ZeroHour
Help Net Securitypublished ()ingested @helpnetsecurity

Building a risk-based vulnerability management program that scales

infoIndustryimportance 15
AI summary · glm-5.3-flash

Asimily CEO Shankar Somasundaram outlines a risk-based vulnerability management approach using inventory, attack paths, KEV and EPSS data.

In a Help Net Security video, Asimily CEO Shankar Somasundaram argues patching everything is infeasible as AI-driven attacks inflate vulnerability counts, with one customer finding a thousand unknowns for each known one. He recommends building a full inventory of devices, applications, and data flows, mapping attack paths for reachability, and prioritizing with KEV, EPSS, and business impact. Mitigations include patching, virtual patching via NACs and firewalls, segmentation, and configuration snapshots to detect drift.

  • Two-thirds of published CVEs are marked high risk, weakening CVSS-based triage
  • Prioritize by reachability, exploitability data, and business impact
  • Virtual patching and segmentation shrink the blast radius
VendorsAsimily
OrganizationsAsimily
Full article150 words · extracted from helpnetsecurity.com · click to collapse

In this Help Net Security video, Shankar Somasundaram, CEO at Asimily, explains how to build a risk-based vulnerability program. He notes that vulnerabilities are exploding by an order of magnitude in the age of AI-driven attacks, with one customer finding a thousand vulnerabilities for every one they knew about.

Patching everything is not workable, and relying on CVSS scores fails because two-thirds of published CVEs are marked high risk. Shankar walks through a better approach. Start with a thorough inventory of devices, applications, services, and data flows. Then map attack paths to see which vulnerabilities are truly reachable in your environment. Layer in exploitability data, KEV, EPSS, and business impact to narrow the list.

He covers mitigation through patching, virtual patching with NACs and firewalls, and segmentation to shrink the blast radius. He closes by recommending configuration snapshots so teams can detect drift and avoid repeating work.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/05/29/risk-based-vulnerability-management-video/