Today in Bengaluru, on April 18, 2024, Indusface, a rapidly growing leader in application security SaaS, has unveiled AcuRisQ on its acclaimed Dynamic Application Security Testing (DAST) platform, Indusface WAS.
AcuRisQ empowers security leaders within large enterprises to prioritize critical vulnerabilities for resolution based on various factors such as business significance, ease of discovery, and interdependence. By leveraging AcuRisQ, users of Indusface WAS can now delve into comprehensive vulnerability analysis and receive a prioritized rundown of vulnerabilities requiring immediate attention.
For instance, a critical vulnerability found in a QA environment may not necessitate the same level of urgency as one discovered in a customer-facing application. The absence of business context in Common Vulnerability Scoring System (CVSS) scores often contributes to vulnerability fatigue, as noted by 85% of CISOs, according to Help Net Security.
Ashish Tandon, Founder & CEO of Indusface, highlighted, “Alert fatigue not only jeopardizes large enterprises but also undermines the credibility of CISOs. Sending VAPT reports laden with numerous open vulnerabilities across multiple applications directly contributes to this fatigue. With AcuRisQ, teams can slash this figure by up to 80%, enabling them to identify and address vulnerabilities posing the greatest business risk. As this practice becomes commonplace, CISOs will increasingly be viewed as facilitators of business rather than obstacles.”
Indusface’s Annual State of Application Security Report 2023 revealed that, on average, enterprise-level companies encounter hundreds of critical and high-level vulnerabilities annually, with one-third remaining unresolved for over six months. Hence, prioritizing vulnerabilities with the highest business impact for resolution is imperative.
AcuRisQ delves deep into each business asset, furnishing “risk-based metrics” to accurately quantify security risks and prioritize the most pressing vulnerabilities for resolution.
Key features of AcuRisQ include:
- Ensuring zero false positives on all reported vulnerabilities
- Furnishing a prioritized catalog of vulnerabilities necessitating immediate resolution
- Assigning a risk score to each open vulnerability based on various parameters, such as application criticality, severity, discoverability, and more
- Offering detailed guidelines for remediation