![]() |
VOOZH | about |
We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.
Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.
Follow TNS on your favorite social media networks.
Become a TNS follower on LinkedIn.
Check out the latest featured and trending stories while you wait for your first TNS newsletter.
The pursuit of “zero CVEs” (common vulnerabilities and exposures) in software is not only unattainable: It diverts critical resources from real-world security challenges. Leaders who have adopted the zero-CVEs tagline are finding themselves with a proverbial hangover from their complicated and fragile mitigation strategy. This obscures a true understanding of your security posture, and leaves you with a foggy, if not incomplete, picture of how vulnerable you really are.
The best way to avoid this hangover is by adopting a transparent approach to your vulnerability management situation.
While organizations are adopting the zero-CVE mantra as a security pursuit, it is essentially a noise-reduction mechanism that only highlights CVEs that have a fix. This is because the zero-CVE philosophy mostly hinges on the idea that only those CVEs with patches are counted. You can see how this is dangerous: In enterprise security, context is critical, and ignorance is far from bliss.
Modern software applications are inherently complex. They are composed of hundreds of components, each leveraging countless open source libraries. For instance, a single application with a few hundred microservices could contain thousands of distinct dependencies, each a potential source of vulnerabilities. New CVEs are discovered daily, meaning achieving and maintaining a zero-CVE state for any significant software system is statistically impossible. In a large enterprise, this can involve tracking millions of entries weekly.
The zero-CVEs concept has several critical shortcomings:
A more pragmatic and effective approach to security and vulnerability management embraces transparency and a platform-centric strategy. Organizations need to acknowledge the continuous discovery of vulnerabilities and shift their focus from eliminating all CVEs to managing real, contextualized risks with continuous security and upgrades. This will ultimately help security leaders and platform engineers better understand their security posture and improve their response time to critical vulnerabilities and software failures.
You can rethink your approach to security without falling prey to the promise of zero CVEs. Here are some ways you can start shifting your security strategy to avoid the zero-CVE hangover:
The zero-CVE mindset is a fallacy that has crippled effective security programs. The path forward requires a shift towards transparency, trust and a platform-based approach that enables organizations to efficiently identify, prioritize and mitigate the most impactful risks, rather than chasing an impossible target.