Collective Defense and Vulnerability Remediation
What is Collective Defense?
In short, collective defense is a means by which a group of entities band together to protect themselves from a common enemy. Its most celebrated and consequential application is probably the?North Atlantic Treaty Organization (NATO), founded in 1949 by the US and European countries to deter the expansion of the Soviet Union and its form of communism.?Ken Blanchard?wrote that “none of us is as smart as all of us”, and collective defense applies that sentiment to defense against a common enemy:?all of us working together are safer than one of us working alone.
What is Collective Defense in Cybersecurity?
The cybersecurity world is an ideal place for the implementation of collective defense, as it’s one of the few examples of a truly collegial and cooperative community united against a common enemy. Indeed, in a very real sense, the CISOs of Coke and Pepsi – two companies otherwise locked in a decades-long existential battle – are on the same team, and it wouldn’t surprise me if they collaborate. Fierce market competitors don’t typically revel in their opponents’ cyber security failures, but rather assume they’re probably next.
To date, there are a number of ways the cyber security community practices collective defense, including:
But an emerging technology is adding a new dynamic to the concept of cyber security collective defense, and it’s injecting a jolt of out-of-the-box-thinking into vulnerability remediation and patch management software, an area of cyber security largely bereft of innovation over the past several years.
领英推荐
Collective Defense and Patch Management
In the early days of systems administration, applying patches or upgrading software versions often resulted in disruption, and IT practitioners were therefore justifiably apprehensive about applying patches, whether they were security-related or not. Fast forward about 20 years, and times – and technology – have changed. Today, less than 2% of patches are rolled back (meaning the original software version – the one with the vulnerability – is re-installed to reverse a disruptive installation). Yet, vulnerability remediation teams continue to be apprehensive about auto-patching, largely for two reasons, one rational, and another emotional:
The only way to address these two realities is data. At present, the only way for a vulnerability remediation practitioner to gain insight into whether a given patch might be disruptive is to ask a colleague at another organization if they’ve applied the patch, and gain the benefit of their experience. Even better, contact 2 peers, or 3, or 10; certainly, an impractical approach to patching experience data gathering.?
But now, that work has been done for them.
The trackd Platform and Patch Management
trackd?is bringing precisely that patching experience data to the vulnerability remediation community, a novel approach to patch management designed to give practitioners the data – and therefore the confidence – to leverage auto-patching to meaningfully reduce their MTTR (Mean Time to Remediate), and therefore, the cyber risk of their organization.
In short, when a patch is applied using the trackd platform, data is recorded that illuminates the experience the user had after applying that patch. Several data elements are collected, but in a nutshell, whether or not the patch was disruptive is the bottom line. This data is then anonymized, and shared with all other trackd platform users, in real-time. Over time, many other users on the trackd platform will apply the same patch, generating 5, 10, or even 100 or more data points for a given patch, and hopefully giving understandably cautious remediation teams the confidence to make more aggressive patching decisions.
Ultimately, the concept of collective defense in the cyber security community comes down to sharing information, and the mutual benefit derived from that knowledge. Threat data has formed the bulk of that shared information to this point, but trackd’s platform is now extending that concept to the admittedly unsexy, yet absolutely crucial, world of vulnerability remediation.
Engineering leader at Apple
2 年The concept is fantastic, akin to medical clinical trials - known good outcomes of therapies (in this case remediations) should be shared!?
Principal @ South Park Commons | ???? Supporting Exceptional Early Stage Founders Globally ??
2 年Great read, as usual!