← Back
Policy & LegalTenable·5 hours ago

How to build an exposure management program the business trusts: Lessons from Tenable’s CSO

Tenable's CSO Robert Huber describes how his organization tackled security tool sprawl and data silos by shifting from fragmented vulnerability management to a unified exposure management program, consolidating 50+ security tools into a single platform. This consolidation enabled the security team to move from presenting 30 slides of technical metrics that business leaders couldn't understand to delivering clear, business-aligned risk visualizations using a traffic-light system that directly ties cyber exposure to revenue-generating business units. The approach addresses modern challenges including rapid AI adoption and allows engineering teams to receive prioritized, actionable remediation guidance rather than fragmented reports across multiple domains.

Read full article at Tenable

Related Articles

Policy & LegalQualys·1 hour ago

PCI DSS 4.0.1: Application Requirements You’re Being Assessed On in 2026

As of March 31, 2025, all 51 previously optional "best practice" requirements in PCI DSS 4.0 are now mandatory and will be fully assessed in 2026 evaluations. A significant portion of the new assessment weight focuses on application-level controls under Requirements 6 and 11, including inventory management of custom applications and APIs along with continuous protection measures. Organizations must prepare for stricter compliance scrutiny on these application security requirements in upcoming PCI DSS assessments.

Policy & LegalGraham Cluley·9 hours ago

US Navy tells sailors and their families: scrub your social media, enemies are watching

The US Navy has issued guidance to its entire workforce of over 600,000 active-duty personnel, reservists, and civilian employees to review and sanitize their social media profiles due to concerns that adversaries could exploit publicly available information to identify military personnel, determine their locations, and identify when they may be away from home. This directive reflects growing awareness among military leadership about the operational security risks posed by oversharing on social platforms.

Policy & LegalSecurity Affairs·11 hours ago

Meta to Pay Up to $18B Over Teen Social Media Use

Meta will pay up to $18B and cap teen Facebook and Instagram use at two hours daily after nearly all US states sued over child safety. Meta will pay up to $18 billion over the next decade and impose real usage limits on teenagers using Facebook and Instagram, settling claims that the company deliberately designed […]

Policy & LegalThe Record·22 hours ago

Exclusive: NSA to host a hacker reunion in bid to rebuild secretive unit

The NSA is hosting a reunion event for former members of Tailored Access Operations (TAO), its elite hacking unit, as part of efforts to rebuild the secretive division following its recent rebranding. The agency expects to welcome back potentially hundreds of former TAO operatives to campus for the celebration. This recruitment effort suggests the NSA is prioritizing the restoration and expansion of its specialized offensive cyber capabilities.