Why Cybersecurity Needs Continuous Exposure Management
嗯,用户让我总结一篇文章,控制在100字以内,而且不需要特定的开头。首先,我需要快速阅读文章内容,抓住主要观点。 文章讲的是Alan和Himanshu Kathpal讨论现代网络安全团队如何从被动防御转向主动风险管理。他们提到传统方法如扫描、警报和定期评估已经不够用了,因为现在变化快,威胁自动化。 Kathpal指出攻击面扩大得比组织追踪得快,云迁移、SaaS和AI等因素导致了可见性差距。关键是要从知道漏洞在哪里转向持续行动,整合威胁情报、分析和自动化到反馈循环中。 他还强调了打破IT运营和网络安全之间的隔阂,适应混合云环境,实时关联数据,减少噪音。同时需要文化转变,将安全视为持续实践而非一年一度的审计。 最后总结是网络安全不是完美防御,而是持续控制在快速变化的环境中。 现在我要把这些要点浓缩到100字以内。确保涵盖现代团队的转变、传统方法不足、攻击面扩大、整合技术、打破隔阂、文化和持续控制。 可能的结构:现代网络安全团队正在从被动防御转向主动风险管理。传统方法如扫描和警报已不足以应对快速变化和自动化威胁。攻击面扩大导致可见性差距,需整合威胁情报、分析和自动化,并打破部门隔阂。文化转变和持续控制是关键。 </think> 现代网络安全团队正在从被动防御转向主动风险管理。传统方法如扫描和警报已不足以应对快速变化和自动化威胁。攻击面扩大导致可见性差距,需整合威胁情报、分析和自动化,并打破部门隔阂。文化转变和持续控制是关键。 2025-10-23 17:30:57 Author: securityboulevard.com(查看原文) 阅读量:19 收藏

Avatar photo

Alan sits down with Himanshu Kathpal to discuss how modern cybersecurity teams are evolving from reactive defense to proactive exposure management. They explore why traditional approaches to risk reduction—built around scanning, alerting, and periodic assessment—are no longer enough in a world of continuous change and automated threats.

Cruise Con 2025

Kathpal explains that the attack surface has expanded faster than most organizations can track. Between cloud migration, SaaS adoption, and AI-driven workloads, visibility gaps have become inevitable. The key, he says, is shifting from simply knowing where vulnerabilities exist to continuously acting on that knowledge. That means integrating threat intelligence, analytics, and automation into a single feedback loop that prioritizes what matters most to the business.

He highlights the need for security programs that bridge the divide between IT operations and cybersecurity—breaking down silos that slow response and obscure accountability. As organizations embrace hybrid and multi-cloud environments, risk management must adapt by correlating data across systems, evaluating exploitability in real time, and reducing noise so that teams can focus on genuine exposure.

Kathpal also emphasizes the cultural transformation required for resilience. Cybersecurity can’t be treated as a once-a-year audit—it’s an ongoing practice of measurement, prioritization, and action.

The takeaway: cyber resilience isn’t about achieving perfect defense; it’s about maintaining continuous control in an imperfect, fast-moving environment. The organizations that can connect visibility with action will be the ones that stay secure amid the chaos of modern enterprise IT.

Avatar photo

Alan Shimel

Throughout his career spanning over 25 years in the IT industry, Alan Shimel has been at the forefront of leading technology change. From hosting and infrastructure, to security and now DevOps, Shimel is an industry leader whose opinions and views are widely sought after.

Alan’s entrepreneurial ventures have seen him found or co-found several technology related companies including TriStar Web, StillSecure, The CISO Group, MediaOps, Inc., DevOps.com and the DevOps Institute. He has also helped several companies grow from startup to public entities and beyond. He has held a variety of executive roles around Business and Corporate Development, Sales, Marketing, Product and Strategy.

Alan is also the founder of the Security Bloggers Network, the Security Bloggers Meetups and awards which run at various Security conferences and Security Boulevard.

Most recently Shimel saw the impact that DevOps and related technologies were going to have on the Software Development Lifecycle and the entire IT stack. He founded DevOps.com and then the DevOps Institute. DevOps.com is the leading destination for all things DevOps, as well as the producers of multiple DevOps events called DevOps Connect. DevOps Connect produces DevSecOps and Rugged DevOps tracks and events at leading security conferences such as RSA Conference, InfoSec Europe and InfoSec World. The DevOps Institute is the leading provider of DevOps education, training and certification.

Alan has a BA in Government and Politics from St Johns University, a JD from New York Law School and a lifetime of business experience. His legal education, long experience in the field, and New York street smarts combine to form a unique personality that is always in demand to appear at conferences and events.

alan has 123 posts and counting.See all posts by alan


文章来源: https://securityboulevard.com/2025/10/why-cybersecurity-needs-continuous-exposure-management/
如有侵权请联系:admin#unsafe.sh