TechValidate Research on Cisco Vulnerability Management

These pages present data that TechValidate has sourced via direct research with verified customers and users of Cisco Vulnerability Management. TechValidate stands behind the authenticity of all published data. Learn more »



370 Customers Surveyed

2,872 Data Points Collected

190 Published TechFacts

10 Published Charts

98 Published Case Studies



Selected Research Highlights


Kenna.VM Case Study

Medium Enterprise Pharmaceuticals Company

Introduction

This case study of a medium enterprise pharmaceuticals company is based on a November 2020 survey of Kenna.VM customers by TechValidate, a 3rd-party research service. The profiled company asked to have their name blinded to protect their confidentiality.

Challenges

The business challenges that led the profiled company to evaluate and ultimately select Kenna.VM:

  • The vulnerability management challenges they were experiencing that led them to implement the Kenna.VM:
    • Too many vulnerabilities with no way to effectively prioritize
    • Not having a way to quantify or measure risk from vulnerabilities
    • Inefficiencies in vulnerability remediation

Use Case

The key features and functionalities of Kenna.VM that the surveyed company uses:

  • The approach they used to prioritize vulnerabilities prior to Kenna:
    • CVSS 8+
    • CVSS 9+
    • CVSS 10+
  • They best describe their current engagement model between the Security and IT team as Security investigates; Security and IT work together to prioritize; IT remediates.
  • The criteria they use to evaluate the success of your Kenna.VM implementation:
    • Reduction in reporting time

Results

The surveyed company achieved the following results with Kenna.VM:

  • Before Kenna vs. After Kenna: Have you seen a reduction in time spent on the following activities? (Security and IT team time combined)
    • time spent on Vulnerability Investigation: 25 – 50%
    • time spent on remediation: over 75%
    • time spent on reporting: 10 – 25%
  • Kenna’s primary advantage(s) over other vulnerability management platforms:
    • Kenna goes beyond basic risk scoring and tells me what I need to fix first
    • Kenna provides awareness of how much risk is in our environment
  • Rates the following for Kenna.VM compared to other vulnerability management solutions:
    • remediation Intelligence (guidance on “what to fix first”): superior
    • integrated real-time global exploit intelligence: superior
    • data science-based risk scoring methodology: superior
    • “Off the shelf” integrations with a wide range of security data sources: on par
    • predictive vulnerability modeling: on par

Kenna Security Customer Research

Before Kenna vs. After Kenna: Have you seen a reduction in time spent on the following activities? (Security and IT team time combined)

Over 75% Over 50% Over 25% Over 10% 0%
Time spent on Vulnerability Investigation

16%

39%

19%

19%

7%

Time spent on remediation

12%

32%

24%

15%

17%

Time spent on reporting

27%

25%

25%

13%

10%

Kenna Security Customer Testimonial

Kenna has helped us to enrich our vulnerability data, allowing us to make more impactful decisions when prioritizing.

Senior IT Security Consultant, Global 500 Insurance Company

Kenna.VM Case Study

Large Enterprise Retail Company

Introduction

This case study of a large enterprise retail company is based on a September 2020 survey of Kenna.VM customers by TechValidate, a 3rd-party research service. The profiled company asked to have their name blinded to protect their confidentiality.

“Even though we’re quite early in our vulnerability management program, Kenna is already adding context to the vulnerability count that we have, which makes it’s easier to have conversations with exec level individuals to gain momentum and buy-in from IT teams. "

“We’ve had a great experience with CX team: CSE has been knowledgeable for any questions, and CSM has been happy to assist with any queries we have.”

Challenges

The business challenges that led the profiled company to evaluate and ultimately select Kenna.VM:

  • The vulnerability management challenges they were experiencing that led them to implement the Kenna.VM:
    • Too many vulnerabilities with no way to effectively prioritize
    • High volume of security data lacking context for decision making
    • Not having a way to quantify or measure risk from vulnerabilities

Use Case

The key features and functionalities of Kenna.VM that the surveyed company uses:

  • The approach they used to prioritize vulnerabilities prior to Kenna:
    • CVSS 10+
  • They best describe their current engagement model between the Security and IT team as Security investigates and prioritizes vulnerabilities; IT remediates.
  • The criteria they use to evaluate the success of your Kenna.VM implementation:
    • Kenna risk score reduction

Results

The surveyed company achieved the following results with Kenna.VM:

  • Before Kenna vs. After Kenna: Have you seen a reduction in time spent on the following activities? (Security and IT team time combined)
    • time spent on Vulnerability Investigation: 10 – 25%
    • time spent on remediation: 25 – 50%
    • time spent on reporting: 50 – 75%
  • Kenna’s primary advantage(s) over other vulnerability management platforms:
    • Kenna goes beyond basic risk scoring and tells me what I need to fix first
    • Kenna provides awareness of how much risk is in our environment
  • Rates the following for Kenna.VM compared to other vulnerability management solutions:
    • remediation Intelligence (guidance on “what to fix first”): superior
    • integrated real-time global exploit intelligence: on par
    • data science-based risk scoring methodology: superior
    • “Off the shelf” integrations with a wide range of security data sources: superior
    • predictive vulnerability modeling: superior

Kenna Security Customer Testimonial

We are a more responsive organization who is getting better control over our overall risk profile.

Senior Information Security Assurance Consultant, Medium Enterprise Health Care Company

Kenna Security Customer Research

What criteria do you use to evaluate the success of your Kenna Security platform implementation?

Kenna risk score reduction
76%
Reduction in Mean Time To Remediate (MTTR)
41%
Reduction in IT remediation time
31%
Reduction in vulnerability investigation time
30%
SLA Adherence
25%
Reduction in reporting time
23%


More to Explore



About Cisco Vulnerability Management

Cisco Vulnerability Management (formerly Kenna.VM) offers an effective, efficient way to reduce your risk profile using risk-based prioritization powered by data science. Rely on it to ID the vulnerabilities that put you at the greatest risk, create a self-service environment for remediation teams, set intelligent SLAs based on your risk tolerance, compare your risk posture against industry peers, deliver clear reports with intuitive metrics, and more.

Cisco Vulnerability Management Website   Cisco Vulnerability Management Website