{"id":2297,"date":"2018-11-07T10:29:53","date_gmt":"2018-11-07T14:29:53","guid":{"rendered":"https:\/\/solutionsreview.com\/security-information-event-management\/?p=2297"},"modified":"2018-11-07T15:29:40","modified_gmt":"2018-11-07T19:29:40","slug":"vulnerability-management-assessment-gaurav-banga-balbix","status":"publish","type":"post","link":"https:\/\/solutionsreview.com\/security-information-event-management\/vulnerability-management-assessment-gaurav-banga-balbix\/","title":{"rendered":"Vulnerability Management and Assessment with Gaurav Banga of Balbix"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-full wp-image-1378\" src=\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2018\/03\/MSPs-websiote-security-interview.jpg\" alt=\"Vulnerability Management and Assessment with Gaurav Banga of Balbix\" width=\"800\" height=\"400\" srcset=\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2018\/03\/MSPs-websiote-security-interview.jpg 800w, https:\/\/solutionsreview.com\/security-information-event-management\/files\/2018\/03\/MSPs-websiote-security-interview-300x150.jpg 300w, https:\/\/solutionsreview.com\/security-information-event-management\/files\/2018\/03\/MSPs-websiote-security-interview-768x384.jpg 768w, https:\/\/solutionsreview.com\/security-information-event-management\/files\/2018\/03\/MSPs-websiote-security-interview-540x270.jpg 540w, https:\/\/solutionsreview.com\/security-information-event-management\/files\/2018\/03\/MSPs-websiote-security-interview-162x81.jpg 162w, https:\/\/solutionsreview.com\/security-information-event-management\/files\/2018\/03\/MSPs-websiote-security-interview-360x180.jpg 360w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p style=\"text-align: justify\">Solutions Review is pleased and honored to have spoken with Gaurav Banga, CEO of vulnerability management provider <a href=\"https:\/\/www.balbix.com\/\" target=\"_blank\" rel=\"noopener\">Balbix<\/a>. We discussed the Gartner Market Guide for Vulnerability Assessment Solutions, key vulnerability management capabilities, and what the future might hold.<\/p>\n<div class=\"widget\"><div class=\"aside-card\">\t\t\t<div class=\"textwidget\"><p><a href=\"https:\/\/logrhythm.com\/forrester-wave-security-analytics-analyst-report-2018\/?utm_source=Solutions-Review&amp;utm_medium=cpc&amp;utm_campaign=Solutions-Review&amp;AdGroup=&amp;utm_program=NAcpc1&amp;utm_content=C-Download-Now&amp;utm_region=NA&amp;utm_language=en\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" src=\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2018\/10\/PM_Forrester_Wave_Display_C.jpg\" \/><\/a><\/p>\n<\/div>\n\t\t<\/div><\/div>\n<p style=\"text-align: justify\">Here&#8217;s our conversation, edited slightly for readability:<\/p>\n<h3 style=\"text-align: justify\"><b>Solutions Review: What do you make of Gartner\u2019s Market Guide for Vulnerability Assessment Solutions?<\/b><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Gaurav Banga: Gartner\u2019s Market Guide for VA is a step in the right direction: to help enterprises and VA vendors understand that there is an overwhelming need to incorporate risk, based on business context, into the VA programs. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Vulnerability assessment (VA) scanners enumerate thousands of vulnerabilities at any given point for a large enterprise\u2014leaving security and IT teams at-a-loss on where to begin, as well as how to allocate finite resources and time. As a result, teams typically go about fixing those vulnerabilities that are perceived to be the most critical (based on CVSS or other standardized ratings) or the easiest to fix, but this leaves many untouched (and potentially the highest business risk ones). <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">If the VA solution is able to understand and take into account the actual business risk associated with each vulnerability, as it pertains to the organization, and arrange the vulnerabilities in priority order based on risk to the enterprise, coupled with an understanding and correlation with existing security controls, the VA market would evolve to be risk-based vulnerability management (Gartner\u2019s definition of a holistic solution). That would allow enterprise security teams to more effectively and efficiently support their security operations and ultimately contribute to organizations becoming more proactive in mitigating (and avoiding) breaches.<\/span><\/p>\n<h3 style=\"text-align: justify\"><b>SR: What do you think of Gartner\u2019s stressing of vulnerability management with context?<\/b><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">GB: Gartner stressing the need for context in vulnerability management solutions is an important step towards setting a new industry standard for security tools.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">We agree with Gartner that there is a need for vulnerability management solutions that provide context around the risk and potential business impact of each IT asset, so security teams and management can identify which ones should be prioritized in taking action.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">There are several important considerations when thinking about context:<\/span><\/p>\n<ol style=\"text-align: justify\">\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">First and foremost is automatically and continuously enumerating the enterprise\u2019s inventory, including every relevant detail (category, type, configuration, usage, etc.) for all devices, users and applications, on-premises and off.<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Second is discovering and understanding deep context around the role and business criticality of each asset and user. Without role and business criticality, enterprises just have an unprioritized laundry list of vulnerabilities.<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Then it is important to incorporate up-to-date knowledge of global and industry-specific threats, such as what is fashionable with the adversary on a daily and weekly basis.<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">All these need to be coupled with an understanding of the various security products and processes already deployed in the enterprise, and their negating effects against active threats and vulnerabilities.<\/span><\/li>\n<\/ol>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">All of the above are essential to establishing the context from which effective risk can be computed, which allows for proper prioritization of vulnerabilities. This context must be carefully and automatically constructed device-by-device, application-by-application, and user-by-user, and continuously updated based on the changing landscape of new vulnerabilities and threats. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Like most current VM tools, simply ranking the severity of the findings with a generic rating (high\/medium\/low risk) is not useful.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">With a risk-based vulnerability management approach, each asset is analyzed using the context of the specific asset, its use in the business, the impact of a potential breach on it, existing controls, and the likelihood of a breach occurring. That calculation allows companies to create a precise, prioritized list of security fixes so there is no doubt as to what actions need to be taken in what order.<\/span><\/p>\n<h3 style=\"text-align: justify\"><b>SR: What capabilities are essential to risk-based vulnerability management? Why do you consider them essential?<\/b><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">GB: The most essential capabilities to risk-based vulnerability management are:<\/span><\/p>\n<ol style=\"text-align: justify\">\n<li><span style=\"font-weight: 400\"> Accurate inventory and categorization of all existing enterprise assets, including managed, unmanaged, cloud, devices, IoT, apps, users, etc. This needs to be updated continuously.<\/span><\/li>\n<li><span style=\"font-weight: 400\"> Analysis across all attack vectors &#8212; not just unpatched software.<\/span><\/li>\n<li><span style=\"font-weight: 400\"> Asset contextualization based on risk and potential impact to the business if a breach occurs.<\/span><\/li>\n<li><span style=\"font-weight: 400\"> Prioritized list of action items unique to each enterprise environment so security teams can proactively tackle mitigation based on business criticality. <\/span><\/li>\n<\/ol>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">When companies compare all assets against all potential attack vectors, it quickly adds up to millions of potential points of attack\u2014far more than any human cybersecurity team can stay on top of without leveraging AI and machine learning. These advanced technologies must be baked into the capabilities listed above in order to provide companies with an accurate and real-time list of prioritized actions. \u00a0\u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">With these four capabilities, vulnerability assessment tools go from primitive scanning for unpatched software and bulk patch recommendations to helping companies proactively mitigate risk across IT assets and attack types.<\/span><\/p>\n<h3 style=\"text-align: justify\"><b>SR: Does the industry need a new definition of vulnerability assessment? Why?<\/b><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">GB: As noted above, vulnerability assessment (VA, formerly known as vulnerability management) tools are limited from multiple angles\u2014limited types of assets (corporate-managed, e.g. servers and company notebooks), sole focus on unpatched software, and operate in a cyclical mode (run a scan, then assess the results\/output) and not real-time. Equally important, VA tools today do not assess and use business risk in computing their output and recommendation for SecOps.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">In contrast, the enterprise attack surface is expanding (the opposite of limited) across the two axes of asset types (e.g. IoT, BYOD, ICS, etc.) and attack vectors (regularly growing).<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">This combination of severe limitations and an ever-growing enterprise attack surface are mandating the VA get redefined and refocused on minimizing business risk and increasing cyber-resilience. Hence Gartner defining the risk-based vulnerability management market.<\/span><\/p>\n<h3 style=\"text-align: justify\"><b>SR: What does the future of vulnerability assessment look like to you?<\/b><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">GB: Traditionally, vulnerability assessment (formerly known as vulnerability management) has been defined as the practice of identifying security vulnerabilities in unpatched software. Though it is typically an integral part of every organization\u2019s cybersecurity strategy, the traditional VA approach has become increasingly ineffective for a couple of reasons. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">First, the traditional tools do not present an accurate picture of the enterprises\u2019 asset inventory (which includes all types of assets, including managed, unmanaged, BYOD, IoT, on-premises, and cloud) and secondly, it is no longer enough to just enumerate vulnerabilities due to unpatched systems, when there are 200+ other attack vectors that can be exploited. This is where traditional VA falls short.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Organizations need to take a more modern approach to properly understand their comprehensive risk posture, with a risk-based approach to vulnerability management (RBVM) that not only <\/span><i><span style=\"font-weight: 400\">identifies<\/span><\/i><span style=\"font-weight: 400\"> vulnerabilities but also <\/span><i><span style=\"font-weight: 400\">predicts breach risk, prioritizes action items based on business risk, and offers guidance on fixes to correct the issues.<\/span><\/i><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">The modern approach to RBVM has the following two key features:<\/span><\/p>\n<ol style=\"text-align: justify\">\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">It covers the multi-dimensional attack surface.<\/span><\/li>\n<\/ol>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Traditional VA tools have limited coverage across the vast and rapidly expanding set of attack vectors. Phishing, ransomware, misconfigurations, and credentials are just some of the vectors not covered by traditional VA.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Next-generation VA needs to monitor and scan for many other attack vectors like device\/network and application misconfigurations, risk from weak or no encryption, use of weak passwords &amp; shared passwords, denial of service, password reuse, propagation risk, phishing and ransomware, zero-day threats, and more.<\/span><\/p>\n<ol style=\"text-align: justify\" start=\"2\">\n<li><span style=\"font-weight: 400\"> It offers visibility for all types of assets, including BYOD.<\/span><\/li>\n<\/ol>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Traditional VM tools typically scan enterprise-owned and managed IT assets such as corporate servers and laptops, and they leave out all the rest. But in today\u2019s modern enterprise, device demographics have shifted dramatically with the proliferation of different asset categories (unmanaged, BYOD, cloud-based, IoT, and mobile, to name just a few).<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Next-generation VM should be able to discover, monitor, and scan <\/span><i><span style=\"font-weight: 400\">all types of devices and assets<\/span><\/i><span style=\"font-weight: 400\"> \u2013 including BYOD, IoT, cloud, and third party \u2013 to automatically and continuously predict breach risk through a single integrated system.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Modern enterprises require risk-based vulnerability management. Only this new approach can provide the critical information that is required to proactively protect a large modern enterprise network that spread out across on-prem, cloud, mobile, leased, software-defined and other evolving system architectures.<\/span><\/p>\n<p><strong>Thank you to\u00a0Gaurav Banga of <a href=\"https:\/\/www.balbix.com\/\" target=\"_blank\" rel=\"noopener\">Balbix<\/a> for his time and expertise!\u00a0<\/strong><\/p>\n<h4 style=\"text-align: justify\"><strong>Other Resources from Solutions Review:\u00a0<\/strong><\/h4>\n<ul style=\"text-align: justify\">\n<li style=\"text-align: justify\"><a href=\"https:\/\/solutionsreview.com\/security-information-event-management\/10-coolest-siem-security-analytics-ceo-leaders\/\" target=\"_blank\" rel=\"noopener\">The 10 Coolest SIEM and Security Analytics CEO Leaders<\/a><\/li>\n<li style=\"text-align: justify\"><a href=\"https:\/\/solutionsreview.com\/security-information-event-management\/get-employees-embrace-siem-best-practices\/\" target=\"_blank\" rel=\"noopener\">Get Your Employees to Embrace SIEM Best Practices!<\/a><\/li>\n<li style=\"text-align: justify\"><a href=\"https:\/\/solutionsreview.com\/security-information-event-management\/4-tips-make-data-breach-detection-easier-enterprise\/\" target=\"_blank\" rel=\"noopener\">4 Tips to Make Data Breach Detection Easier For Your Enterprise<\/a><\/li>\n<li style=\"text-align: justify\"><a href=\"https:\/\/solutionsreview.com\/security-information-event-management\/dont-become-complacent-in-your-cybersecurity\/\" target=\"_blank\" rel=\"noopener\">Enterprises: Don\u2019t Become Complacent in Your Cybersecurity!<\/a><\/li>\n<li style=\"text-align: justify\"><a href=\"https:\/\/solutionsreview.com\/security-information-event-management\/comparing-the-top-siem-vendors-solutions-review\/\" target=\"_blank\" rel=\"noopener\">Comparing the Top SIEM Vendors \u2014 Solutions Review<\/a><\/li>\n<\/ul>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\"><br \/>Widget not in any sidebars<br \/><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Solutions Review is pleased and honored to have spoken with Gaurav Banga, CEO of vulnerability management provider Balbix. We discussed the Gartner Market Guide for Vulnerability Assessment Solutions, key vulnerability management capabilities, and what the future might hold. Here&#8217;s our conversation, edited slightly for readability: Solutions Review: What do you make of Gartner\u2019s Market Guide [&hellip;]<\/p>\n","protected":false},"author":41,"featured_media":1378,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[551],"tags":[675,353,95,13,896,112,86,21,57,22],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Vulnerability Management and Assessment with Gaurav Banga of Balbix<\/title>\n<meta name=\"description\" content=\"Solutions Review is pleased and honored to have spoken with Gaurav Banga, CEO of vulnerability management solution provider Balbix.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/solutionsreview.com\/security-information-event-management\/vulnerability-management-assessment-gaurav-banga-balbix\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Vulnerability Management and Assessment with Gaurav Banga of Balbix\" \/>\n<meta property=\"og:description\" content=\"Solutions Review is pleased and honored to have spoken with Gaurav Banga, CEO of vulnerability management solution provider Balbix.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/solutionsreview.com\/security-information-event-management\/vulnerability-management-assessment-gaurav-banga-balbix\/\" \/>\n<meta property=\"og:site_name\" content=\"Best Information Security SIEM Tools, Software, Solutions &amp; Vendors\" \/>\n<meta property=\"article:published_time\" content=\"2018-11-07T14:29:53+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2018-11-07T19:29:40+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2018\/03\/MSPs-websiote-security-interview.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"800\" \/>\n\t<meta property=\"og:image:height\" content=\"400\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Ben Canner\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ben Canner\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/vulnerability-management-assessment-gaurav-banga-balbix\/\",\"url\":\"https:\/\/solutionsreview.com\/security-information-event-management\/vulnerability-management-assessment-gaurav-banga-balbix\/\",\"name\":\"Vulnerability Management and Assessment with Gaurav Banga of Balbix\",\"isPartOf\":{\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/vulnerability-management-assessment-gaurav-banga-balbix\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/vulnerability-management-assessment-gaurav-banga-balbix\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2018\/03\/MSPs-websiote-security-interview.jpg\",\"datePublished\":\"2018-11-07T14:29:53+00:00\",\"dateModified\":\"2018-11-07T19:29:40+00:00\",\"author\":{\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541\"},\"description\":\"Solutions Review is pleased and honored to have spoken with Gaurav Banga, CEO of vulnerability management solution provider Balbix.\",\"breadcrumb\":{\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/vulnerability-management-assessment-gaurav-banga-balbix\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/solutionsreview.com\/security-information-event-management\/vulnerability-management-assessment-gaurav-banga-balbix\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/vulnerability-management-assessment-gaurav-banga-balbix\/#primaryimage\",\"url\":\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2018\/03\/MSPs-websiote-security-interview.jpg\",\"contentUrl\":\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2018\/03\/MSPs-websiote-security-interview.jpg\",\"width\":800,\"height\":400,\"caption\":\"The Essential 16 Incident Response Books for Professionals\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/vulnerability-management-assessment-gaurav-banga-balbix\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/solutionsreview.com\/security-information-event-management\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Vulnerability Management and Assessment with Gaurav Banga of Balbix\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/#website\",\"url\":\"https:\/\/solutionsreview.com\/security-information-event-management\/\",\"name\":\"Best Information Security SIEM Tools, Software, Solutions &amp; Vendors\",\"description\":\"Buyer&#039;s Guide and Best Practices\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/solutionsreview.com\/security-information-event-management\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541\",\"name\":\"Ben Canner\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g\",\"caption\":\"Ben Canner\"},\"description\":\"Ben Canner is an enterprise technology writer and analyst covering Identity Management, SIEM, Endpoint Protection, and Cybersecurity writ large. He holds a Bachelor of Arts Degree in English from Clark University in Worcester, MA. He previously worked as a corporate blogger and ghost writer. You can reach him via Twitter and LinkedIn.\",\"url\":\"https:\/\/solutionsreview.com\/security-information-event-management\/author\/bcanner\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Vulnerability Management and Assessment with Gaurav Banga of Balbix","description":"Solutions Review is pleased and honored to have spoken with Gaurav Banga, CEO of vulnerability management solution provider Balbix.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/solutionsreview.com\/security-information-event-management\/vulnerability-management-assessment-gaurav-banga-balbix\/","og_locale":"en_US","og_type":"article","og_title":"Vulnerability Management and Assessment with Gaurav Banga of Balbix","og_description":"Solutions Review is pleased and honored to have spoken with Gaurav Banga, CEO of vulnerability management solution provider Balbix.","og_url":"https:\/\/solutionsreview.com\/security-information-event-management\/vulnerability-management-assessment-gaurav-banga-balbix\/","og_site_name":"Best Information Security SIEM Tools, Software, Solutions &amp; Vendors","article_published_time":"2018-11-07T14:29:53+00:00","article_modified_time":"2018-11-07T19:29:40+00:00","og_image":[{"width":800,"height":400,"url":"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2018\/03\/MSPs-websiote-security-interview.jpg","type":"image\/jpeg"}],"author":"Ben Canner","twitter_misc":{"Written by":"Ben Canner","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/vulnerability-management-assessment-gaurav-banga-balbix\/","url":"https:\/\/solutionsreview.com\/security-information-event-management\/vulnerability-management-assessment-gaurav-banga-balbix\/","name":"Vulnerability Management and Assessment with Gaurav Banga of Balbix","isPartOf":{"@id":"https:\/\/solutionsreview.com\/security-information-event-management\/#website"},"primaryImageOfPage":{"@id":"https:\/\/solutionsreview.com\/security-information-event-management\/vulnerability-management-assessment-gaurav-banga-balbix\/#primaryimage"},"image":{"@id":"https:\/\/solutionsreview.com\/security-information-event-management\/vulnerability-management-assessment-gaurav-banga-balbix\/#primaryimage"},"thumbnailUrl":"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2018\/03\/MSPs-websiote-security-interview.jpg","datePublished":"2018-11-07T14:29:53+00:00","dateModified":"2018-11-07T19:29:40+00:00","author":{"@id":"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541"},"description":"Solutions Review is pleased and honored to have spoken with Gaurav Banga, CEO of vulnerability management solution provider Balbix.","breadcrumb":{"@id":"https:\/\/solutionsreview.com\/security-information-event-management\/vulnerability-management-assessment-gaurav-banga-balbix\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/solutionsreview.com\/security-information-event-management\/vulnerability-management-assessment-gaurav-banga-balbix\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/vulnerability-management-assessment-gaurav-banga-balbix\/#primaryimage","url":"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2018\/03\/MSPs-websiote-security-interview.jpg","contentUrl":"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2018\/03\/MSPs-websiote-security-interview.jpg","width":800,"height":400,"caption":"The Essential 16 Incident Response Books for Professionals"},{"@type":"BreadcrumbList","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/vulnerability-management-assessment-gaurav-banga-balbix\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/solutionsreview.com\/security-information-event-management\/"},{"@type":"ListItem","position":2,"name":"Vulnerability Management and Assessment with Gaurav Banga of Balbix"}]},{"@type":"WebSite","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/#website","url":"https:\/\/solutionsreview.com\/security-information-event-management\/","name":"Best Information Security SIEM Tools, Software, Solutions &amp; Vendors","description":"Buyer&#039;s Guide and Best Practices","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/solutionsreview.com\/security-information-event-management\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541","name":"Ben Canner","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g","caption":"Ben Canner"},"description":"Ben Canner is an enterprise technology writer and analyst covering Identity Management, SIEM, Endpoint Protection, and Cybersecurity writ large. He holds a Bachelor of Arts Degree in English from Clark University in Worcester, MA. He previously worked as a corporate blogger and ghost writer. You can reach him via Twitter and LinkedIn.","url":"https:\/\/solutionsreview.com\/security-information-event-management\/author\/bcanner\/"}]}},"_links":{"self":[{"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/posts\/2297"}],"collection":[{"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/users\/41"}],"replies":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/comments?post=2297"}],"version-history":[{"count":0,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/posts\/2297\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/media\/1378"}],"wp:attachment":[{"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/media?parent=2297"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/categories?post=2297"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/tags?post=2297"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}