Tenable has announced enhancements to ExposureAI, the generative AI capabilities and services within its Tenable One Exposure Management Platform.
The new features enable users to quickly summarise relevant attack paths, ask questions of an AI assistant and receive specific mitigation guidance to act on intelligence and reduce risk.
The platform’s generative AI-powered search and chat applications are fueled by Google Cloud – including Gemini models in Vertex AI.
Organisations face a high volume of exposures and more complicated threat actor tactics, techniques and procedures (TTP’s) across the modern attack surface today.
They are also facing a global cyber workforce shortage of 5.5 million trained professionals, according to the most recent data from ISC2[1].
Even the most seasoned security experts struggle to sort through, understand and prioritise complex attack paths.
As a result, 44% of IT and cyber leaders say they are either very confident or extremely confident that they can leverage generative AI to improve their organisation’s cybersecurity strategy[2].
Tenable Attack Path Analysis, part of the Tenable One platform, leverages generative AI-based capabilities to help organisations enhance their preventive security.
This includes explainability functionality that provides specific mitigation guidance with clear visibility and succinct analysis of complex attack paths, specific assets or security findings.
Added functionality includes:
- Attack Path Summary: Security practitioners can view a summary generated for each attack path in a single pane of glass that provides comprehensive descriptions of the entire attack path and gives direction on how an attacker can leverage a live attack path within the environment.
- AI Assistant: Users can ask Tenable’s AI assistant specific questions about the summarised attack path, as well as each node along the attack path. Questions like: What can you tell me about this asset? How many domain admins have access to this asset? Which patch can I apply to mitigate the vulnerability in this attack path? What is the number of attack paths this patch mitigates?
- Mitigation Guidance: This feature automatically provides specific mitigation guidance for each attack path. Security and IT practitioners no longer need to spend time sifting through options to determine which patch or version number to apply, or which user group has unauthorised access.
“When cyber teams examine the risk to their infrastructure and data, often the biggest challenge is deciphering the immediate course of action,” said Glen Pendley, Chief Technology Officer, Tenable. “ExposureAI, with Google Cloud, takes the guesswork out of the process and saves invaluable time in recommending the exact path to remediation.”
“Generative AI is a game changer for cyber defenders; helping them to better protect their organisations against increasingly sophisticated and relentless threats,” said Eric Doerr, Vice President of Security Engineering at Google Cloud. “Integrating our security-specific gen AI models into partner solutions, such as in Tenable’s Exposure Management platform, will further empower defenders to address pressing security challenges and mitigate disruptive cyber risks.”
[1] 2023 ISC2 Cybersecurity Workforce Study https://www.isc2.org/Insights/2023/10/ISC2-Reveals-Workforce-Growth-But-Record-Breaking-Gap-4-Million-Cybersecurity-Professionals
[1] Based on 761 respondents in a commissioned study conducted by Forrester Consulting on behalf of Tenable, October 2023