best implementations I would expect to see are the ones where the platform and the organizational processes evolve together over time. Thanks a lot, Chris. So that extremely insightful. I want to jump into, the next part of the report, which is unsurprisingly about automation and AI. because we couldn't have the webinar in twenty first century without talking about AI today. So I wanna jump into this topic, but I do wanna highlight something very interesting, right, because this is one of my favorite finding of this report, because it brings a very simple and yet very telling contradiction. When asked about the need for automation in exposure managements, 88% of the respondents said that they need automation because without it, they can't keep up with the volume of risk they need to assess. And more than 90% agree that more automation would boost confidence in prioritizing the right risk. Right? So, of course, it makes sense. Great. This is compelling. It aligns with what we've been discussing before. AI automation needs to happen. But where it gets interesting is that 90% still rely on manual processes at every stage of the exposure management process, and only 11% say that, a bit more than half of the processes are AI driven. So the belief is there. Right? But the practice isn't necessarily there. And looking ahead, organizations agree that they need to ramp up investment in AI driven processes for for exposure management, and they highlight a near doubling within the next two years. So all that to say that clearly, you know, automation is key, and yet not everyone seems ready for it. So, Chris, the question is simple. Why this contradiction, do you think? And nearly everyone agrees automation is a fix and yet adoption lags. Yeah. That's a great one. So I'd say, you know, because automation is easy to agree with in principle and much harder to trust in production. So, if you look at it and say, you know, automation depends on good data, clean integrations, defined workflows, and confidence in what happens when the system takes an action. If the underlying process is fragmented, automating it can simply just make that fragmentation move faster, if you will. And, you know, I'd say AI adds another layer to that. Security leaders are understandably cautious about allowing an AI system to make consequential decisions when they can't explain the data, the guardrails, or the reasoning behind those decisions. And that is why, you know, I I think the first successful wave is not replace the analyst. It is automate the repetitive connective work around the analyst, enrichment, correlation, summarization, prioritization support, generating relevant validation scenarios, and, you know, recommending remediation. I think you really have to keep a human in the loop where judgment and accountability really matter. And the direction that becomes, I think, really interesting is, you know, agentic orchestration across the life cycle rather than a different AI assistant embedded in every every point tool. If an AI layer can work from a trusted intelligence foundation, coordinate validation, and help move findings toward remediation, you begin to attack that, you know, 42 of the week problem in in a meaningful way. You know, the value is less AI as a feature and more AI used to connect and accelerate an existing threat management workflow. Yeah. Thanks, doctor Chris. So, you know, when we when when we we bring up this data about nearly doubling the, the the growth in the use of AI and exposure management, there's no if I understand correctly, there's no single tool or single place where this needs to happen. Correct? It's rather a wider process. That's right. Yep. I I I completely agree. Yeah. Okay. And so I want to jump then into the final question that we have for you. And it requires a little bit of context before I jump into it because when we're analyzing the raw survey, or the raw data from the survey, we came across an interesting correlation between the perceived value of AI, which we're just talking about, and, c 10 maturity. So the survey asked respondents which areas of exposure management they expect to benefit the most from AI and automation, and as a result, of course, where they might invest in the future. But then we split those results by c 10 maturity levels of these respondents because we want to see whether exposure management correlates with well, exposure management maturity rather correlates with specific investment priorities. And so in this chart, it represents what we found with organization that are still planning their c 10 program that's in green and those who have a mature c 10 program already in place in dark blue. And the result is is is quite interesting. Because if we look carefully, teams planning for c 10 programs seem to want AI concentrated during the early phases of c 10. So that's the discovery, the scoping phases, kind of detection phases. But teams with mature stem programs, they see more benefit in downstream phases. So prioritization, validation, mobilization, remediation, etcetera. So simply put, there seems to be a correlation, right, between the value of AI and the maturity that an organization has with CTEM and explosion management. But is that just a coincidence? So this is where my question comes from, Chris. What do you these results? Are we looking at causation or correlation of maturity and the benefits of AI? And is there something really concrete around what we discovered here? Yeah. So I'd say I I think it's a bit of both, but there is, I'd say, strong causal component to it. I'd say early in a CTEM journey, the organization is still trying to establish the basics, you know, scope the environment, discover exposures, consolidate intelligence, and create a usable data foundation. AI is naturally attractive at the the front of the process because it can help search, summarize, enrich, and make, you know, sense of all of that information. I'd say kind of once the program matures, the constraint changes. The the organization has more structured context and more repeatable workflows. Now the hard questions are what actually matters? Can an adversary exploit it? Do our controls work? You know, what should we fix first? Those are exactly the places where AI can create more leverage, but only because the organization has built enough context and and process for the AI to work against. There's probably correlation, there as well. You know, organizations that are already comfortable governing automation and AI may move through that c 10 maturity curve kind of faster. But the the broader lesson is that, you know, I'd say AI amplifies the operating model you give it. It doesn't substitute for one. And so as c 10 matures, a connected architecture, much like what you're doing at Filigram, gives AI something grounded to reason over and and something measurable to act upon. That's great. Thanks a lot, Chris. I think we're just about, time. With this five minutes left, Adam, so I we finished our main questions for, for Chris. So I wonder if there's anything in the q and a or anything that was asked during the session. And, yeah, we can take it from there. Awesome. Thank you, PL. This is great, by the way. I'm so happy that that we got this session together because this is, this is amazing. Again, for the for the audience, if you have any questions, for PL and Chris, please ask away in the q and a tab. First question that I'm seeing here is, like, from the report, were there any takeaways based on geography or any regions that are kinda leading the way? So if you want, I can I can mention what we find, and then I can ask and, Chris, I can ask you what what you think of it? So from the report, if my mind, Sure. remembers correctly, North America was very often the the leading geography in terms of investment in, in cyber risk exposure management, using threat intel in a fully automated process. And I think one of the most telling numbers was that they are this geography or the companies in that geography who are planning to increase the investment the most in risk quantification, tools for their threat intelligence and threat exposure management processes. So do you is that surprising to you that North America is is always kind of leading the charge in that area? So I I think that's an interesting one. Over the years that I've been in the industry, I've tended to see that that is usually the way things have been. We've seen a lot of innovation. We've also seen The Americas is known for kind of being a bit more of a litigious environment as well, which tends to also drive a lot of change and rapidly because organizations are responding to changing legal landscapes and and changing legal precedent. And CRQ and and and broader risk quantification is something that we've seen a fairly significant amount of growth. I I know I will say, you know, just having come back from Black Hat just a couple of weeks ago, that was a big topic that that kept coming up, from a lot of the people that I were talking to and, you know, a big piece of that being kinda North American focused. But at the same time, I'd say that we've seen kind of an explosion of that kinda happening around the world as well in in a positive sense, happening in EMEA and then also to, I'd say, maybe a slightly lesser extent in Asia Pac. But I think that, you know, all of that is is coming. And I think the world is looking for more of that because people are looking at you know, going back to the earlier conversation we had about the importance of being able to do good decision make good threat informed defense, risk quantification really helps with that. Awesome. Thanks a lot, Chris. Adam, it is no more questions, and I think we are we are at the end of it. Yes. Timing actually is is working out, very well. But, yeah, we're right at about time. I just wanna say, on behalf of myself, PL, and Chris, you can speak for yourself, but I thought this was amazing. Thank you guys both for, for speaking on here. And thank you, to the audience all for taking the time out of your day to enjoy this. And there's a survey that should be popping up on your screen right about now. We'd love to hear your feedback, on the session as well as any other topics that you'd like to see us present on, in the future. Any feedback is valuable, and greatly appreciated, and it'll help us improve our webinars and produce the most relevant, sessions for you in the future. So, again, huge shout out to Chris for, for the taking the time out of his day to, join us and share his, you know, knowledge and expertise with us. So thank you very much, Chris. We really appreciate it. Thank you, you. Chris. So so on that note, thank you guys again, and I hope you all enjoy the rest of your day. Thank you all. Thanks, all. Bye.