How TARA Works

Detailed Insights with Risk-based Vulnerability Management

Risk-based vulnerability management (RBVM) is a cybersecurity approach that allows organizations to prioritize remediation based on the actual risk of each vulnerability.  

Unlike legacy vulnerability management, risk-based vulnerability management does not just reveal vulnerabilities; it quantifies them with a threat context and potential business impact awareness.

RBVM uses threat intelligence to identify the vulnerabilities attackers are discussing, experimenting with, or using, and generates risk scores based on the likelihood of exploitation.  By contrast, the legacy Common Vulnerability Scoring System (CVSS) rates vulnerabilities based on the damage they would do if exploited. Time has demonstrated that many vulnerabilities with high CVSS scores pose little to no risk of ever being exploited. Given this low probability, directing resources toward risk-verified vulnerabilities reduces mitigation efforts and increases risk coverage.

A Better Approach

Remediate Vulnerabilities

Most organizations struggle to prioritize vulnerability scan results and use a “legacy” approach that remediates Critical and High (CVSS Ranking) vulnerabilities. 

Legacy

Vulnerability Management
  • Classifies vulnerabilities by CVSS score
  • Provides static scoring
  • Checks minimum compliance boxes
  • Focuses on Critical and High vulnerabilities

Risk-Based

Vulnerability Management
  • Leverages threat research to understand evolving attack techniques
  • Prioritizes vulnerabilities based on the risk to the business
  • Applies AI technology to predict the potential impact
  • Drives mitigation activities to maximize risk reduction

Flexible Options

TARA is suited to meet the needs of organizations that need a turn-key managed vulnerability program as well as those that want a risk-based view to improve prioritization of existing scan data.  For firms that want to invest resources to maximize risk coverage, TARA’s data-driven approach delivers results:

Vulnerability Program

A full-service approach that includes installation, configuration, and ongoing management of scanning software as well as a client-specific, risk-based vulnerability dashboard.  

Findings are segregated by mitigation group or location to provide clear priorities for the patching teams.

Vulnerability Enrichment

Software as a service that ingests vulnerability data from scanner technologies, enriches it with threat intelligence, and delivers risk-based scoring in a client specific dashboard.   Findings are segregated by mitigation group or location to provide clear priorities for the patching teams.

Mitigation Support

Our Mitigation Support service provides you with monthly meetings to review risk scoring, discuss questions about findings, evaluate progress, and refine mitigation priorities.  

Quantifying Risk

Understanding which vulnerabilities are the riskiest is the secret to effectively utilizing mitigation resources.  TARA provides risk insights that can reduce mitigation workload by 90% or more.

Click on the steps below to understand more.

1

Global Threat Research

Attack Techniques are Evolving
2

Predict Probability

And Likelihood of Vulnerability Impacts
3

Unique Risk Score

for each vulnerability
4

Enterprise Risk Score

a Sum of All Vulnerabilities
5

Dashboard Displays

Results are graphically rich

Global Threat Research

TARA utilizes global threat research to understand how attack techniques are evolving.

Hacker Social Structure

Content of Hacker Discussions

Hacker Community Metadata

Technical Information

Predict Vulnerability Probability

Intelligence is fed into a powerful AI engine that predicts the probability and likelihood of a vulnerability impacting your environment.

Patented Hacker Knowledge Graph Powered Features

Proprietary Blend of Over 60 Parallelized Models

Computed Probability of Exploitation

Assign a Risk Score

A unique risk score is assigned to each vulnerability.

Enterprise Risk Score

All vulnerabilities are summed to create an enterprise risk score.

Your Dashboard is Tailored to You

Results are displayed in graphically rich dashboards tailored to your organizational structure.

Stop managing vulnerabilities. Start managing cyber risk.

Request a demo to find out how TARA can benefit your organization.