11:30 – 11:55 am

IT teams use vulnerability scanners and vulnerability management systems. Through strict patching regimes, vulnerabilities are closed as soon as possible. Many organizations still struggle with this topic in the OT domain:

  • You can't protect what you can't see… does that always apply? So what about zero-day vulnerabilities?
  • Can IT updates also simply be rolled out in OT? Or only in Level 3?
  • Which firmware updates are really important?
  • What can we do with CVSS, EPSS v5, VSAR, KEV?

In this lecture, you will get answers to these kinds of questions. You will learn to make choices based on actual risk by considering attack vectors, exploitability, asset criticality, and more. We will also look at the significance of current developments in this context, such as Claude Mythos.

This provides you with the tools to practically implement risk-based vulnerability management in your organization.

 

Speaker: Gert Ippel

Back to the program overview

 

 

FHI, federatie van technologiebranches