CyberWiseCon Europe 2025

Krasimir Kotsev: The Art of Vulnerability Management - Practical Application of Cyber Triage

42:42 · 20 May 2025 – 23 May 2025 · YouTube

About this talk

In this session, Samir Kotev presents an in-depth analysis of vulnerability management, emphasizing its evolution into vulnerability intelligence for 2024. He outlines the challenges organizations face in identifying and remediating vulnerabilities, particularly the overwhelming numbers that can exceed 60,000 for a typical corporate infrastructure. Kotev advocates for prioritizing vulnerabilities based on their criticality to the organization's assets using methods such as threat modeling and real-time threat intelligence. He discusses the importance of understanding the distinction between vulnerability scanning and penetration testing, stressing that while the former identifies issues, the latter tests the actual exploitation potential. Kotev also introduces Kikimora, a platform designed to aid organizations in managing vulnerabilities more effectively by automating processes and providing actionable insights.

Full transcript

ladies and Gentlemen please welcome our next speaker CRA Samir kotev presenting the topic the art of vulnerability management practical application of cyber triage I've been doing cyber security for 15 years and they said that's impossible you're so young I started when I was 14 as a gr hat hacker let's say because when when you're 14 you're hacking things here and there without actually knowing what you're doing

and with the time actually my passion evolved into something more professional so as of today uh I'm the founder of kikimore iio and soul cyber so these are two companies the first one is a vulnerability management and orchestration platform which allows you to keep away the Hackers from your infrastructure and uh the second one is a company specialized in guess what pen testing offensive security and vulnerability

assessments today we're going to be talking about uh vulnerability Management in 2024 and actually I'm calling it vulnerability intelligence because it's not management anymore it used to be management 20 years ago when we didn't have huge organizations with huge amount of FY interconnected systems right when we had about 2 3,000 vulnerabilities and you can man manage this one you can remediate you can patch that's okay Patch

Tuesday works for everyone nowadays that's simply impossible so it's an art actually to cope with all the vulnerabilities out there you need some specific methodology or approach for this one so imagine that today is your first day as a security manager in a big Corporation maybe a nuclear power plant or an energy company and you've been tusked to find out the vulnerabilities of the company what's the

first step you start by actually identifying the it connected systems in the company right so you start by discovering the infrastructure the network IP connected systems and day number two you found out that the company has actually the team is telling you we have an approximate of 3,000 devices which is it doesn't make sense to you because it doesn't mean anything so you run your vulnerability Discovery

you check your attx surface modules and your threat intelligence feeds and you find out that actually the total number of systems is 3,170 the activity actually took about two weeks to complete with all the vulnerability scans the agent data which gathered can you guess how many vulnerabilities you have approximately that's a real-time data an upated one from our of our customers just try to guess blindly What's

the total number of vulnerabilities and weaknesses detect Ed for the 3,000 systems 25,000 there was a a good one say again 100K okay you're close 62,000 K that's for 3,000 vulnerabilities now a lot of you will say okay but this data is meaningless I mean how can you actually have 62,000 vulnerabilities well the answer is you don't actually out of this 60,000 62,000 to be more precise

you need to find find out what's the most critical to your specific organization not all of these are actually U affecting your infrastructure not all of these are exploitable not all of these are affecting external assets of yours or critical assets of the company so we need to find out what are the most critical 5% which are endangering our organization right out of the 62,000 about 5%

are actually critical to your and they need immediate approach so they cannot wait for the next patching life cycle or for the next penetration test they need to be remediated immediately how do we find out what's the most 5% we start by actually Gathering the information with some vulnerability scans with uh some it security Audits and guess what we end up with a huge vulnerability database because

we have scanning in place but we also need penetration testing right because we have some critical web applications or mobile applications on top of this one we are is to 27,000 certified so we have some compliance SK we are also auditing the cloud infrastructure not only this one but we also need to Mark pass and fail for the compliance officers when they need this information there is

a bunch of vulnerability Discovery methods out there usually more than 10 in a company in in the average company after after actually several spending several weeks of sorting the data we end up with an Excel sheet covering all the vulnerabilities out there with system identifier domain name IP address system owner remediation owner and so on so it's great we have an Excel sheet and in this big

organization you can expect these 3,000 devices to be managed by a team of 10 or 15 people maybe so what are you doing you're sending the Excel sheet to all the responsible parties are they out of this one they create jur tasks in two hours right 62,000 records it's it's quite easy you just create the jur tickets or you assign into the the office desk personnel and

then voila it's fixed but it doesn't work like that vulnerability management nowadays is quite different and actually I'm going to show you why now what's the issue actually the activity usually takes about let's say you have a team of 13 people security expertise in in your company it takes about 58 days to actually prioritize assign assess um and prepare for remediation the 62,000 vulnerabilities so what's the

problem here well 58 days is about two months and that's official statistics it only takes about 12 days for a vulnerability to be exploited actually one vulnerability is mostly exploited in the first month of Discovery so if you fix it on the second month it means that you're probably already compromised well what do we do actually we pay a lot of money for Security Experts that's like

five or six people we pay them a lot of money to remediate to assess the findings to tell us what's the most critical for the company but guess what half of the money we're spending on cyber security is pure loss which means that it's an operational cost and these Security Experts which we hired are doing sorting and documenting documentation of the vulnerabilities instead of actual security research

so it means that our resources are completely useless and we are not utilizing them in the best possible way right what do we do to actually know how to remediate the 5% most critical vulnerabilities well first of all everybody should start with tread modeling and I'm surprised to see how many organizations are not doing tread modeling can you raise hands how how many of you actually performed

a proper threat modeling for your applications and you actually investigated the the boundaries one hand thank you two three that's that's great so you know your threats I guess uh that's a company which knows what is the The Logical boundaries what is the front end of the application who is using it where is the data going in the back end how is it uh sanitized how is

the data input validated so once you do the threat model link you actually understand what your users are doing and what the potential hacker will try to do to compromise your company because the interface for the for the users is the same which the the hacker will be using so that's what we start with the first model is based on assets so what are the most important

Assets in the company once I know this I can actually start creating my thread model the second one is based on data flow so you simply start creating beautiful diagrams about what happens with the data where does the data enter the application where does it go to the uh the database what user is having access to the the information at this level so there is a lot

of tools by the way you can use the oasp thread Dragon for example which is quite a good tool to to help you with the the thread modeling there is a lot of games by the way a lot of cyber security games actually it's professional tools but in the form of um a game interactive game which is helping you to document your threat model you can rely

on models like stride which is the the Microsoft model or pasta uh so stri for example is focusing on uh spoofing tempering uh repudiation information disclosure uh denial service and elevation of privileges so these are like the most important things in in your thread modeling the next one is thread model based on network and system connectivity so when you're making your thread model you you need to

consider how are the systems interconnected to each other where are they based who has access which system is externally exposed which one relies in the DMZ which one is uh local area network so you need to consider the data flow you need to consider uh backups and cor storage uh servers you need to consider all the Gib repositories which are sitting out there and waiting to be

compromised you need to think about a lot of things and this is happening during the the threat model right once you have this one we can actually move to the next phase we start fixing vulnerabilities but as I said you can't fix it all it's impossible now 3,000 assets is not even a big number that's like a small to medium mediumsized company there is there is a

lot of organizations which are like averaging 10 or 20,000 assets so you can imagine you you can't fix it all so choose what your most critical to your business choose the 5% how well first we need to focus on the unknown what is the unknown a lot of companies they don't know their assets so I'm surprised how many companies are just using utilizing the attack surface modules

of the vulnerability scanners and they're like this is not our asset do we have it is this ours who is managing this one who is responsible so they don't know you have a bunch of assets which you're unaware of and guess what because you don't know about them you cannot patch you cannot update so these are the first assets that somebody's going going to compromise the second

one is actually known and unknown what is the unknown somebody I know my assets but I don't vulnerabilities why because I never started a vulnerability scan I never initiated security audit or what I did was I started a network scanner which gives me like the the overview of the system it rather gives me system information and metadata but no actual vulnerabilities it's just the the information gathering

part I think all the security officers uh they love running vulnerability scans remotely without authentication because everything looks good the organization is quite safe everything is green but in reality you you didn't detect anything you have a lot of vulnerabilities which are unknown for your known assets and then the third component is maturity which is I know my assets I know my vulnerabilities now let's focus on

remediation or more mitigation if remediation is not possible at that very moment a lot of systems actually cannot be patched because they they need 27 for uptime so when you want to patch something or you want to update you need to raise change requests they need to be approved by the management but this is a business critical asset or component for the organization you cannot do it

so next step is know your assets and blind spots first of all identify the most critical assets of the company so if you have 3,000 systems roughly about 10 20 or 50 systems maybe is going to be priority high priority systems for you or applications the rest can only lead to further attacks and to further uh pivoting in the network but is no critical resources and should

not be considered with critical priority so the thing is when you know your vulnerabilities make sure you immediate the vulnerability is affecting the most critical assets first I see so many companies nowadays who are trying to fix all the critical vulnerabilities but guess what sometimes a medium vulnerability affecting a KP key production environment in my company is so much more critical compared to a critical and exploitable

vulnerability affecting my back office printer right so focus on the most important assets first focus on the owner of the asset and not only this one but the asset priority what's the business function is it an Earp system is it a CRM system is it my critical business application which my users are using and they keep my business running or is it just a Dev version of

my application which is running somewhere on a local server in my office there is a huge difference and last but not least where is the location of the asset because very often especially let's say an interconnected networking assistance one company with many branches across the the continent or the world they forget about their locations they just run a data center somewhere out there and they forget about

their assets so they're focusing on the important assets they're protecting the life assets the key production environment but the replicated asset which is um a cold backup uh standby server complete replica of the protection server it gets unknown nobody takes care of this one right so once we know the Assets Now we need to select the proper scanning technique another myth is that penetration testing is the

ultimate solution or it doesn't work like that penetration testing is expensive a lot of companies cannot afford pen testing and if you have 3,000 assets I'm definitely not going to select pen testing for all the assets out there I would rather run a vulnerability scan maybe a network based one but as I said there is a common misconception that network based Canan provides visibility vulnerabilities not really

it gives you the the perspective of the most exposed vulnerabilities over the most on the most exposed assets other than that non-authenticated or non- agent-based vulnerability scan is completely worthless it doesn't provide any actual vulnerability or weaknesses data so what I'm suggesting for most critical servers of yours better have an agent Bas scanning establish an agent based scanning it has an administrative access it pulls all the

vulnerabilities out there and it's so much better compared to the network scanning does it mean that we should leave Network scanning aside no but when I have agent based scanning I see all the vulnerabilities when I run a Network remote scanner I actually see the most critical vulnerabilities first and the most ones so there is another myth that cloud is secure by Design I'm running my application

in the cloud I don't need pen testing I don't need security they're taking care of me yeah but cloud is like a complex thing you can have SAS you can have pass you can have infrastructure as a service so the cloud is nothing more than a traditional infrastructure in a remote location so and they give you some fancy uh interface where you can toggle the things where

you can toggle network security zones you can uh turn on and turn off endpoint protection or uh EDR but at the end of of the day if you don't configure the cloud security it's not secure it's not secure by Design you're going to get compromised sooner or later and then you get on the CEO meeting and you say well we're protected we were on the cloud yeah

but you didn't protect the cloud right so you're not protected at all penetration testing now penetration testing when you get to the point where you you hit pentesting activities it means that you have no more CVS to uh to scan to identify usually pen testing efforts would not generate CVS in the the majority of the cases so pen testing is I'm actually trying to break into something

I'm trying to break the window and get into the house compared to vulnerability scanning which is I observe the house I see a bunch of open windows and maybe a door which can be easily bypassed and I create my report based on this one without actually trying to get into the house now when we talk about that's a completely different topic uh a lot of companies I

see industrial control system companies out there are afraid to run scatter security audits which is a huge mistake because due to the nature of these devices and the specific protocols in use usually these are not updated which makes them the most vulnerable on the other side they are the most isolated as well so as long as you keep the B hackers outside of your scatter Network you

are quite secure but if you let them by chance by some other mistake into the scatter Network you better run security aies for the scad network because otherwise it's going to be a huge boom out there so yeah that's a very important component and then another misconception I see a lot of companies selecting purchasing a vulnerability scanner and then they say well I scan the the domain

there is no vulnerabilities or the Contra they scan the IP the server and they say well five vulnerabilities so my application is secure application vulnerability scanning is so much different than Network vulnerability scanning one solution nesus another qualis tenable rapid 7 I'm not advertising all the solutions out there they have app scanners and network scanners and kubernetes scanners three different things right so we talked about the

sca uh also we need to consider what are the where is the asset base so if the asset is based in the external infrastructure well apparently it's the most vulnerable one so we need to prioritize if the asset is based somewhere behind a bunch of firewalls and intrusion prevention system Cloud flare and web application firewall very hard to get in I mean it might be vulnerable but

it might be a critical vulnerability and exploitable one and the maturity of the exploit code may be pretty high but nobody can get there so it cannot be exploited how about the code everybody forgets about the software code so the software code there is something which is called sast which is static analysis of the Cod and dust Dynamic analysis of the code people very often confuse the

two um terms SAS is when we are actually running a scan of the code itself and not the application we're not interactively playing with the application we're not trying to punch the the application we're not trying to to inject something which is which will break the application we're simply providing a tool with access to the s to the source code and the tool is actually auditing the

source code one is not excluding the other I would suggest both but only for the critical assets it doesn't make sense if you have as I said key production environment staging death and so prepro and so on doesn't make sense to run four different scans for the four different instances only the pro environment is public facing that's the one my users have access to so I would

focus my expenses and efforts on the one which is used by users um on the other side the dynamic scanner is quite useful because it is it is playing with the application like a user so it's trying to inject code some SQL injections cross scripting is trying to play to to break the the the logic of the application to the best extent possible because the scanners are

dummy you know they they cannot access the application the pen testing usually is so much more beneficial than the vulnerability scanner because it's examining the business logic it's trying to think like a human it's is performed by a human by a living human not by AI or ml or something out there it's an actual Personnel who is trying to break into the application considering where does the

traffic go what am I going to to do with the data if this is a banking application maybe my accountant wants to steal money from me right so their lowlevel user can try to elevate their privileges into a high privileged user so this the D scanner would not consider but the pentester will definitely do manual auditing so that's actually all these things are manual auditing to a

certain extent now the D scanner is an automatic tool but if you just run the scan and based on these results you don't do any additional actions yes it's an automatic process but it gets you know so what you need is a manual assessment of the results and then when you see that there is a potential vulnerability well the pentester will try to break in he will

try to play with the vulnerability to exploit it further to create an exploit if there is no available right they they'll try to actually exfiltrate data they will try to get the to the next mile to The Last Mile real time threat intelligence can you guess how how many of the vulnerabilities are exploited at zero days like percentage some rough number 20 okay 62 62% of the

days there is something which is called epss and it's not very common nowadays but it's very very important so that you can prioritize your vulnerabilities epss is a predictability scoring system in compar reason to the traditional CVSs which nowadays companies are mostly utilizing CVSs provides static information about the vulnerability what's the exploit code maturity do I need to be having mnik to exploit it do I need

to have access administrative access do I need to be inside the network there is also the temporal part which is how is my infrastructure changing if somebody gets into the the infrastructure by exploiting somewhere are they going somewhere inside are they pivoting and trying to exploit another system or they will stay where they are this is what CVSs is doing however CVSs doesn't give me information about

is this vulnerability actively exploited as of today is it actively exploited if I'm running um a hospital application for example is it actively exploited in the hospital environment out there in the world is it a Zer day how many trctor groups are currently trying to exploit this vulnerable ability so that's what epss brings me that's the information it's beautiful versus the static information of CVSs epss bring

so much more context to the organization so it's actually considering the life envir the realtime environment the actual data nowadays today not two weeks ago or five months ago when the vulnerability was observed by some security researchers or hackers so that's something I would strongly recommend every company to uh to use as part of their vulnerability program just to give you an example I'm using Mion but

it could be any other uh threat intelligence solution out there I'm not getting paid by mandant to to to advertise them just want to show you the comparison according to the MVD CVSs rating the same vulnerab uh there there is 40% medium vulnerabilities 46% 46.8 High vulnerabilities now the same data observed through the Trad intelligence solution you can see how different are the results because the data

on the right picture is a static data which was generated over time the data on the left side is an up to-date active data which shows if there is mare Associated today maybe today there is no but tomorrow there will be and this information will be updated so this information you can also extract from the DPSS scoring system and make it work for you according to my

expertise and the one of my colleagues these are the most important threat intelligence factors to consider during your vulnerability prioritization first of all know what of the CVS are exploited in the wild you have 62,000 vulnerabilities how many of them are exploited in the wild 5 10 or 20 you have 62,000 vulnerabilities but only about 100 are weaponized so if you don't have a weapon vulnerability in

the most cases it cannot be exploited it's like having a rifle but without ammunitions so if it's not weaponize it's useless until somebody will create ammunition a payload for this to be exploited how many of them are exploited by mware and this mware can be quite dangerous it can infect a lot of systems in my network the mware can spread and infect the whole infrastructure I would

put Priority on this to be honest and trctor exploitation how many of these are actually actively exploited it could be that I discovered a vulnerability and I reported somebody created a CV for this one the official entity and it was not exploited for eight months not a single try or maybe five or 10 tries by someone out there should I be concerned I would be so much

more concerned if the CV was exploited 15,000 times yesterday now let's take into consideration a use case which uh I have created in my in my practice for um an energy company they discovered a vulnerability which is um 6.8 medium now the numbers are changed if you actually observe this CV this specific CV the CV the CVSs score is different but this is just an example so

that you can see how you can make your calculations to work for you so if we consider 6.8 a medium vulnerability but there is no the CV is not actively trending in the wild or it is I'm adding points to the risk score if the CV is exploited by malware well no it's not so I'm not adding the score is it exploited by zero day no it's

not so I'm not adding to the risk score is it what is the exploitation state is it confirmed or is it unknown if I if it's unknown I should not be so much so concerned with this one but if this is confirmed to exploit I would put some points on this one now let's focus on the asset criticality is it affecting a key production environment or a

critical application in my organization yes plus one score that's so much more critical compared to uh it uh a security compared to an asset which does not require any it security at all if I have again A pler or a printer in my office which is not connected to any other system it cannot create any more damage I will not even consider about consider implementing security measures

on this one if this is a presentation laptop which I'm just using for events and conferences I have no actual data no company data on my computer should I Implement strict security measures I will not waste time or money with this one asset exposure so again if the asset is publicly facing everybody can see the asset all of you in this room can see the asset and

you can try to exploit it tomorrow I mean I'm pretty scared already so I'll increase the risk but if this is an asset which is very well isolated a bunch of firewalls proper Network segmentation the asset doesn't allow for external connections I would not increase the risk why would I do it and last but not least a lot of companies actually forget about hardening hardening is actually

the real deal and you can eliminate about maybe 70 80% of the vulnerabilities by applying proper hardening to your systems so if I have let's say Microsoft Office macros vulnerability which allows for remote code execution so so somebody can execute a code and steal my database from my computer that's pretty dangerous especially if my database is not encrypted it's it contains sensitive um well yeah but if

I disabled Microsoft macros by Design in my GP for example and I would not allow for a code to be executed on my system again doesn't make sense to me yeah let let them try to exploit it I mean they're getting nowhere because Microsoft Microsoft is not exploitable at this point because I hardened my asset or is the vulnerability requires connection to the command and control server

yeah but I disabled external connections from my system system so so what I'm going to get infected but I cannot my system cannot communicate with the control server of the hackers so it makes them it makes it useless I I would suggest adopting the the strategy to your specific organization but basically these are that's the triage that's the component you are considering in the context of your

specific organization to protect it CV critical doesn't mean anything nowadays you have 100 of thousands of these but when you consider this criteria then you narrow down to 50 or 100 vulnerabilities which are important organization now few basic measures what can you do to help yourself we talked about it you can have multiple security audits you can Implement some strong defenses but at the end of the

day not everybody can afford it I work with a lot of lot of startup companies finte companies mette companies they don't have the money they need budget to expand to evolve they need budget to make their brand awareness to develop their sales and marketing nobody wants to invest in cyber security at this basic level of development what can you do about it these are the three basic

steps which you can Implement at no money network security protect your assets it eliminates about 60 70% of the vulnerabilities if you have a proper Network segmentation I cannot stress enough how many issues this one is resolving by itself the second one application white listing how many of you have application white listing on systems okay now I see more hands but again it's like 10 people so

application white listing is already available in your windows infrastructure and you can have identical means of securing applications which is in general harder to run on Linux systems but there is ways to protect it and it's just a matter of configuration you don't need to purchase expensive Solutions out there and spend huge amount of money thousands of Euros on this one you just need to have someone

to configure this for you based on your specific needs and by this one you're eliminating about half of the vulnerabilities out there and last but not least system hardening that's the ultimate goal if you have a golden image if you have one image which you're Distributing across the company and this one has some predefined security measures in place well you're eliminating so many of these vulnerabilities if

you only consider the center for internet and security benchmarks usually you have for the Windows systems you have about 400 available security controls to implement start with this you can have 100 or 50 you can have 200 security controls it's it's some start you already ahead of the hackers you can have the you can have it completely tailored to your needs um I see a lot of

companies selling complex MDM solutions for huge amount of money but guess what you have security hardening for your mobile devices as well for Android and iOS so you can simply go and configure these devices with certain Benchmark which is suitable to the the organization needs to the specific Department to a specific group of people maybe the accountant needs one set of rules but the it guys in

the company they need a bit more right we have different needs everybody has needs uh and this is something quite easy to to implement uh now for example you can use Enzo to implement hardening across all the systems in your organization you select the policy the the controls which you want to apply you distribute across the systems and all the next day everything stops working so yeah

but the the reality is on the next day everything is protected and you should always consider what will stop working indeed uh now you can reach the the CIS benchmarks but you can also uh create your custom list pretty much all the application vulnerability scanners support CIS benchmarks and you can trade them taer based on your needs thank you very much for your attention I hope that

with this information now you can fortify your defenses and you can make use of what you just learned cyber security triage and vulnerability intelligence nowadays is based on trade intelligence data live data hardening of the asset how protected is my asset exposure of my asset and how important is this asset for me and for my organization thank you okay we have a few questions for you people

were actually very active during this one so Prett ni what do you think about the upcoming cyber resilience act will that change the game of vulnerability management it's already there you have ISO 270001 you have pcss you have nis2 they overlap about 80 80% uh but did you read it did you actually prepare for this one I think the same will be with cyber ailan act some

rules are written and it's a matter of interpretation and understanding nobody saying specifically what you need to place can you still hear me yes I think so uh so I I think it's it's a great thing to to happen but it brings maturity in the organizations it's not about the specific security controls which are outlined in the the Cyber resilience act it's a great thing don't get

me wrong I I think it must be there and more companies must be conscious about the the personal data about the sensitive information uh Trade Secrets you should protect yes and the Cyber resilience act gives you a framework how to do it and where you should be looking for to fortify your infrastructure I think it's changing the the way of thinking it's changing the mentality it's it's

like gdpr before gdpr we knew that we have to protect our personal data but how many we're actually protecting it right so now this one is establishing rules to follow which companies they usually know that they have to follow these rules anyway but they don't because there is no a regulation to enforce it so I think more companies will be forced to protect the data nowadays because

of the the residence okay the next question we have is do you think the idea of priority leads towards perimeter security instead of a defense in depth model both you should have layer defense if you only have perimeter defense you're getting nowhere you're receiving a fishing email you open the the attachment or the file they are inside so your parameter security is is already busted so balance

that with the idea of prioritizing yeah so um I again put my focus on prioritizing my assets and where are my assets based I I need to have perimeter defense that's for sure and that's not a complex thing to to establish actually it's a pretty easy configuration change uh however if I don't have a proper segmentation between my different Networks if I don't have proper segmentation between

my departments between my locations across Europe for example uh well parameter security would not help you it's a complex approach you need to have multi-layer defense otherwise you're nowhere okay then we have a question about how can vulnerabilities be communicated developers in a way that prevents them from feeling overwhelmed considering the fixing the issue helps new development uh by using kikimora so that's what we've been working

on for the last three years because we started as Security Consultants specialized in vulnerability assessment and Pen testing uh but we were asked to actually vulnerabilities scan assess prioritize assign and have them remediated because we're not remediating but we're asking people to remediate and we're pushing we're like the the guy with the stick who is did you remediate did you fix this one so we we got

tired of doing this and that's why we created kikimora iio which is a vulnerability management solution and it allows you to orchestrate all the scans and tests and Audits and Cloud security audits then you can inside our solution you can assess you can prioritize based on the importance of the asset you can see the evidence for each vulnerability the remediation steps there is an AI assistant which

is helping you with steps how to reproduce the vulnerability how to remediate how critical it is how um affected assets you have how many of them are going to get compromised tomorrow uh so yeah by by or by creating your own solution I mean it's a matter of process we automated the process by creating a software application but you can achieve it without a software application as

well you can actually create like um a dashboard or uh intera interactive reporting with tools freely on the market with powerbi for example or uh similar so you you have your ways if you if you don't have budget for cyber security tools you can make it by yourself but as I said storing the data in an Excel sheet is not the best approach and it doesn't doesn't

work okay and then I think we should go with one more question there are several others but we won't have time for them all and you will be at the ask me anything stand afterwards presumably so you can ask them directly but why is kikim Mora's risk use case Matrix better than the matrices of other companies um all right so we tailored kikimora to the specific needs

of small organizations right now there is a lot of vulnerability scanners out there a lot of great Enterprise Solutions and we have a lot of great competitors uh mostly in the US by the way not not so much in Europe though however what we did we saw that a lot of companies they don't have the internal expertise to to fix it so they cannot afford to hire

a pen tester security auditor vulnerability analyst uh system administrator and so on they don't have the need for this they only need like 10 or 20 hours of Consulting per month so that's why we connected our service and Consulting knowledge with the solution so with the kikimora subscription every user gets x amount of hours of security Consulting per month so we can spend three hours on pen

testing two hours on secure C auditing 5 hours on vulner ability assessment and whatever shoots your needs um that's one thing then the other one is nowadays data needs to be manageable in a much more easier and understandable way so that's why we created an AI assistant which is helping you by digesting your current vulnerability database reaching out to MVD for the threat into uh for the

weaknesses information what is this one how to remediate how to reproduce and so on and now we are releasing also um thread in feed so that you can know how critical and how actively exploited the vulnerability is today not not two weeks ago perfect thank you and last thing do you know how many vulnerabilities has an average Windows system all of them that's a very good answer

1,000 actually 1,000 security misconfigurations weaknesses and vulnerabilities um I'm going to be here myself and you can find us in the the corridor me and my team are um having a boot stand uh and thank you for the opportunity to be gold partner of the the event so you can meet us and talk more about security what