Mitigating Vulnerability Weaponization with VulnCheck’s Tom Bain
VulnCheck chief marketing officer Tom Bain discusses how organizations are using VulnCheck to mitigate weaponization for virtually any vulnerability.
Transcript
This is Textron tv. Hi everyone. Welcome back here, the Textron tv.
Um, our next guest, well, it's almost RSA time, you know, we're making our list and checking it twice. Uh, our next guest has an RSA theme, uh, discussion we're gonna have. But let me introduce him and his company to you.
First, I wanna introduce you to Tom Bain. Tom's the CMO over at a company called Vol Check. That's V-U-L-N-C-H-E-C-K.
Hey Tom, welcome to Text Drunk tv. Thanks for coming on. Hey, Alan, thank you for having me.
Ah, it's our, it's our pleasure. So, Tom, you know, as I often do, before we jump into the company and what we're gonna talk about, our audience likes to know who, who it is that's talking to them. So, and I do too.
Why don't you give us a little background? Sure thing. So, uh, so Tom Bain, chief Marketing Officer, Volek, um, as you, as you said, I wasn't born that way.
So a little bit about my background. I've been in cybersecurity probably 20 plus years at this point, from marketing for about eight different cybersecurity startups, um, across database security, network security, endpoint security, a couple of times security training, third party risk, iot security, and now, uh, as we say at Volek Exploit Intelligence, um, Excellent. At, so what, well-rounded cyber background, we call that, huh?
Yeah, I, I think so. Uh, you know, it's interesting because you can touch, you can touch a lot of different areas of cyber, right? And be almost an expert by not quite a total expert, right?
When you're, uh, when you're at the marketing seat. But it's great because I think what I've seen is like this, this almost this, this like curve of, of innovation happen in cyber so quickly. And I think that over the past, like two to three years, it's really escalated, right?
And I think it's starting to collide with a lot of the forces in the market where, you know, organizations, even big organizations are looking for really different solutions that are going to help them build some efficiencies. Um, so it's, it's been cool to see that. Excellent, man.
Um, let's talk about v check. Give us the background there. Yeah.
So at, at v Check, we're an exploit intelligence company. So we help, uh, we, we have a large, we have a rather large tam, which is great, like as a marketing person, and I'm looking at measuring my ICPs. We basically have product, basically products, cybersecurity products where we basically put our exploit intelligence into some of the most widely deployed cybersecurity platforms in the world.
Uh, we also have enterprise customers, so we help enrich those workflows, uh, for enterprise teams. And we have a bevy of federal customers as well too, who use our exploit intelligence and, and, and the broader set of our solutions for a lot of what they're doing in terms of protecting the nation and protecting critical infrastructure. So we've got a really large, we've got a really large market, and that total adjustable market is, is significant, right?
It's the first time as a marketing exec that I've ever really had that large of a market and not just like some like little niche of cybersecurity. So you, you mentioned the phrase exploitable. Can you say, repeat that again?
Sure. Yeah. E exploit intelligence, and I can give you a little, I can give you a little background on, on sort of what, how we define that.
Yeah. Let me, so, so Tom, I'm, I'm in security 20, 25 years myself. Back in 2001, I started a company called Co-founded a company called Still Secure.
And we had a vulnerability management com, a vulnerability management play, uh, and as well as the network access control. So I'm, I'm familiar with, you know, vulnerability management and, and, and, you know, what's, uh, what's uh, accessible, what's exploitable, et cetera. When you talk about this, how, how is that different than kind of traditional vulnerability management?
Sure. No, that's a, that, that's a great question. So I think where, where V Check sort of is, I think where VUL Check is delivering its innovative approach in this area is we're doing two things.
Number one, we're taking almost a coalescence of vulnerability management and threat intelligence and really smushing it together. There's, you know, $26 billion spent combined in those, in those two sub-sectors of cybersecurity, Alan. Um, and what we have realized, the second thing is it never managing those vulnerabilities and being able to prioritize those vulnerabilities and having awareness of those vulnerabilities, even it's never happened fast enough.
Because what we're seeing is compared to about five years ago, it was taking a year on average for any vulnerability to ever be weaponized and then exploited in the wild and, and maybe not even exploited in the wild. So we've, what we've seen is low performing security teams have really never suffered any consequence if they, if those vulnerabilities remain unpatched. But that's shifted.
And now it's about eight days on average for any run of the mill vulnerability, not just a celebrity vulnerability to be weaponized and exploited in the wild. And it's very easy to, for any attacker to just go right to GitHub and pull that exploit code down. And that's what we're seeing now, which is the vulnerabilities if they're disclosed by a vendor, um, you know, name, name your vendor, like a Microsoft or Apache or in the OT world, like a Siemens or something like that.
They're just seeing those vulnerabilities be disclosed by the vendor they can go to get and go get it. And now all of a sudden they can build an exploit against it. It's become easy and the economics have changed, is a lot cheaper now too.
Sure. Now there's two aspects regarding that. One is, I, I think that has driven a lot of the automated remediation activity that we see in the market.
You know, back when I was at Van, right when I was at Still Secure and we had our van vulnerability assessment and management tool, um, there were, there were patching, you know, Citadel, Hercules comes to mind 'cause they were huge in and, and DOD um, you know, they were solutions available, but there was a lot of resistance because the real issue was, it wasn't just finding out your vulnerabilities, it was until I approved the patch, I, you know, ran it in the lab, made sure it didn't break anything. It could take 30 to 90 days or water to roll up to roll up a remediation out. Um, I think because of the speed to exploit today, people are much more into or much more accepting of automated remediation.
I think part of it is also, 'cause we've all gotten so used to our apps being updated in the background constantly. Yes. And, and so, you know, you slip a few patches in there too, who knows the difference, uh, kind of thing.
And then, you know, it goes, it goes down easier, let's say. Um, I think the second thing though is there was always this distinction that the better vulner, the more sophisticated vulnerability, uh, folks had between what was existing exploitable and then what was reachable, right? Yes.
Just because you have a vulnerability doesn't mean it's necessary. And there might be an exploit in the wild for it doesn't mean it can reach you. And, and, and then, so that whole sort of network mapping attack strategy, um, think not Sky High Networks, sky Networks, giddy Cohen had a company that kind of pioneered this, where they would draw a 3D attack map mm-Hmm.
And show you how an attacker couldn't reach that vulnerable, vulnerable server or don't. Um, how does what you guys are doing at VUL check match up to all of that? Yeah, I think, I think what you're referring to is really sort of that, that attack pap that can be so complex that an attacker Mm-Hmm.
Is going to take into an organization. I think it's worth noting that last year at RSA and Kevin Mandy has stood in front of, of the audience and his keto and basically put up some data. And that was really telling for, for us at V Check, which was exploits and not phishing attacks are the number one root cause now of the breach analysis, at least that Mandy and, and Google performed last year looking at every single breach that they went and investigated.
And it was by a landslide as well too. It's the first time that phishing was not the number one root cause of any breach. So crazy.
And, and what's happened now is that instead of relying on employees to do dumb things and not be security aware and security conscious within the workplace, now attackers are looking at this and saying, okay, well, you know, I can, I can just go to a website and pull down this vulnerability and start running exploit code against it and figure out how I'm going to get into that organization. I mean, there's 250,000 CVEs, you know, in the universe, and the scale I think is unprecedented. So what we're doing to try to solve that is we're adding some scale in terms of how we deliver the, a prioritized feed for one of our solutions to our customers.
We also do some really advanced exploit code and detection artifact work as well too. And when we put that together, we're basically distilling that huge number that scale, that scale of, let's just say 250,000 cvs down to the 2% that will probably be exploited to help organizations prioritize. And we do that by maintaining over 300 million, uh, records on these CVEs.
We refresh it every hour and we pull this from over 400 sources. The best example I can probably give you is if you think about the way that, that the NVD is constructed, or if you even think about how, how CIS is keve less known exploited vulnerabilities catalog is constructed, there's a lot that has to go into that. So they can push that data out to the, out, out to any organization, out to any product manager who wants to instrument those feeds through their solutions.
But there's a lot of human curation that take, that takes place. And as we've seen in the news over the past two weeks or so, the NVD is lacking a lot of data. That is, that is wouldn't typically be very helpful for organizations inclusive of CPE data.
So CPE data gives you, gives any responder the information for how that vulnerability, what software and firmware packages that vulnerability can be found in from every version of that, of that software on the internet. And that's the scale that we're taking, which is like a whole internet scan, distilling that down to the 2% that matter, and we do it autonomously, which is the big difference. And you just hit on that, Alan, which is, we, there's no human interference.
There's zero human that has to do anything to be able to extrapolate value from like this scalable, very highly prioritized data set that we're providing. Got it. Love it.
Tom, I'm sorry we went down the rabbit hole here. We never even got to main description. I main our main topic of discussion, I think it's time we hit that right.
Uh, so V Check was selected as one of the, uh, innovation Sandbox finalists. I think it's 10 finalists usually, right? Yes.
Uh, at the 2024 RSA conference in their Innovation Sandbox event, which I think takes place Monday of RSA week, which is Monday May 6th. Correct. Um, First of all, congratulations on that.
Thanks. It's, it's quite a feather in the cap as we were talking, you know, off camera. When you look at, over the last 18 or 19 years that they've done sandbox, and you look at the 10 finalists every year, it's a who's who of, you know, fantastic cyber security companies that have come out of this.
So being selected as a finalist as, as they say on the Miss America badge or whatever. Right. You're all winners, right?
Everybody, if you made it to the finalist, they That's right. In accomplishment. But let, let's talk about it.
What, you know, what, what do you think really kind of got the judge's attention that made you stand out? I, we had Cecilia Mar Ye on the, on, uh, on our show a couple weeks ago. I forgot how many, told us how many companies applied for this.
Um, what, what made you guys stand out, you think? Yeah, I, I think, I think that we're, so we're solving, I, there there's a number of directions I could go in answering that, but I think we're solving a problem that's really been one of the biggest problems in the cybersecurity market for as long as vulnerability management as a discipline has been around. And if you think about intelligence fed vulnerability management, threat intelligence feeds or threat intelligence solutions have really been in place to solve totally different problems, which was to go and triage vulnerabilities that were exploited by hand.
And I think if you look at it basically in a, in a holistic way, Alan, there's not enough analysts, there's not enough people to do the work. And that was really sort of the, the, the genesis of, of vtech, which was to do this autonomously to enable teams to, to not have to worry about interpreting a report, right? Like, what do I do with A PDF?
Uh, and then also looking at and consuming data that is, you know, a large am a large amount of data to begin with. Um, just really removing any of the barriers to being able to let software do its job with the, with the intelligence that we're providing. I think the second thing is that it's, we're so highly applicable to so many different areas of cybersecurity between, you know, we talk to product managers all the time of like large cyber companies that are building solutions.
We talk to enterprise teams, we talk to federal agencies, and we have, we have a solution or a set of solutions rather that can help any of them, right? Like, it, we just kind of feel it's like better data, faster, no human interference ever Zero. And using that autonomous approach to be able to do things faster, to be able to triage and to manage what you need to, what you need to look at in terms of threats to your business much more quickly.
And I think the final thing is we're we're almost taking, we're blending a couple of different areas of cybersecurity in terms of like vulnerability management, threat intelligence, and maybe a few other areas as well too. And we're basically just equipping teams to be able to do things so much faster and to be able to power platforms that are, that are, you know, that, that are all of a sudden much more enriched and much more accurate and efficient with V Check. And so I think it's like, if you look at like, you know, I I, it's not really the, the goal, but it's almost an organic output of our mission, which is we're kind of securing the whole cybersecurity ecosystem in a way.
I'm not saying we're a silver bullet for anything, but we're taking an approach that like we think everybody should use our data. Excellent. Excellent.
Um, for those of us, for those of you who out here who are going to RSA, as I mentioned, the sandbox, uh, is on Monday. You can go by and check out all of the finalists there. Monday also happens to be where we're doing our DevSecOps AI event at RSA in Moscone.
So if you're gonna go check out the sandbox, come, we'll be there all day doing our DevSecOps ai. We have an amazing light up, um, if anyone needs a, uh, expo pass, which I think gets you into Sandbox, I know it gets us into the DevSecOps. It gets you into the lot of the Monday events, uh, over at, at Security Boulevard.
We, we do have a, uh, code for a free pass you can get to and you can go see Vol check. Tom, one last thing I didn't do, but people want to get more information on v check. What's the website?
Yep. com. Um, we've got some really cool offers for, you know, for organizations there.
And we've got a huge, um, we've got a huge community tier of solutions, um, that we've, that we've launched as well too with, you know, thousands of new registered users where we want, we want to seed our data with the entire, you know, with the entire ecosystem again. So we've got, we've got tons of solutions. Come check us out.
We make it easy, frictionless, start using vol, check. Love it. Um, you'll be there all week though too, not just Monday.
Yes, I will. I will be there, uh, on the Sandbox stage on, on Monday, and I'll be there. I think I am because of Sandbox.
I get there on Saturday and then I'm leaving Friday There. Well, actually, I'm, so I unfortunately won't be there Monday. My youngest son's college graduation is Monday.
And there are some things that are just more important than RSAI. Totally. But I'll be there Tuesday and I, I'll, I'll try to look you up.
Um, thanks very much for coming on, Tom. Best of luck with V Check and, uh, you know, we'll see who wins this. It's gonna be a great sandbox this year.
We, we've interviewed some of the others. There's amazing companies as always. But congratulations to you and the whole team and good luck.
Thank you very much. I'm looking forward to it. And, and thank you Alan.
Alright. Tom Dane, chief Marketing Officer of Vol, check one of the RSA Conference Innovation Sandbox finalists for 2024. We're gonna take a break here on Tech Trunk tv.
We'll be back in a moment.