3rd Party Data Ingestion
Default 3rd Party Data Ingestion
- 3rd party data ingestion from Tenable, Rapid7, CrowdStrike, SentinelOne ingestion
- Breach & Attack Simulation is included in Base license
Benefits
Unified view of exposure from code to cloud, Lower licensing cost and complexity Additional and Higher licensing cost
- 3rd Party data from Tenable, Rapid7 can’t be ingested
- Needs a separate product Qualys ETM
Drawback
High licensing cost, added complexity and risk of vendor lock-inRisk Score and Threat Exposure
Real Risk Score (1-100)
- Considers vulnerability severity, age, access, attack complexity, threat intel, asset criticality, business impact, security controls and attack feasibility
- Global, Industry and Regional Threat Intel
- Provide IOCs to detect Vulnerability Exploitation
- Vulnerability to Threat Actor Mapping
Benefits
Practical Risk Score, Targetted exposure reduction and remediation, high ROI Inaccurate Risk Score (1-1000)
- Multiple scores (QDS, Tru Risk)- more confusion rather than clarity
- Scores Ignore security controls in place and doesn’t evaluate attack feasibility
- Generic Threat Intelligence
- No IOCs to detect vulnerability exploitation
- No Threat Actor Attribution
Drawback
Misleading and inactionable risk score. High efforts and uncertain exposure reductionCyber Asset Attack Surface Management (CAASM)
Comprehensive and Easy
- 100+ Out of box integrations
- Visibiity of Security Controls and their Effectiveness
- EDR, Network Security, etc
Benefits
Quick time to value and Single view of Cyber Asset Inventory Incomplete and unuseful
- Limited integration with technologies in ecosystem
- Raw application inventory- no security controls category
- No visibility into security controls effectiveness
Drawback
High complexity because of agent dependency and incomplete view of assets