Introduction
In the world of retail that is heavily based on storing and analyzing customer data, security is paramount. Especially for those who have built their business on trust and loyalty. With the increasing digitization of transactions and the proliferation of online shopping platforms, the importance of robust security measures – for both risk mitigation and regulatory compliance demands – is higher than ever.
Exposure management and comprehensive security programs play a pivotal role in ensuring that sensitive customer information remains protected.
Faced with challenges that are scaling by the day, a global retail company turned to the Vulcan Cyber ExposureOS™ (exposure operating system) to overcome vulnerability data overload and reduce risk across.
The situation
- Many assets to manage and protect (60k+), which included over 90k+ vulnerabilities.
- Many types of data, assets and vulnerabilities from different sources – hosts, cloud resources, images.
- No comprehensive view of their exposure posture – prioritization, remediation, SLA tracking.
- Vulnerability scan data not correlated or normalized, making it difficult to deal with scale of risk.
- No effective way to report or communicate with different stakeholders on remediation.
The retail industry at a glance
The client’s environment comprised different types of assets of which 82% were hosts, 10% images, and 8% cloud resources. This information came from three main integrations (connectors) that the client added to the Vulcan Cyber platform.
Additionally, they connected collaboration and reporting connectors to simplify the way data and remediation tasks are exported within the organization.
To tailor the specific needs of the client, Vulcan Cyber developed a “CVSS vs EPSS heatmap widget” to determine the best approach to risk scoring, case by case, and enable better decision-making when it came to prioritization.
Read here to learn more about EPSS >>
The process
- The company implemented Patch Tuesday tagging to identify and flag relevant vulnerabilities.
- With the advanced Vulcan Cyber ExposureOS contextual capabilities, they leveraged threat info in risk scripts for vulnerability prioritization.
- The client built over 70 playbooks (automated workflows) and are currently running 77 remediation campaigns covering over 2,452,846 vulnerability instances.
The results
The most significant improvement the client saw was a 72% decrease in MTTR over the past year. We expect a drastic reduction in the number of high and critical vulnerabilities in the coming months. Meanwhile, MTTR reduction means risk is mitigated faster and more effectively, and remediation SLAs are met.
Vulcan Cyber for retail
Given the critical need for retailers to protect their digital operations and maintain customer trust, leading retailers use Vulcan Cyber to understand and reduce exposure risk across all attack surfaces. The Vulcan Cyber ExposureOS is designed to help information security teams aggregate, correlate, prioritize and remediate exposure risk from one platform.
See for yourself. Get a demo today.