Research
Our team (formerly of Kenna Security as well as co-creators of the EPSS) invented risk-based vulnerability management. But we believe there's areas of exposure management that haven't even been tapped, and they need to be explored urgently given the monumental challenges facing security teams. We're excited to publish our research (including ongoing benchmarks of our global and local models) and present them here.
Jay Jacobs, Chief Data Scientist
Michael Roytman, CTO
Dr. Benjamin Edwards, Head of Modeling
Jerry Gamblin, Head of Research
Exploring with a Purpose
We have the better, if harder, problem of the meta-analysis (“research about research”) of many observations, always remembering that the purpose of security metrics is decision support.
Measuring vs. Modelling
Using CVSS to steer remediation is nuts, ineffective, deeply diseconomic, and knee jerk; given the availability of data it is also passé, which we will now demonstrate.