Note: This is part 2 of a 5-part series in which we examine a smarter approach to attack surface management. Catch up on last week’s post first.
Attack surface is on the rise– but that’s not necessarily a bad thing. As organizations mature, they undertake normal growth activities like business transformation, or M&A. These initiatives expand their web of internet-facing IT, but with limited resources and dispersed accountability, ability to maintain oversight wanes. And in the shadows of…. well… shadow IT, malicious attackers lurk.
Last week we discussed why programmatic attack surface scanners are no match for motivated attackers. In today’s post, we’ll explore how human ingenuity can help, providing every organization with their own Hacker’s Advantage.
While attack surface drift typically occurs over many years of growth and business change, it can also happen suddenly, and unexpectedly. Covid-19-induced “shelter in place” orders have forced a quick shift to fully remote work (where possible). But accelerated timelines for introducing new online services have caused many organizations to shortcut standard launch protocol. And while the arrangement may not last, the impact of mismanaged IT will.
Bugcrowd’s Attack Surface Management portfolio provides two uniquely valuable solutions for discovering, prioritizing, and managing unknown attack surface. Combined, they are the ultimate attack surface management solution.
Asset Risk is best described as ingenuity-driven asset discovery and prioritization. This on-demand offering leverages the power of our global Crowd of vetted security experts to find and prioritize previously unknown internet-facing attack surface. With access to the latest reconnaissance strategies and tooling from those actively developing them, Asset Risk helps organizations out-hack digital adversaries before they strike.
How Asset Risk works:
If Asset Risk can be summarized by, “human-powered, software assisted,” Asset Inventory can be thought of as the reverse. Bugcrowd Asset Inventory, which is powered by Bit Discovery, is a software-based continuous scanning solution fueled by an ever-growing pre-indexation of (almost) the entire internet. Organizations can configure alerts, filter inventory, and collaborate with other business units to more effectively manage their internet-facing assets. Additionally, extensive APIs help programmatically ensure compliance and security for the business at large.
How Asset Inventory works:
While the two solutions can be deployed separately, combining Asset Risk and Asset Inventory enables insights from one to fuel and sharpen the activities of the other. This can improve inventory accuracy, better inform priority rankings, and more rapidly reduce risk across the business.
For more on how technology-backed human ingenuity plays a crucial role in staying ahead of malicious attackers, stay tuned for next week’s blog, or contact us today!