
Cyber Rants · 2025-12-12 · 32 min
Key moments - from our scoring
Substance score
33 / 100
Five dimensions, 20 points each
CTEM marks a fundamental shift away from the commoditized annual penetration test - a compliance checkbox that Lauro likens to leaving your house for a year and checking only one locked door. The hosts emphasize that Gartner's framing of CTEM addresses real environmental changes: the cloud transition, distributed networks, third-party integrations (Slack, Cloudflare, AWS, GitLab), and the impossibility of maintaining visibility through vulnerability scanners alone. Traditional vulnerability management misses human error, misconfigurations, social engineering susceptibility, and integration failures (like Change Healthcare's MFA gap). True CTEM requires continuous, cyclical risk assessment - not just tools but human validation through threat hunting, adversarial simulation, and configuration reviews. The hosts clarify common misconceptions: phishing simulations via KnowBe4 aren't real social engineering, vulnerability scans aren't penetration tests, and 24/7 SOC monitoring is reactive, not preventive. CTEM is fundamentally about identifying material business risk (what's exploitable and costly) rather than drowning in trivial misconfigurations. This resonates with mid-market and enterprise security leaders tired of compliance-driven conversations and looking for meaningful risk conversation with business stakeholders.
CTEM (Continuous Threat Exposure Management) is ongoing, cyclical assessment across people, processes, and technologies, while annual penetration testing is a compliance checkbox often descoped to a single attack vector. CTEM catches risks that emerge between audits and addresses real-world threats like misconfigured third-party apps and social engineering, not just known CVEs.
Vulnerability scanners only identify CVE-matched findings and miss human error, misconfigurations, integration failures (like disabled MFA on GitLab or AWS), social engineering susceptibility, and third-party app security gaps - all of which require human validation and testing.
No; phishing simulations raise awareness but are not true social engineering, which is a multi-pronged approach involving multiple vectors and psychological mechanisms designed to exploit human trust. Real social engineering testing requires hypothesis-driven, comprehensive validation.
CTEM includes continuous configuration review and validation of third-party applications and integrations; human-led testing would have caught the missing MFA enforcement on external applications before attackers exploited it.
Yes; SOC monitoring is reactive (alerting after an attack occurs), while CTEM is proactive (preventing the attack before a log event is generated). SOC is one defensive component but cannot fulfill the full depth-of-defense paradigm alone.
Our reviewer’s read on each dimension, with quotes from the episode.
A few genuine practitioner observations are buried under heavy repetition and filler - the distinction between KnowBe4 simulations and true social engineering is worth noting, as is the point that CVE-less risks (misconfigurations, credential stuffing paths) fall outside scanner coverage. But the core argument is restated circularly throughout the episode without deepening.
your phishing campaigns through KnowBe4 or similar platforms are good best practice and you should absolutely do those. I'm going to go out on a limb and say that is not social engineering
you can't vulnerability scan the GitLab looking at a. Right. Your SOC is not going to help you there.
The hosts self-acknowledge they are not presenting new ideas ('we're not really talking about anything new'), and the arguments - compliance-driven security is reactive, humans are the weakest link, annual pen tests are checkbox exercises - are the industry's most recycled talking points. The framing of CTEM as a renamed version of existing practices is honest but itself a common critique.
our industry is better than any other industry that I've ever seen at coming up with new terms for things that we already do
we're not really talking about anything new. We're talking about just working more toward the ideal state, the ideal best practices
There is no external guest - both hosts are co-founders/practitioners at Silent Sector, a mid-market cybersecurity consultancy. They demonstrate hands-on client experience but neither brings the seniority profile (e.g., enterprise CISO, major incident responder) that would warrant a higher score on this dimension.
In fact, I think we just had this conversation yesterday or the day before with a client about this
Somebody asked me, we, uh, had a team ask us the other day, Zach, like, what are some things that you've seen
The episode is almost entirely abstract. The lone data point - '54% of breaches start with humans' - is stated without any source attribution. Change Healthcare and Cloudflare are namedropped in passing without any analysis. Recommendations remain directional ('scan more frequently,' 'do threat modeling') with no concrete timelines, cost figures, or case study depth.
54% of, of all breaches start with the human. All right, that's, that's facts. That's like there, there's been all kinds of data, um, matrices and things
Ask Change Healthcare how that worked for them
The two-host format generates no productive tension - both hosts consistently affirm each other with 'yeah, absolutely' and 'exactly,' and questions are leading setups rather than genuine probes. There is no pushback, no challenging of claims, and no moment where a point is meaningfully stress-tested.
That's a perfect. Which also right there.
Yeah, absolutely. You know. Oh, uh, well
Computed from the transcript - who did the talking, and the words that came up most.
On this episode, Silent Sector breaks down what cybersecurity really looks like beyond the buzzwords. We dive into CTEM and why continuous exposure management beats the outdated once-a-year pen test. You’ll hear how adversarial simulation, social engineering, and threat modeling work together to reveal real-world risk - not just compliance checkboxes. If you’ve ever felt overloaded by industry acronyms or wondered how organizations can actually stay ahead of evolving threats, this conversation brings clarity, strategy, and straight-talk insights from the front lines of cyber defense. Pick up your copy of Cyber Rants on Amazon. Looking to take your Cyber Security to the next level? Visit us at . Be sure to rate the podcast, leave us a review, and subscribe!
Transcribed and scored by The B2B Podcast Index.
Speaker A: Welcome to the Cyber Rants podcast where we're all about sharing the forbidden secrets and slightly embellished truths about corporate cyber security programs. We're ranting, we're raving, and we're telling you the stuff that nobody talks about on their fancy website and trade show giveaways, all to protect you from cyber criminals. And now here's your hosts, Zack Fuller and Lauro Chavez.
Speaker B: Hello and welcome, um, to the cyberrants podcast. This is Zach Fuller, joined by Lauro Chavez. Today we are going to talk about uh, continuous exposure of the environment and continuous testing of the environment. We're going to introduce a term that's been around for a few years, but we're going to be talking about cetim, continuous threat exposure management. And is it really different than what we've been doing for all these years? If so, how? And uh, where are the overlaps? Where are the parallels? So we're going to get into that today right after a quick commercial break.
Speaker A: Want even more Cyber Rants? Be sure to subscribe to the Cyber Rants podcast. Get your copy of our best selling book Cyber Rants on Amazon today. This podcast is brought to you by Silent Sector, the firm dedicated to building world class cybersecurity programs for mid market and emerging companies across the US Silent Sector also provides industry leading penetration tests and cyber risk assessments. Visit silent sector.com and contact us today.
Speaker B: And we're back with the Cyber Rants podcast. Lauro, it's good to be here.
Speaker C: Yeah, it's, it's good to be here. Zach, talking about ctim, AKA vulnerability management as a service, AKA continuous pin testing as a service. Do you have any other akas?
Speaker B: Oh there, there's so, there's so many. The interesting thing, so our industry, and I, I say this over and over when I'm speaking at, you know, on stage and stuff, our industry is better than any other industry that I've ever seen at uh, coming up with new terms for things that we already do. And then we pat ourselves on the back and go, oh, awesome, you know, look how cool we are. Right? Um, but no, I think, I think there's validity to this because I think there's um, it is, it is a new term and essentially a spin off of what we've been doing, but also kind of an evolution and just kind of a way to get people to think a little bit differently that I think is important now. In fact, I think we just had this conversation yesterday or the day before with a client about this, the, the once a year pen Testing. Do you want? Why don't we start with that? Talk about the traditional way, the way that most companies still do it, and maybe a little bit about why things have shifted and maybe that's not the best practice anymore.
Speaker C: Uh, a ye olde way of thinking. Ye olde pen test. Yol. We do it once per year as the tradition has been for the last 30 years. Yeah, it's, um, it's silly when I, when I look back now and think that anyone was ever okay with an annual pen test and just doing it once a year. And then all the leaders are looking at their pocketbooks going, duh. Right? We, we couldn't afford it. We didn't have the budget. But for once a year, uh, you're right, Zach. So, you know, I think the tradition has been a compliance based pen test. Right. Once a year was the de facto standard for a really, really long time, like decades and decades. Um, and I like to use this analogy, uh, and I pulled it out yesterday with the client, right? Would you go away? Would you take a vacation for 12 months? Right. You're going to be gone for a whole year. You're going out of the country for a whole year and you only check one door in your house that's locked. That's it. That's it. You're going to leave for a whole year and you can only check one door to make sure it's locked. Right. And nobody, anybody listening is like. That sounds so silly. But that's literally what we've been doing for decades with the annual pen Test. We wait 12 months, we descope it down to one web application or one external network, and we think that's good enough. And we've been okay with that. Uh, and in the background, the adversary is laughing at us, put on our clown makeup and leveraging our lack of visibility against us. Right. And so I think we've come to a point now, Zach, Is it fair to say that the old way of doing things is no longer relevant?
Speaker B: This is a new kingdom, ladies. No, I, I think so. You know, and, um, so of, of the best, uh, acronym and name creators, uh, among the best in the world is of course, Gartner. Right.
Speaker C: So they're the best.
Speaker B: Oh, yeah. If they name something, that becomes the standard. Um, and, uh, a few years back, 21 or 22, they coined this term, right. Semi. And um, they're looking at a couple different things. I think when you label something, when you name something, it becomes more recognized, it becomes more formalized and all that. So I understand the reasoning behind it. I just like to joke about them, you know, because we do come up with so many acronyms in this industry, like maybe worse than the military even.
Speaker C: So I'd say so there's an acronym for everything.
Speaker B: And you know I always like every day I'm hearing, hearing new acronyms in our space. So um, it's almost like you could be ah, a, you could be a scholar of acronyms in the cyber security world. That's all you could do is study acronyms. But I think what they're doing, they're taking into account some, some shifts in the environment that are long over. They've been happening for a long time. It's not like this is absolutely news but. Right. We, the, the transition to cloud, um, a lot more externally facing environments. Right. A lot less um, containment. Right. So we've got distributed networks, we've got a lot of cloud environments, we're using a lot of third party applications across the board. Um, all of these things are creating a ah, very uh, or have created a much more difficult environment to maintain visibility of. Plus um, the tech teams, especially IT teams and mid market companies and such like we work with, they're always strapped thin as it is. So to try to continue to keep um up with vulnerabilities is tough. But it's even tougher when it's the once a year exercise where it's like whoa, look at all this stuff we have to fix. That's a pain for anybody. And even if they're doing it quarterly or whatever, same thing. So I think the idea in a lot of cases is let's just chip away at this kind of day in and day out and get this into a cyclical activity and an ongoing practice and bring it all together. And then finally um, and curious to hear your thoughts. But I think the other thing too is that like you said, uh, the once a year pen test tradition, ye olde pen test has um, it was very much for compliance and it's become very commoditized, very much check the box activity. That's why we are transitioning to the term more adversarial simulation. Right. Of true adversarial simulation. You don't. That's not something you can just check the box if you're staying true to the essence of those words. Whereas a penetration test has become very much commoditized. So with that um, I think it's that, that ongoing, that ongoing exposure but also m. A broader exposure. Right. So whereas the pen test, the commoditized pen Test approach is really just looking at one attack vector. Whereas if we're really looking, doing true, let's call it continuous threat exposure management. Thank you, Gartner. Right. Or whatever you want. Whatever coin you want to term. We should be looking at the environment more holistically, meaning across people, processes and technologies, not just a, uh, tech look at one specific attack vector. So.
Speaker C: Exactly.
Speaker B: I'll, I'll pause there. That was my rant for right now. What are your thoughts?
Speaker C: Yeah, sure, I'll jump in here. I think that any real true cybersecurity practitioner would say that we're tacticians and we're supposed to secure the environment and that we, we look at an organization from a risk perspective just by the nature of our profession. Traditionally the business up until this point has been looking at that problem through a compliance lens. And compliance has always been the driving factor of additional security this or additional security that. Very few companies were like, oh, cybersecurity, that's a brilliant idea. Let's be proactive. They're like, oh, let's wait until they rip our band aid off at the compliance audit before we do any of this stuff. Right. And that got the industry through for the last 30 some odd years. Right? And now things have changed. Right? The uh, I don't want to be throw another weird cybersecurity industry term. Right. But, but the, the attack surface. Right, and the risk surfaces have all changed. Right. AI has helped advance to that, but it has been changing and companies are now forced to look through the lens in which they should have been looking through originally. The tacticians lens of how do we make our organization secure, not just wait until compliance tells us we need to do an extra couple of things. Right? Because let's be honest here, right? At rest, encryption is not going to stop you from a ransomware attack. It's not going to stop your data from being stolen. It's only going to protect you if someone steals a laptop out of the back of a car or figures out some way to get into your data center and find out what drive all your data's on and takes it. Right? So these compliance components are going to make us do things that are absolutely necessary in the defense in depth paradigm. Right? But they're not tactical. They're not stopping the bleed today or stopping the exposure today. And you mentioned something very important, Zach. We've, we've coupled our businesses with external third parties. We have git labs going on with our web applications being managed by third party. Um, we're throwing cloud flare. Thank You Cloudflare for breaking everything recently into, into the play of things. Right. We've got, um, you, you know, companies are using Slack, they're using the Microsoft or Google ecosystems. They have a lot of things intertwined. And a vulnerability scan is not going to capture all this stuff. Right? Continual vulnerability scan, absolutely. Uh, an important element in the CTIM space, but won't capture everything. And likewise, leaders need something more to talk about than, hey, We've gone from 30,000 vulnerabilities to 10,000. Right? That doesn't. Are you making progress? Yes. All my patching folks out there, you're doing an outstanding job. I'm so sorry that the, the weight is so hard right now. Um, and, and there's a podcast, we talk about risk, you know, re ranking those vulnerabilities. Right. Risk, re ranking. Um, uh, but, uh, to, to digress back here, you can't just go to leadership and say, hey, we've, we've got, we've got. We've gone from 30,000 vulnerabilities to 10,000. You need to have an impactful conversation about what our risk exposure is. And the vulnerability scanning alone is not going to give you that. You need to be doing some holistic testing and validation of some form CTIM or whatever acronym you choose. If you can beat Gartner, good for you. But that's what needs to be occurring in order for you to maintain a really true, resilient, uh, hardened environment. You need to be looking at those external interfaces of the business and those external risk points and risk factors at all times, as much as possible to give you that holistic picture of where my risk is today. Right. And that could be with a not enabling MFA on some third party app that the IT team's using. Ask Change Healthcare how that worked for them. Right? So it's very important that we're not just scanning vulnerabilities, we're doing human validation of the vulnerabilities we're looking for. I hate to use another industry term that I just attest, threat hunting. Right. But we're hunting for risks in the environment. Right? Misconfigurations. Making sure that change management is, and this is part of ctim, making sure that change management is being effective and you're not throwing changes out that aren't being reviewed and now getting picked up in CTIM activities. Right. So the time has come for organizations to stop living in the old time of the compliance pen test. And if you really want to be relevant today and you want to be resilient from M attacks in 2026, you're doing some form of continual management of risk and you're moving into that upper right quadrant of risk management excellence, right? If you're looking at our data sets that we have our Gartner chart, right, Our silent sector quadrant chart, moving into that top right quadrant. You have to be doing this continual stuff because, um, doing just the compliance, bare minimums are no longer going to be satisfactory, um, especially if you, if you want to stay in business in the future. Because the, the attackers, the adversaries, they are certainly not waiting for once a year to, uh, review your risks.
Speaker B: So wait, they don't, they don't wait till after you've completed your latest audit and it was successful and you've got everything wired tight and cleaned up. They don't, they don't wait for that time to attack.
Speaker C: That'd be so cool. It'd be so cool if they did that. They'd be cyber bros if they did that. They're not. No, they're dirtbags. They're absolute dirtbag scoundrels and they're gonna catch you at your weakest moment because they smell blood.
Speaker B: Yeah, absolutely. You know. Oh, uh, well, and I think we, we have to reiterate too because, uh, a lot of times, you know, traditionally in a lot of the industries, uh, a lot of, A lot of companies still think about, um, vulnerability management as basically shoring up their risk exposure. So in other words, if it's a, it's, if, if there's a CVE associated with it, then that's, that's a risk. And if they've covered that and they've patched and they're good, but they forget about, you know, all their system configurations, email security, stuff like that that the, the scanners aren't going to pick up. Right. And there's not necessarily a CVE out there matched up for it. It could be human error, it could be, um, uh, susceptibility to social engineering, things like that, um, that aren't always picked up by a tool. So as much as we'd like to automate away the full, you know, continuous threat exposure management world and just pay a SaaS service to do it, unfortunately it doesn't work like that. It is going to require some human involvement throughout. Now there's a lot that can be automated, which is great, but we also need, you know, to have some boots on the ground, whether that's something you're doing internally or bringing in a third party for, um, you know, make, make sure that you're continuously looking at, um, the organization, uh, holistically, that whole attack surface, not just what one or two tools are throwing off, um, for you. And, and I don't want to go off too far on a rant on this. Just because you have a 24.7sock monitoring service, that doesn't make you more. That's. It's too late. Right? Right. When they're, when their bells and whistles are going off, it's too late. That's great. If nothing against those, uh, it's part of a security program. But I've, I've had too many conversations with organizations that think that, oh, well, uh, I'm just gonna. This sock service, they've been pitching me this product and this tool and it's like, yes, it can be great as part of your security program, but they are seeing it as holistic answer to security, which it is not. So just one component note there.
Speaker C: Yeah. And I want to jump on that and just say that once a log event has been generated, an action has occurred. That is not good. Right. Anything. Well, not always. Right. Log events are generated for all types of things. But if, if a log event is generated, it goes to a sock team and they're alerting you of an incident, something's already happened. And it would have been way better to just stop them from being able to create or generate a log event. Right. Be proactive about it. The SoC is a reactive component to help you in an incident, but they cannot in their own stop it or fulfill the whole paradigm of defensive depth.
Speaker A: Right.
Speaker B: Here's another thing I want to throw into the conversation, and that is when we think about, uh, threat exposure management, it doesn't. Regardless of if you're doing the yield once a year pen test or continuously and you've put it into cyclical activities and all that. We are not looking for all the stuff that tools throughout, trivial misconfigurations and all that. We're looking at what's real risk to the business environment, what's a material threat to the environment that can actually cause harm. That's the concern. Right. So. And a lot of organizations aren't getting to the root of that. They're getting so much data that it seems just absolutely overwhelming as opposed to getting to the root of what is actually going to be exploitable, um, in their environment in a way that's going to cost them money or reputation or system outages or whatever, you know, whatever it is, but something that's a real risk. Um, I don't know if there's anything you want to add on that note, but we.
Speaker C: Well, you can't vulnerability scan the GitLab looking at a. Right. Your SOC is not going to help you there.
Speaker A: Right.
Speaker C: Your SOC is not going to help you understand a misconfiguration that one of the developers made on an AWS thing. Right. So you have to. And maybe they can. Right. At full final boss evolution of a SOC and you've got everything intertwined even through APIs and external resources. Right. There may be a way to do it, but we just don't see companies that are that mature with it yet. Right. They're doing, you know, doing host logs and things like that. Right. They're, they're not really integrating third party components to it. So it's important that you back everything up with a test. Right. If I just like to throw it back to the science. Right. You can throw your hypothesis and go test it. So we're, we're training users to, to prevent phishing attacks. Right. Let's just an example. We're using a training program like no before and we're sending them simulated fishing every year or every month or every quarter. Right. Every frequency you're doing at yield timeframe that you pick. The important thing is to. That's a hypothesis that we're assuming that they're going to accept this training, understand this training, apply this training in all situations. And then you have to go and test that by doing a CTEM exercise with social engineering and test those humans as part of that. Hopefully not ye annual pen test, but if it's a ctem, maybe once per quarter certain individuals get, get included as part of that social engineering exercise as part of that adversarial simulation and they get focused on it. And then maybe the next quarter all of the third party apps get not only um, a review from the penetration test or adversarial sim team, they also get configuration review from the architects. Right. As part of that exercise so that we're looking at the configurations and make sure that they meeting our standards. Or are they missing a couple things like mfa? Right. Or maybe SSO is not reaching them or maybe they're integrated into sso but you can still get to the app without having to go through SSO and you need to enable MFA there so you don't get credential stuffed. So there's a bunch of other variables that come in. Uh, as you said Zach, to just vulnerability management. Right. You can't assign a CVE to everything. Um, unfortunately the idea behind C Tim is taking human Intelligence and applying it to the entire business's risk exposure and trying to understand where the important fires that need to be put out are right. And you can't do that with a scanner alone. You can't do that with a sock alone. You can't do that with endpoint protection alone. And you can't do that with just a single pen test.
Speaker B: Yeah, absolutely. And to touch on the human element piece because that's so critical. Um, your phishing campaigns through KnowBe4 or similar platforms are good best practice and you should absolutely do those. I'm going to go out on a limb and say that is not social engineering. Nobody is engineering a way to really um, uh, exploit you know, human trust. And, and they're not, they're not putting in these different mechanisms. Social engineering is a multi pronged approach. It's not just one email, it's not just you know a ah, text. One text message in a vacuum. There are multiple components that come together to create an experience for a human to. That, that pushes ah, them into doing something they wouldn't otherwise do. So um, the reason I bring that up is I have heard that a lot. I ask you know, organizations and tech leaders. Well you know, what are you. So what are you doing for social engineering to test the human element? They say oh well we're good. We got um, we, we have phishing emails go out monthly to our, to all the staff. It's like well that's, that's good make them aware of that. But it, that's not a social engineering campaign either. That's, that's like. That's equivalent to calling a vulnerability scan a pen test. In, in my.
Speaker C: That's a perfect. Which also right there.
Speaker B: Right.
Speaker C: It totally happens. Absolutely that happens. Should not happen. Some reason it happens.
Speaker B: That's yeah. Um, but um, but yeah that's, but anyway I, I share that just because that's our, that's our focus of the show right Is to help people navigate through the weeds and understand what's what in this environment because there's so much stuff out there, so many acronyms that um, you know it's, it's hard for people to, to uh, comprehend sometimes and, and you all have lots on your plate as it is. So to, to. Let's, let's cut down to the basics of what works. You know and I do say that a lot is, is. It's the fundamentals are what are. Are the most important or what works every time. Right. And in, in, in. In a combat situation it's shoot Move, communicate. If you've got those three things down, your chances of success are so much greater, uh, than if you're missing any one of those components. Right? So get the basics down, get the fundamentals down and let's try to cut through some of the noise, um, out there that's, that's in the industry. Um, I applaud everybody for coming up with new, you know, lenses and new approaches and things like that. But we also have to kind of build bucket the practices into what they really are and just remind people that hey, this is, this is nothing new. This is just an evolution of best practices. And to be fair too, a lot of companies have been doing this for many, many years. The most proactive organizations have been doing this. They say, you know, look, risk is something that's ongoing. It's not just once a year. We've got to continue to understand it, you know, modify and grow with it, um, as we go. So highly proactive companies have been doing, you know, continuous pain pen testing. They're um, you know, constantly finding different ways and red teaming their, the organization doing their configuration reviews, doing their um, you know, looking at um, their accounts and things like that just to make sure that they have checks and balances in place so that things aren't falling through the cracks throughout the year, um, between when they do those checks. So with that, um, before we wrap up here, Lauro, if we're looking at 20, 26 and somebody wants to get a better handle, maybe there, maybe uh, those listeners that are in that ye old tempo and that's okay because most organizations still are, um, let's say they want to get more proactive and get more of a CTEM program going or just, let's just call it, you know, uh, continuously assessing and addressing their risks. What recommendations would you have for them to, to get started on that path?
Speaker C: Yeah, great question. So number one, you know, I think you, you hit the nail. Right? Right. Dead center. Good sir. One swing with the social engineering. Fishing simulations are not social engineering. There's a multi staged approach that we'll go through to you have people are skeptical today, Zach. You got to work hard to convince somebody. Just the yield email with the yield link that looks yield suspicious is just not good enough. Right. You've really got to betray the trust of humans that you're inter, you're going to interact with and test. Right. So specialized teams that do this. But I, I'll say that's probably one of the most important things that you should focus on for continual, you know, Risk management or CTIM or whatever you're
Speaker B: going to call it.
Speaker C: Right. Um, because 54% of, of all breaches start with the human. All right, that's, that's facts. That's like there, there's been all kinds of data, um, matrices and things that have been done. There's an overwhelming majority that have, ah, figured out that the humans are the weakest link and they're going to give you the most direct access. Right? Because as an adversary, the most important thing you really need is an account, right? To do, to do damage, you need an account. Right? And so it's hard to get that account by kicking through the door on a technology. In some cases it's there, but it's harder to find these days in 2020, you know, six. So humans are still guaranteed they have an account. You know, they do. They're operating with it. Right. So I think, number one, plan some social engineering, continual testing with your humans, because unless they're repaired, you have to understand what you're up against. I think that's, maybe that's number one, Zach. Understand what you're up against here, right? Like, you have to understand that the cyber adversary doesn't have an allotment of time. They don't have a scope, they don't have a money, uh, limitation. If they, if they want you, they will just spend the time and the time and time. Right. So it's important to understand all the elements that they're going to use to go after you. So understand, understand what you're up against first. Number two, understand that 54% of that is going to come after your humans. Test your humans. Right? And then second to that, everything that you have exposed, uh, network infrastructure wise and specifically web application wise, make sure that you're looking at that more frequently than once a year. I think that it's, it's. We probably kicked that dead horse a couple times. It's still dead. Uh, the yield pen test is not just going to cut it anymore. Right. I understand there might be a money, uh, situation, but look into options for a continual monitor, at least continual vulnerability scan to give you some idea of what that surface looks like and include those web applications. Okay. If you're, if you're doing, if you're agile and you're scanning your web applications once per year, shame on you. Okay. You, uh, Somebody asked me, we, uh, had a team ask us the other day, Zach, like, what are some things that you've seen? You, uh, know what big mistakes companies make and big egregious exploits that we find. And I shut that all down by saying one thing like you don't even have to worry about these horror stories if you'll just do mature change management and make sure that you're checking all the changes for risk impact and scanning your web applications before they go to prod. Right. Um, or before they get exposed in dev for testing little uh, things like that, um, you don't have to do so not to use another term, practice devsecops, ensure that you're continually testing your humans throughout the year and number one, understand what you're up against here and that there is no time limitation or money limitation for the resources that the adversary has. Um, and I know a firm shameless plug uh, that does CTIM pretty well and as can get you in that top right quadrant of risk management excellence. So you know, you can always contact them if you wish.
Speaker B: The shameless plug. Absolutely. Um, yeah. And then, and then I'd back that up with I think another thing that a lot of organizations don't um, have a good handle on. Surprisingly they, they do in their heads. Right. But a lot of, a lot of organizations have not documented their actual attack surface and, and their, their full environment. Right. Of course, um, of course modeling software inventories are your first, you know, your first requirements of just about any framework. Right. But truly um, understanding you know, what that looks like from an exposure perspective I think is going to be key to um, knowing what you have and in order to uh, be able to better monitor it and protect it.
Speaker C: Uh yeah, modeling I don't think is mentioned in CTIM very much. I don't think Gartner really, really talks about the importance of threat modeling. But threat modeling the environment is going to be key to understanding where all this. We have to do a, you have to do some form of a uh, discovery. Right. Uh where the risks are. Right. And, and you know the threat modeling exercise can, can certainly get you there.
Speaker B: Yeah, yeah, absolutely. Gotta, gotta start, start there and then, and then know the lay of the land. Um, but, but yeah, I think, I think we've um, I think we've covered it pretty well and I think the biggest objection of course is if with mid market and smaller companies is budget. Right. Because well we, you know, we can't afford to do continuous pen testing and all these activities. Um, and that's fine but the, the point is it's about progress. It's not about perfection. Right. We understand everybody's working with limited resources, so um, it's incremental. What's the next thing that we can do a little bit better to have that ongoing risk reduction, um, that observation of risk, that monitoring and then that reduction, um, and what are the different components that we can put that on? So for some it might look like we, you know, starting like you said, with that continuous web app vulnerability scanning for example, and then maybe adding a couple social engineering layers in things that you could even do internally, uh, with, with the organization. Um, but, um, and then, and then of course your change management and all of that. But um, start, start where you can make it incremental. Nobody, nobody expects an organization just to go to this full blown, you know, constant testing, assessment, you know, remediation process. But it's something that can be built into operations over time and be fairly streamlined, um, and relatively cost effective when it's, when it's done, uh, correctly. So um, it's not a, it's not a reinvention. We'll go back to, you know what, we're kind of where we started. We're not really talking about anything new. We're talking about just working more toward the ideal state, the ideal best practices. And I think that's the, you know, the underlying essence of what needs to be done with any organization, whether it's in. And that's, you know, of course true in your cyber risk management program, but really any area of business. Right. Always looking to improve, so incremental changes, you know, a little bit every day. Um, and uh, yeah, that, that makes it more likely to get done instead of just that, you know, one looking at it as one huge project with a huge cost basis and all of that. Um, take it a piece at a time. So. And yeah, like, like the shameless plug. You know, we know somebody who does this stuff every day and can help you with that if you need it. But with that, any last words of wisdom? I, you know, I think this is our last podcast before Christmas. So um, I guess wish everybody Merry Christmas and Happy holidays and Happy New Year.
Speaker C: So yeah, absolutely everybody hopes you have a Merry Christmas and a Happy New Year. We'll see you in 2026. Um, no final thoughts. Everybody have a wonderful holiday and Merry Christmas to you out there. We'll, we'll see you in 2026.
Speaker B: Outstanding. Well, thanks for listening to the Cyber Rants podcast and be sure to share this information with the people who need it. This is, this is our mission. Um, you know, our mission as a company is to protect the backbone of the American economy and our way of life. And education is one piece of that, that we do. So we'd like to get out, get this information out there, help us do that, and reach out for, uh, future topics that you want to hear about. And again, Merry Christmas and enjoy the holidays. We'll see you, uh, in the new year.
Speaker A: Pick up your copy of the Cyber Rants book on Amazon today. And if you're looking to take your cyber security program to the next level, visit us online@www.silenceector.com. join us next time for another edition of the Cyber Rants podcast.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.