As cyber threats become increasingly complex, organizations face mounting challenges in maintaining visibility and control over their external and internal assets. Traditional reactive approaches often fall short in identifying and mitigating emerging vulnerabilities across diverse environments.
Modern technology, especially Cyber Threat Intelligence (CTI), empowers enterprises to move from reactive to proactive defense. By integrating CTI with Attack Surface Management (ASM), organizations can achieve real-time visibility, contextual threat analysis, and prioritized response strategies.
Osman Celik, a research analyst at KuppingerCole, will outline the necessity of employing CTI in ASM solutions. The discussion will include best practices for proactive cybersecurity strategies, the impact of AI on threat intelligence, and strategic recommendations for organizations.
Gabi Reish, VP Product Management for Cyber Threat Intelligence at Bitsight, will demonstrate how Bitsight integrates CTI into their ASM solution. He will present best use cases that highlights how actionable threat intelligence fuels faster decision-making and stronger security outcomes.
Hi, everyone. Welcome to the KuppingerCole's webinar series.
Today, we are going to talk about why CTI is the game-changer in proactive ASM. My name is Osman Celik. I am a research analyst at KuppingerCole, and I've been working on ASM tools in the last two years. I have quite an insight now to share with you, especially when it comes to the use of CTI in ASM tools.
Today, I'm joined by Gabi Reish from Bitsight. Hi, Gabi. How are you doing? Hi. Nice to meet you. Nice to meet you, the audience. Yeah.
So, we are going to have a joint webinar today, and I'm going to start with some housekeeping to begin with. So, you are muted, and you don't have to control any of the buttons below, and we will have some polls and questions for you in this webinar, questions coming from you, to be exact.
So, we will have three poll questions, and you will see in the right-hand side down there, the polls, questions, and chat buttons. So, whenever we share the polls, please use the poll section to answer the questions listed there. You can answer them throughout the whole webinar. And when I finish my part and when Gabi finalizes his part, we will have a 15 to 20 minutes long Q&A session.
So, you are more than welcome to put your questions into the questions or the chat button, whatever you prefer. And at the end of the webinar, don't worry, we will record this webinar, and you will have access to all the slide decks and also the offline version of the webinar.
So, today the agenda is starting with me giving insights from my latest report and the role of CTI in ASM, and Gabi will cover what Bitsize offers, and then we will have the Q&A. All right. To begin with, yeah, let's have our first poll question, and then I will give you 10 seconds to answer this. Does your organization have an ASM solution in place today? Actively deployed in evaluation or proof of concept phase or no? Very simple question. And whenever we have time, we can also discuss the poll results, if time allows, at the end of the Q&A. All right.
So, in order to understand the importance of CTI in ASM, I thought that maybe we should start with what is CTI. And I was looking for a cool definition. This is the coolest definition I found. CTI is the evidence-based knowledge about existing or emerging threats, including context, mechanisms, indicators, implications, and actionable advice. CTI informs decisions regarding the response and prevention of cyber threats. The reason why I wanted to stick to the slide deck is because CTI and TI, which is Threat Intelligence, is used interchangeably, and both of them mean the same thing.
But when it comes to CTI, we need to understand one thing, and that crucial thing is that CTI is one of the perfect tools or platforms that can complement other cybersecurity solutions. Today, we are going to discuss its role in ASM, but I wanted to tell what other solutions are also using CTI or CTI feeds, let's say.
So, it could be a SOAR solution that is using CTI to enrich the incidents or the mitigations, or the SIEM trying to increase the accuracy of detection or the alerts, or any sort of detection and response tool like XTR, endpoint detection and response tools, or network detection and response tools, or replication fireballs that need some context of the threat intel data. So, we should always keep in mind that CTI is a very crucial capability for any cybersecurity solution out there today. And that's why we are kind of putting ASM and CTI together.
My expertise is coming from an ASM perspective, and Gabi's perspective is coming from Threat Intelligence management. So, we are going to see how CTI benefits from CTI. Just one more thing to clarify, by the way, when I mean ASM, it can also mean the Threat Landscape Management, Exposure Management, because in the market, there is not a consensus of naming their attack surface management tools.
So, in some slides or in your daily life, if you see Exposure Management or Threat Management, Threat Landscape Management, you will see that they are all related to ASM. And in my report, I had four subcategories of ASM. They were namely External Attack Surface Management, CyberAsset Attack Surface Management, which is CASM, and Third-Party Risk Management tools, and Digital Risk Protection tools.
So, keep in mind that you will not see the name of ASM or CTI as a standardized version to gain information. So, let's do some vocabulary now, and it will help us to understand what we are going to discuss in the upcoming slides.
So, STIX and TAXII, these are the protocols that CTI tools need in the purpose of sharing the Threat Intelligence in most cases, because CTI sharing is very important nowadays, and I actually had a couple of colleagues and friends working on their PhD thesis on this. So, this is something that companies and also organizations in the government, also from the public sector, that requires some attention. And STIX and TAXII protocols are helping with representing and structuring and sharing the threat information.
TTPs, tactics, techniques, and procedures. This is how threat actors or cybercriminals plan, execute, and refine their attacks.
IOCs, Indicators of Compromise. So, these are digital traces of any component you can think, and that signs a malicious activity. And when it comes to IOCs, we have to know that these can be also provided by your ASM vendor. And I would say from my observation from the market, there are some solid tools that are already providing out-of-the-box IOCs, and there are some vendors, which are very few actually, allowing you to create your own IOCs, custom ones. MITRE ATT&CK mapping. I am sure some of you have already heard what MITRE ATT&CK is, but what is its relation to CTI?
It's basically a framework that provides, sorry, it's a structured framework that provides mapping of adversaries' tactics and the techniques and procedures they use. And CTI uses this TTPs to classify, analyze this threat behavior and map this based on your attack surface. And in many vendors in my research, I've seen that they utilize it very effectively. And then it is kind of a quick access to your threat landscape. It's like a quick snapshot. And then this is very cool. The last one is dark web monitoring.
Not all the sensitive data or your cracked credentials are not in the surface web nowadays. So there are tools that are tracking the website that are in dark and deep web and search the forums and then the chat groups and also behave like one of them. Cyber Threat Intelligence teams from different vendors or different communities do that. And they also track these hidden surfaces of the web, let's say.
And last but not least, the global collaboration is something which, as I said, as I mentioned earlier, there's a huge demand from academia and also public sectors to see how we can actually facilitate the cyber threat sharing. There's a reason why I listed these collaborations and organizations. Maybe you might want to take a look at them. All right. So why do we need CTI in ASM? It is no different than most tools, but there is something specific to ASM in this slide you will see. So working with assets can be a tough job. Sometimes you have thousands, maybe millions of assets.
And either working with ASM or your asset management tool won't be enough to understand what assets are exposed or can be subject to a threat. So you need to contextualize your assets data and CTI provides that. The second one is maybe for me the most important one is prioritizing the risks that are identified in your system. And you need to figure out which one to remediate first. So CTI helps with that. The next point is you need to understand what your attack surface is exposed to.
And like I mentioned with the MITRE ATT&CK mapping, so you need to map your threats based on your industry, your prioritization and your organizational needs. And CTI also helps with that, too. The identifying threat actor and targeting trends are actually is something that we should all be aware of. And it is also highly relevant to this last point where I will talk about the strategic risk reporting. So CTI tools or feeds actually also helps you understand what threat actors are doing and what are they targeting nowadays? Which countries they are coming from? What are their motivation?
Like we are having this modern warfare nowadays. We had recent wars in the world and we have seen how cybersecurity was involved in that, too. So it is always important to keep in mind that the political and also geolocation dynamics are also affecting the motivations behind the patterns behind the threat actors. So CTI also helps you understand those motivation and patterns.
And another important point and also the theme of our today's webinar is being proactive when it comes to mitigation before being hit by the cyber criminals, before already receiving the damage and paying the cost of the incident. So CTI helps you learn about the threats and the threat landscape itself before you are exposed to it. I already talked about monitoring dark web and threat forms.
It's, again, important because then you are not limited with the surface web level information. And the other thing is like similar to mapping threats, you need to attribute the threat information you have because you might end up having lots of threat intelligence data feeding to your solution. But you need to also relate and also contextualize what it is. So CTI attributes the threat intel data as well. And like I discussed, some vendors are releasing the reports around threat actors and what is happening in the world.
And then they release these reports in the weekly, monthly, or yearly basis. And it's a helpful reference point for both executives, C levels, and also the technical people in your organization. So let me talk a bit about my latest research. It was actually a pure research based on ASM, not only CTI. CTI was considered one of the key capabilities of ASM. But in this slide, I would like to highlight why ASM solutions utilize CTI. So I wanted to first explain it to market drivers. Market drivers are like the reasons why CTI is becoming more and more integral to the ASM solution.
So like the main motivations of ASM vendors. So the number one is undoubtedly sophisticated cyber threats and targeting networks. We will discuss how sophisticated attacks are becoming more sophisticated, especially by the use of AI. So we will discuss this later. But this has to be kept in mind that the traditional vulnerability management tools are not just enough to stay up to date. And so you need to provide threat intel data constantly in real time for real time action as well to stay up to date again.
And the other motivations are like you have lots of sensitive data that you have to secure. So CTI will help you locate where it is shared or if it is shared, if it is exposed or not. So extra layer to DRP. So that's one of the reasons why I explained the sub components of ASM.
DRP, digital risk protection, is one of the sub component of ASM, one of the subgroups. So DRP tools help you monitor your brand in social media or also, again, in deep and dark web and prevents damage affecting your brands. So let it be a conversation in Telegram channel or, let's say, impersonation in social media like Instagram or Twitter, etc. So CTI solutions also feed you with this kind of threat intelligence data as well. And last one, it completes your ASM solution. And this is my point and my take in the report.
And the second part in the market highlight is kind of where I discussed the summary of the actions they take. It is not like you should not think that these are the actions that has to be taking as an ASM vendor or ASM user. But this is what is going on, basically. So based on my observation, ASM vendors are taking three approaches to work with CTI data. The first one is some vendors are using their internal teams and they utilize CTI data generated by these teams. The second one is the integrated CTI tools that are actually CTI feeds that are integrated the ASM solution.
And the other vendors are just providing connectors to third-party CTI feeds. The rest of the list is actually kind of similar.
So, for example, the vendors are collaborating with each other or the organizations for threat sharing purposes. Consolidated CTI enables you to enrich and also consolidate your internal CTI with external CTI in case you have internal teams plus an external feed. Risk scoring and prioritization and also real-time asset and vulnerability correlations are actually core capabilities of ASM. I will discuss this later on in detail. And there are also efforts to automate how to use CTI more effectively. And this is most of the time done by AI and ML tools.
Most vendors are having problems processing the non-English content. All since AI and human intelligent methods are used, all of these three combined. One of the biggest priorities of ASM vendors are to mitigate zero-day vulnerabilities. They highlight this very often. It's not because it's the only attack vector CTI serves or addresses, but this is one of the hot topics.
So, if you want to make better use of CTI, we need to understand how AI and ML is used. And in most cases, generative AI and agentic AI, which I will discuss in the next slide.
So, the reason is very simple, actually. We need a better management of CTI data because of its volume. And we need to also get rid of the hassle of manually analyzing threat intelligence data, especially when the volume and the context is too long to understand by your internal teams. We need real-time decision-making.
And also, we need to understand better threat actors because they can now evade traditional detection tools. And this will help us increase our speed and scale in our analysis of the threats that we might face. And the role of AI and ML is automating correlation and pattern recognition, identifying unknown threats and TTPs, and predicting attack paths and continuous learning. I want to elaborate only on the continuous learning. It's because it's the only part that might be unclear to you. Continuous learning helps your ASM solution to learn proactively about what to do in case of an incident.
So, if you have an AI in place, then you are not only based on the expertise of your internal teams. So, AI and ML can help you also implement the CTI data better. AI and ML in action, we can think like this. You have the role threat intelligence feeds or data from your internal teams, and you use the natural language processing extraction to make better understanding of it, correlate and enrich it with your threat data and your asset data. And then the most important part for me is you determine the scoring of your risk so that you can prioritize what is more important for you.
And then it leads to your remediation. And then here we see some AI tools are also helping with what actions to take and what steps to be aware of when it comes to remediation. The considerations, we should always be also aware of the pitfalls of the AI. There can be a model bias and data quality, and then there can be some false confidence in automated decisions, and you need to continuously retrain your AI and ML mechanisms. I will shortly discuss the Gen AI and agentic AI.
The reason is because I'm going to keep this short because I don't see that many vendors are neither using Gen AI or agentic AI. Maybe Gabi will have to say more about this. I think this is one of the strengths of BitSight, by the way. But I wanted to give a short overview of it. So Gen AI is basically a technology that is acting upon your request. So simply put, it generates outputs in response to your promise.
But on the other hand, agentic AI has the ability to minimize the human supervision, let's say, and it can act autonomously and it can also help you with decision making because it's goal driven. And it can be also set to work autonomously. So it has the memory and it has the ability to plan and act according to the plan. And for users, it means that you can continuously monitor your threat feeds. You can correlate your intelligence data. It means better protection against evolving threats, evolving threats with AI, actually.
And also it can also help you take actions with minimum human intervention again. But there are a couple of considerations we need to keep in mind as well, because these are technologies that still are not very common to see in ASM market. Both of these, to be honest, I've seen a couple of solutions deploying Gen AI, but agentic AI is something super rare in ASM market. So the considerations is we need to talk about some audit trails because then every decision and also the action taken by AI needs to be traced and reviewed. And it can be hard to keep the pace with it.
Your memory management should be up to date because then if you use the outdated information, then you can take incorrect actions. And the last but not least, your analysts and stakeholders has to understand why AI made a specific decision. So it has to be explainable. To wrap up my part, I think I am over my time, but I will summarize my part. So what are the key use cases of CTI in ASM? So I already discussed with the threat detection and response tools. And these are also part of ASM under the name of identification and remediation.
You try to understand the difference here, but it is part of threat detection and response. You have to prioritize your vulnerabilities. CTI really helps you with that. And as a customer, maybe after remediation, this is the second most important thing you should keep in your mind. Alert prioritization. You have a bunch of alerts that are coming to your ITSM solution maybe and CTI helps you prioritize them as well.
And like subcomponents of ASM, DRP and TPRM, there are also benefits from CTI because then you get also an overview of your supply chain risks and also your brand related intelligence. Well, I think we already discussed the trajectories and the geopolitical risk monitoring. These are also very important because then the pure ASM solutions does not really provide you that unless they have a good CTI feed connected to it.
And the last point I would like to say that threat intelligence is helping you with complying with regulations, especially when they are mapped against control groups coming from certain regulation. Thank you very much, Osman. And I also wanted to thank Kuping and Go. And we are very, very proud, Bitsight, of being recognized as a leader in the different categories of your research and reports related to 2025's leadership compass for attack surface management.
You know, what it really means for us is that we've been recognized with our strong capabilities that go beyond threat intelligence. It's about asset discovery and ASM capabilities, the threat intelligence integration, third party risk management that we have to offer. So we're very, very excited and we're proud of being actually recognized as such leaders. So I really appreciate the work, Osman, that you've done and we'll be happy to share this webinar and discuss and provide more details.
So maybe to discuss a bit about, I would like to start my presentation sharing a bit about who is Bitsight. And then I would like to provide my perspective related to threat intelligence as related to attack surface management. So if I go to the second, we have a problem here, small problem.
Okay, so who is Bitsight? So just in there, I want to show very short slides. Bitsight is all about helping security leaders rapidly identify exposures and detect threats. And the reason is in order to really to prioritize, communicate and mitigate these risks across the extended attack surface. We have been founded in 2011, our headquarters in Boston. We have offices in New York, Lisbon, Tel Aviv and Singapore. We have over 3,400 customers. We have very big investors. One of them is Moody's.
Some examples, we have four of the five different top investment banks in consulting firms, some of the companies there. And as you can see there, we have multiple recognitions. And as I said, we are very, very proud of being recognized by Cupica Gold as part of their attack surface report. And as part of the extended, it's actually the second year in a row that we've been recognized. So what is Bitsight all about and what's our vision? And our big vision is that with all the data and looking at all the data, we want to provide a data-driven approach to addressing the modern cyber risk.
And it's about combining real-time understanding of your attack surface on one hand, understanding on top of that, building on top of that, your business context. Because we understand that by just scanning your network, understanding assets is not enough. You need to understand the impact of different assets. That's the business context. On top of that, we have the ability to look at your exposures and vulnerabilities. And then on top of that, the threat intelligence. This webinar, we're focusing on threat intelligence.
But what cyber risk intelligence is all about is looking at the full attack surface management. The full combination of how, again, we want to address the cyber risk in modern organizations today. And how do we want to provide them with the relevant context for them to take action? I think the key word here is prioritization. Prioritizing what matters. And in order to prioritize what matters, you need all these different layers to actually understand the context, the impact, the likelihood, and relevance. And this is what we want to offer as part of our cyber risk intelligence.
BitSight offers four main solution pillars. First of all, we have an exposure management platform that offers you a very strong capability of predicting, understanding, and preventing related to different issues, related to different assets. We have our cyber threat intelligence platform and capabilities that offers you, provides you with strong insights to the different assets.
And many of the different things that Osman mentioned before, from OSINT to the deep and dark web, insights, ability to provide for multiple different use cases, good understanding of how your threat intelligence, what's your threat context as related to your attack surface. Third-party risk management. We have coverage of about 65,000 different enterprises and organizations across the globe, providing very strong insights to enterprises, our customers, to their third-party supply chain, to their customers.
What their vendors' security posture is once they decide they want to work with specific vendors. And last but not least, we provide for the governance and risk organizations strong analytics to understand the real truth, the real security posture and performance of themselves as a first party, but also third party. The way I look at attack surface and maybe augmenting what Osman was saying is that I see the aspect of attack surface as an extended attack surface. It's all about discovering and focusing on your threat exposure. And where we see the threat exposure is three different layers.
It's about the where. What are the different insights that you have about your attack surface and attack surface of your supply chain, of your third parties? And providing you with a very strong context for you to understand who are these vendors? What are they looking at? What are the different assets and what are the different exposures that you have right now that attackers are seeing? So putting yourself in the attacker's view or attacker's, what are they seeing? And then based on that, understanding your attack surface. The second part is the who, how, and when. That's a threat context.
So once you understand the attack surface, building on top of that good threat context is understanding and enriching your attack surface with understanding of your threat intelligence. Understanding what are the different assets that are most exposed? What are these assets? What's the likelihood of these specific assets to be exposed? And last but not least, how do you focus on these specific assets? That's the what? Prioritize exposure. And all of them combined together is all about prioritization. And it's expediting the mean time to respond by focusing and prioritizing on what matters.
That's what we believe and that's what we're driving. It's all based on three main technologies or main pillars of technology. The first one is our technology which we call GIA or Graph of Internet Assets. And that's our proprietary AI machine learning model that maps internet assets. The next is Groma. Groma is our technology for internet scanning. And like many of our competitors or other competitors of this technology, we don't rely on third-party sources. We actually are doing the scanning ourselves with Groma.
And finally, we have our BitSight AI which is our overarching AI infrastructure that accelerates threat intelligence, the collection, analysis, and delivery of intelligence insights. So these three technologies are what it's all about. I want to show some examples of how we are using these different technologies and how we're building our strong threat intelligence combined with attack surface today. So the first thing I would like to show you is how we're all combining the things together.
So what we've shared and you'll see in the report also that BitSight, as I said before, we have Groma and we have GIA that enables us to do the scanning and map the enterprises, any of our customers' assets, exposed or externally facing assets. And this is our ESM capability. When we combine the ESM capability with threat intelligence, then basically what we're providing now is attack surface intelligence. We are seamlessly mapping all of the assets that we found in our ESM towards our threat intelligence platform where we understand what are the different assets. We provide look and mentions.
We check all these different assets. Are there mentions in the dark web? We do monitoring of these different assets on the dark web. We look at them. And then what we do is we generate asset-based alerts in case there are mentions or in case there are specific vulnerabilities to these assets that have likelihood to be exploited.
So what you can see, we provide an end-to-end experience to our customers from the discovery and scanning of your enterprise and find information in order to provide you with the externally faced attack surface, towards attack surface intelligence, towards providing you with alerts and indications of specific mentions as related to these specific assets on the dark web or anywhere else. Another example is our vulnerability intelligence.
Because what we do is we provide to our customers today, we provide them with good visibility about the specific vulnerabilities that they are right now susceptible to. In this case here, this is vulnerability detection in our third party risk management solution. But also in our first party, we provide our customers with what are the key vulnerabilities that there's likelihood of you to be exploited. And in addition to that, what we provide right now is a threat intelligence context. We provide the DVE score. What is a DVE score? It's a dynamic vulnerability exploitation score.
It's vulnerability exploitation intelligence. This is a significant and unique score that provides customers with the information about the likelihood of that specific vulnerability to be exploited within the next 90 days. This is built based on a model, an AI model that we build in order to understand the chatter, the threat risks, and what a customer is talking about, what threat actors are talking about that specific vulnerability. So you can see here that we are prioritizing remediation of vulnerabilities with threat context in order to provide good prioritization.
And the last but not least that I want to talk about is AI. So Osman was saying, and I agree with you that many of the threat intelligence vendors are not significantly embracing AI these days, generative AI and agentic AI. But in difference with that, Bitsight, we've been doing that almost from day one. And specifically to generative AI since 2023, we've been investing a lot in AI, in generative AI, in different capabilities here. Some of the examples we are using AI for internet analysis. We're using it for internal analysis.
We're using it in order to analyze intelligence items, things that we are collecting, posts from the dark web. We're using it to summarize and provide good information about what we see in intelligence items. We're using it to generate new intelligence with finished reports about, from a sector perspective, industry, geography, personas. We're using it, and I'll show some examples. We're using it in order to provide a good user experience with providing you with assistance capabilities so that you can actually decipher the intelligence in an easy way.
And last but not least, we are using AI in order to provide very efficient collection. Because at the end of the day, intelligence is collection, analysis and delivery. So we are using intelligence or AI today in order to enhance and accelerate and expedite our ability to provide strong collection, which means that we are providing more data, more insights to our customers. So BitSight AI, which is our AI capability, is an overarching technology and infrastructure, which we are embracing across the entire platform in different layers. I'll show you some examples.
So this is our chat or prompt where customers can ask questions. We'll provide them with answers based on the unique data that we're collecting. We provide strong transparency. What Osman was saying, it's important to provide transparency to sources. What Osman was saying about privacy, we do that. So we provide references and links to the intelligence where we got information from. We have follow-up questions. We provide customers with feedback loops so that we can avoid and we can make sure that the fidelity of the data is critical. So we're spending a lot of resources, a lot of investments.
So we're providing generative AI and agentic AI in very, very powerful ways. Another example that I would like to show is BitSight Pulse. What is BitSight Pulse? We're using AI in order to curate the delivery of intelligence items. This looks very much like a Netflix sort of a concept where a Netflix and TV, what we're doing here, we're streaming content of CTI. We're streaming CTI context, and it's all personalized based on the usage and based on the user, what they're interested in.
So, for example, there's specific channels. In this case here, the customer was interested in ransomware, ransomware in the healthcare industry. And he was interested in cyber attacks in the UK. And we provide specific content with AI that is related to that specific channels of specific interests. So it's all about personalized content based on relevance and usage. It's all normalized with AI. We are structuring that from hundreds of sources, all powered by AI. And there are multiple different use cases and applications for this new capability, a part of AI.
So I would like to summarize my presentation. This was some examples, and I would like to summarize my perspective. As I said at the beginning, threat intelligence is a key component to attack surface management. Osman was talking about attack surface management.
And we strongly believe that in today's dynamic attack surface, where everything is consciously shifting, and there are more devices, more assets, more services, more cloud resources, and third parties, and it's all dynamically changing, you need a very strong attack surface capability that can discover, can scan, can provide you with good indications. But this is not enough because you need to prioritize what matters.
And if you want to prioritize what matters, and then to understand where you need to actually focus on, and you need to remediate, this is where threat intelligence comes into play. Because threat intelligence will give you the good insights that says, yes, this is all the attack surface. This is all different locations where threat actors can penetrate and get into your organization. But these are the places that, or these are the specific vulnerabilities that they're talking about.
So threat exposure, threat intelligence, combined with attack surface management is what threat exposure and what attack surface is all about, combining the assets, exposure, threats, and good business context. That's what Bitsight is proud of providing.
And again, we are super proud of being recognized by Kubernetes Go as a key vendor and a leading vendor in this space. Thank you very much. Thank you.
Thank you, Gabi. It was a great presentation. I really like the last slide you used when it comes to correlating these three pillars into the context. So we have two more poll questions. I will give you 10 seconds to answer each of them, and then we can start with the Q&A. So number second of the poll questions is, what are the challenges you face while implementing AI to your ASM solutions? First one is regulatory compliance. Second one is trust and confidentiality. The third one is lack of workflows. And if you have any other reason, then you can also mention in the chat.
So please use the polls tab to answer our poll questions. I see that people are answering already. And our next question is, what is the biggest challenge when implementing cybersecurity?
Budget, security shortage, wrong tools of choice, stakeholder management. We will discuss if time allows the results at the end.
All right, Gabi. So I have two questions from Alfred. I think I can start with the first one. Can you explain more about the dynamic vulnerability exploit, DVE scores? Yes. Great question. So DVE is all about what is the future. I would say it's the future, but it's all about predictive threat intelligence. Predictive threat intelligence is about understanding and trying to predict what's the direction and using threat intelligence in order to provide good predictions and good prioritization. What is the DVE model?
We've built a model based on understanding of mentions of threat activity in the different mentions, in different social media. A threat actor is talking about a specific CV. Is that specific CV exploited by 9-1-1? Is it trending in specific forums? Does it have forks or different metasploits or exploit kits on GitHub? And we combine them all together in order to provide the score from 0 to 10. And we update that every two hours. So that's very, very dynamic. And this is our score, which, again, it's all about giving you a score of the likelihood of a specific CV to be exploited.
And this is very, very different from the CVSS, because CVSS is giving you a strong indication of the severity of an impact of a CV, but it doesn't give you the dynamic information about the exploitation or the exploitability or the probability of a specific CV to be exploited. And that's what we add, combine together, based on threat intelligence and threat context that I just mentioned.
Yeah, I just wanted to also ask, you know, also in order to elaborate more on this question. So in the market, I see when there's either using CVSS, EPSS, or key catalog risk scorings, or a combination of these three, let's say. How does your dynamic vulnerability exploit scoring? Is it related to them, or how do they differ from them? So they are not... So our DV score is not reliant neither on CVSS nor on EPSS. It's not based on that. We are actually building our own model that we've seen over time. And we built this model in a way that we actually looked and checked it.
There's this very, very strong correlation between the score itself and the probability of it being exploited over time. So yes, there are the other, as I said before, CVSS is a good indication or model that talks about the impact of a specific CV. It's like a market standard now, yeah.
Yes, and we also share this with customers. We share both the CVSS and the DV score. But what's unique about the DV score is understanding, going to the different forums in a dark web, going to the different sources and using that in order to build a strong probability score or predictive score of that specific CV to be exploited, which is a bit different. All right. So our next question is again from Alfred. Thanks for contribution to the discussion, by the way. What are the future plans for integrating generative AI into the platform?
Maybe I can put some insight into this, and then you ask for this, Gabi. I think the lack of utilization of AI in general, not only GI or from the perspective of agentic AI, I think that ASM vendors should invest more into this area because it really helps with remediation, which is like the most important point that the customers cares about, right?
Yes, I very much agree. I think that AI in general, when you think of what the purpose of AI is taking many of the different, taking the heavy lifting tasks that are because of the volume of the data, are very complex to do that manually and actually automating things and providing you with insights. And we all know about it.
You know, when we do chat GPT or other things, we know on a personal life that when we use chat GPT, it's actually crunching a lot of giving us insights that used to be a lot more complex. And CTI, I think that intelligence is a perfect fit for that because when you think of the immense, the amount of data and to crunch all this data, the alternative to AI is basically to manually process a subset of the data. And if you're manually processing only a subset of data, you're missing a lot.
Now to the question of the future plans there, I think that what's interesting is that we are looking at how can we use AI and we're using AI overarching in different elements there, in our complete portfolio of insight products. So for example, I have an ESM solution. We have an ESM and we find specific issues and how do we mediate the issues? So we're using AI in order to forgive you with assistance and directions on how to mediate these specific issues. That's an example.
We're using AI right now to understand and it's one of the products that we're going to shortly come up with that based on your specific framework, if you care about NIST or DORA or ISO 2701 or whatever it is, and what are the different insights or different relevant insights based on the framework that you're based on, what are the specific insights and the issues that you need to resolve first? And we'll provide you with on-demand reports. A last example I would like to say, let's say your manager or your CEO or somebody from the board is asking you to generate a research report.
So on a specific topic related to TTPs or a threat actor, a ransomware group that you just heard about in the news. In the past, it used to take you days to build something. But now with a strong AI solution, which is attached to the data, threat intelligence data, it could really accelerate the power of you building a report on demand based on your interests, your needs. And on top of that, you can augment that with anything that you want to do then.
Yeah, I actually shared my take on the agentic AI, but you know that as a person from an analyst company, we are mostly exposed to the theory. So what we try to do is the practical part by looking at what vendors are doing. We look at their solutions as long as they share with us. And my personal experience with the use of agentic AI is very limited because I haven't seen it on action, actually only once. So I would like to also see what are your expectations? Where should we see the agentic AI in relation to ASM in general, not only in the role of CTI?
So I think that the agentic AI and virtual, and we already have our first steps in this space. Are super relevant in order to generate specific related content. I would like to say, with agentic AI, what is agentic AI? It's building or subsetting a task into multiple small tasks and building a workflow that the AI system can actually go and decide how to actually run the workflow based on the different scenarios.
Now, I've got multiple different examples of how we are using and how we can, we are already using and we can use agentic AI. For example, in the world of remediation and of taking action, and the topic of this conversation was all about taking from insights to actions. And to build good actions, building a good agentic solution and framework that understands the different considerations. For example, I've got a vulnerability. I would like to interrogate the agent that talks about the dynamic vulnerability, the DV score. And based on the DV score, I would like to take a specific action.
And I would like to run remediation. I maybe would like to mobilize or I would like to communicate with a specific EDR or a specific vulnerability detection tool. So there's multiple different facets of how you could use that from an actionability perspective. But just I want to say one caveat and it goes to what you said, Osman. There's a concept in agentic AI called human in the loop. Not human in the middle, but human in the loop. And I believe at least at the beginning, it won't be autonomous agent, agentic AI. It will be agentic AI with human in the loop.
Meaning humans will be involved in some of the decisions that agentic AI will be taking into consideration. And it won't be completely flawless or won't be completely transparent from a human perspective. There'll be human in the loop and some compliance issues then. Yes. But I think it's really, at least from my end, I'm really excited to see if it can help with the remediation. And that's also highly related with the other Siemens SOAR tools as well. Not only for ASM, but I think that this is something what customers could benefit drastically. That's my take on this.
But I'm really, again, excited to see in the upcoming years what's happening in the ASM market. If any vendor is offering, hope to see it coming from BitSight as well. But this should be something that the vendors all be keeping in mind for their future investments. That's my observation. This is an innovation that is missing in the market at the moment. All right. So we have another question. How does BitSight differentiate its threat intelligence from competitors?
So, to me, answering this question, I would say there are three points there. How do we differentiate in collection? How do we differentiate in analysis? And how do we differentiate in delivery? If we're talking about collection, we offer right now, up to date threat intelligence by automatically maintaining collection from the widest set of sources right now in the market. And that's critical and important because the wider that you can provide to collect data, the better the insights are.
And it's not only that, it's about the wider set of sources and we are adopting swiftly to customer needs all the time. So a customer needs more sources and all of that is automatic. There's no manual intervention on bottlenecks during the process. That's number one. Number two, analysis. We significantly reduce the response time to threats and we're using AI models to quickly process large amounts of data. And we're doing that in order to operationalize threat intelligence.
And again, there's no manual intervention, no bottlenecks. And last but not least about the differentiation, about the delivery.
We, from the beginning, we made it easier. We make it easier from a threat intelligence now with BitSight and the combination of ESM of BitSight and threat intelligence. We make it easier than ever to detect and respond to the imminent threats. By providing a very, very flexible delivery set of options for all different use case. And I think that, Osman, you mentioned some of the intelligence use cases. We understand that the different personas, maturity levels, and we are providing different, curating different types of delivery based on understanding all that.
So collection, which is the wider set of collection, analysis, all about providing, identifying threats. And last but not least, with delivery is addressing the different use cases, personas and maturity levels so that you can actually understand and it will be easier for you to proactively detect and respond to the different threats that are related to you as part of your attack surface.
Yeah, I just wanted to, I was just curious, I don't know if you have, know this information by heart, but when I was thinking about one of the edges you guys have is for me that you can process and collect the threat intelligence from different languages. Because what I see in the market is that, yes, okay, we can understand the threat intelligence data if it's in English. But what if it's in a different language with a different alphabet, like Russian or Chinese or Arabic? So what do Bitsight offers in terms of that?
All languages are completely transparent, so language is completely transparent to us. You can analyze, you can search, you can investigate specific intelligence items in Russian, Chinese, Arabic, Farsi, any different language, basically French, German, whatever it is. The main point is that we provide the capability, Japanese, if Bitsight is interested. Was there a case like that? Japanese hacker groups?
We have Japanese customers that are doing search investigations on ransomware groups that are related to Japan and they are searching specific mentions and brands that are related to Japan and they're looking at it. So, yes, we are completely language neutral and we provide a very interesting way of not only searching based on that, but any intelligence item we do an automatic translation and if you're interested in English, then we'll translate everything if it's in Russian or Chinese to English that you can actually look at. Just one question around this again.
This is also some of my interest. Do we really need an internal team, for example, understanding Russian? Or do we automate this process just by trusting the translator tools or the AI tools that are doing the translation for us? We have no... What is the second way, let's say, as of today's technology? What is the safest approach? The technologies that we're using are 99%, I would like to say, I never say 100%, strong reputation, trustworthy from a language perspective. We have a lot of track record with customers and ourselves, a lot of testing and verification.
All of our translation is all done automatically with the different tools and technologies that we have today. All right. Thank you. I'm just checking if you have any more questions. Maybe you can raise your questions.
Otherwise, it could be your last chance. We can go over the poll, maybe some of the answers in the poll if we have some good answers there.
Yeah, true, true. Let me just find that so maybe we can have a break on them. Thank you for reminding. Our first question was, what are the challenges you face while implementing AI to your ASM solutions? I will tell you the number one and the number second challenges. Lacking of workflows and trust and confidentiality came up as the biggest challenge. What would you like to say about this?
Well, yeah, we hear this a lot. And to me, there are three guiding principles of implementing what we've done implementing AI. Number one, privacy. It's very important that we do not put in different models, internal assets, internal domains. So privacy, number one guidance. That's number one. Number two, transparency. Transparency means two things. It means that we provide any time that we provide an answer, we provide them with what's the source of that. But also when we provide customers information, we also provide them with a chain of thought.
What was the process that AI came up with a conclusion? And last but not least, it's fidelity. We try to build technologies to avoid as much as possible hallucinations that come with these AI models. And that's so privacy and security. That's number one. Transparency and fidelity are what's guiding us.
And yes, we understand that. And we want to base on these three guiding principles to increase the trust of customers in using our AI models. Yeah.
I mean, like I did not answer to the question in order not to manipulate our audience's answers. But if I were to answer, I would also go with trust probably and also with clarity from my point of view, that I think that some vendors are afraid to implement AI tools simply because they don't know what to expect from these tools, how they would affect their overall user experience and how would they actually maybe create open ports and enlarge their attack surface maybe.
Can you imagine you're trying to have an attack surface management tool and then you're adding another layer of attack surface because you don't know what to expect from AI. And then maybe simply because of what to expect from AI is maybe blocking when there's to maybe invest in this area. So the next question was, does your organization have an ASM solution in place today? Out of our audience, 40 percent said yes, we are evaluating proof of concept phase. 30 percent said that we already have it and 30 percent said no.
I hope that we help our audience with our insights who are actively already implementing or haven't considered implementing one. That's like 70 percent of our audience today. But I mean, I hope we answered your questions today and you still have a couple of minutes if you have any last question. And the last question, last poll question, was about what is the biggest challenge when it comes to implementing cybersecurity? Number one was skills shortage and the second one was wrong tools choice. Would you like to elaborate on this? I think it's very clear.
It's always like the same problem, right? Yeah, it's picking the right tools, I think. And the biggest challenge right now is, again, shortage of skills. That's a big challenge in implementing cybersecurity. And that's why I think I will provide a good help and a good assistant. All right. I think then we are done with everything and I see no new questions coming. So I would like to thank you, Gabi, for joining me today. My pleasure. Sharing your insights. I would like to thank also Bitsight's team for making this webinar possible.
And a big thank you for the audience with their questions and also with their interest into our webinar. So looking forward to see you guys next time. Stay tuned and have a good day. Bye bye.
See All Locations
See All Locations