What is our primary use case?
I am familiar with Unified Vulnerability Management through Tenable, which serves as my primary tool and playground. Unified Vulnerability Management is a universal vulnerability management tool. I have been using Tenable AI, Tenable AD, and Tenable IO for more than eight to nine years, approaching close to ten years of experience.
I worked for TD Synnex, the largest distributor in the USA and globally. In my role as a senior cyber security architect, I implemented their Unified Vulnerability Management application across approximately 9,000 servers with global operations. I also worked for Caterpillar as a data security admin level four, which is the highest level of engineering role beside the America Tech. I found that they used vulnerability tools including Tenable and other vulnerability management solutions. Based on my understanding of the rhythm of business, I applied Unified Vulnerability Management principles and evaluated their capabilities from an engineering perspective.
How has it helped my organization?
During my experience with Unified Vulnerability Management at TD Synnex in 2022, I was involved when they merged two large organizations, Tech Data and Synnex, becoming TD Synnex with approximately twenty organizations altogether. I was responsible for the merger and acquisition program, and I proposed implementing Unified Vulnerability Management from the root with the new application. I rebuilt their naming convention, which was a substantial task, and discovered many gaps in the process.
What is most valuable?
From Unified Vulnerability Management, credential scanning emerged as the most significant feature. Credential scanning identifies when someone attempts to log in to our network from outside, a capability that no other application recognizes. If someone tries to log in inside our network from outside, it will not be recognized by any other application, but Unified Vulnerability Management, especially through credential scanning, recognizes and prevents the operation.
Credential scanning is important for Unified Vulnerability Management as it serves as the first line of defense against hackers attempting to enter your network. From my role as a cybersecurity design architect, this capability is crucial. Most EDR, XDR, and other protection tools may not catch these sophisticated attacks because hackers use AI and different methodologies to gain access. They act as real users, injecting usernames and passwords, which can easily compromise credentials and allow them inside the network. Other tools cannot detect such activity, which is why I focus intently on this and secured my credential environment.
Unified Vulnerability Management is a very important part of my security strategy. My understanding shows that I have worked with many complete security postures, and vulnerability management is one of my areas of expertise. I believe that Unified Vulnerability Management is the backbone of any organization's security posture.
Unified Vulnerability Management means a comprehensive security approach that combines vulnerability discovery, assessment, prioritization, remediation, validation, and reporting into a single centralized program platform. I can secure servers, workstations, network devices, and cloud resources including Azure, AWS, and GCP, especially from an American market perspective. It also includes applications, APIs, containers, Kubernetes, mobile devices, IoT, and DevOps elements. Unified Vulnerability Management prioritizes vulnerability scans to detect CVEs, ensuring continuous monitoring and assessment, tracking remediation progress, and automating patch deployment. It integrates threat intelligence and complies with standards including NIST CSF, 853, CIS control, ISO 27001, PCI DSS, and HIPAA.
The features I rely on most day-to-day in Unified Vulnerability Management are asset discovery, vulnerability management, patching, remediation, and threat intelligence. These are the most significant aspects for me. Additionally, I work to reduce security tool sprawl, achieve faster remediation patching, improve compliance readiness, enhance risk-based decision-making, and maintain visibility across hybrid and multi-cloud environments.
I have used various solutions including Microsoft Defender Vulnerability Management, Tenable One, Rapid7, InsightVM, and CrowdStrike Falcon for vulnerability management. Additionally, I also utilize Wiz for cloud vulnerability management tools.
Unified Vulnerability Management has centralized the process of identifying, assessing, prioritizing, remediating, and monitoring vulnerabilities across my organization's entire IT ecosystem through a single integrated platform and governance framework, making this the most significant advantage.
I observe that Unified Vulnerability Management provides significant asset discovery, vulnerability scanning, and the capability to detect vulnerable CVEs, ensuring continuous monitoring and assessment that creates alerts if anything occurs. It also uses risk prioritization based on CVSS scores, threat intelligence, exploit availability, and business impact while emphasizing patching prioritized exploiting vulnerabilities.
What needs improvement?
I believe Unified Vulnerability Management can improve by emphasizing continuous monitoring, which necessitates a dashboard for users. Creating more mobility, especially since many incidents occur outside regular hours, would be beneficial. If anything goes wrong, a mobile version or mobile dashboard could be extremely helpful. Mobility is now a mandatory capability, allowing users to manage vulnerabilities through mobile applications.
Beyond mobility for Unified Vulnerability Management, more flexibility is also required. For example, vulnerability scanners routinely scan and create reports. It would be beneficial if I could create a runbook so that if any unwanted events occur, it generates alerts and stops operations. This would create a complete package for secure posture and management, allowing me to protect not just through scans but also through prevention.
For how long have I used the solution?
I have been working with Unified Vulnerability Management for more than eight to nine years, approaching close to ten years of experience.
What do I think about the stability of the solution?
Unified Vulnerability Management is stable and should be since organizations are investing heavily. As a cybersecurity engineer, I prefer more than one tool, especially EDR and XDR, to ensure dual protection as any failure could jeopardize your entire business. Using two tools instead of one provides an extra layer of security for the environment, especially within enterprises.
What do I think about the scalability of the solution?
Unified Vulnerability Management demonstrates scalability. For instance, I currently manage 9,000 servers while only purchasing licenses for 3,000 applications, enabling me to expand from 9,000 to 12,000 servers when needed without disruption.
How are customer service and support?
Customer support varies. After COVID, I find customer support lacking, and I am not sure why the principals do not prioritize it more. They focus on technology but also created community sites for users to ask questions, which often provides automated responses for common queries. For new issues, there might be a delay in receiving help, and sometimes it involves answering machines when calling for support, which can be frustrating. I believe OEM should consider refining their support strategies, employing better AI agents that can cover frequent questions and enhance their response to users.
Which solution did I use previously and why did I switch?
I previously used other solutions before Unified Vulnerability Management, particularly Tenable products including Tenable, Tenable IO, and Tenable vulnerability management for vulnerability scans.
Before using Unified Vulnerability Management, I evaluated options including Azure Security Center, Microsoft Defender, Qualys, and Splunk, integrating these to enhance capabilities for vulnerability management. My primary focus is on Microsoft and Tenable, with limited use of Microsoft Defender vulnerability management before switching.
What was our ROI?
I observe that Unified Vulnerability Management leads to significant returns on investment, in which automation reduces the need for human intervention. I can configure everything to operate on schedule; therefore, no need for manual operation is required. Everything scans automatically, creates reports, and generates ServiceNow tickets for remediation. It becomes a hands-free application that streamlines my processes greatly.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing is not directly managed by me; however, I strongly recommend Tenable as I view it as a prime vulnerability management application worldwide. Even when comparing other tools, I vote for Tenable because they continuously research and tackle challenges faced by many organizations. Pricing-wise, vulnerability management generally involves two types of models: one for licensing individual devices and another for environments. It is advantageous as you may not need licenses for all 9,000 servers but can effectively manage and scan even with fewer licenses for prioritized servers.
What other advice do I have?
My advice to others looking into Unified Vulnerability Management is to consider Tenable One as my first choice. I tend to favor Tenable and its different use cases. For example, Microsoft Defender is advantageous only within Microsoft platforms, whereas Wiz is beneficial for cloud-only environments. Given more comprehensive needs, Tenable One stands out as compatible with most infrastructures. ServiceNow has a vulnerability response function, but I have limited experience with that. I have also looked into CrowdStrike, particularly their Exposure Management, but I have not explored it fully as it is newly released.
Every technology is developing rapidly, and there is a growing emphasis on AI within this evolution. Just three years ago, AI was not as prevalent, but now it significantly enhances productivity and efficiency. However, it represents a double-edged sword; while largely beneficial, AI can also create risks. It learns from inputs, and if anyone employs bad prompts within an enterprise context, they might expose vulnerabilities without recognizing it. Therefore, I need to safeguard AI use alongside utilizing DLP systems to protect such instances, ensuring protective measures are in place for any potentially harmful inquiries made to AI.
I rate this solution a nine out of ten based on my overall experience.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other