Cisco Vulnerability Management (formerly Kenna.VM by Kenna Security, which was acquired by Cisco in June of 2021), is a vulnerability management platform featuring real-time cyber-risk analysis and predictive modeling based on intelligence feeds and global attack telemetries to provide accurate, reliable risk prioritization and protection.
N/A
Microsoft Defender for Cloud
Score 8.5 out of 10
N/A
Microsoft Defender for Cloud is a Cloud Security Posture Management (CSPM) and Cloud Workload Protection Platform (CWPP) for Azure, on-premises, and multicloud (Amazon AWS and Google GCP) resources.
For user end devices this product has worked great for us. We have been able to find vulnerabilities/risks with certain software in bulk on devices and implement fixes for them very quickly. CVM has also provided us visabity on all our devices that we never had before and we can close gaps security wise a lot faster knowing now where problems are at
If you need to proceed with pay as you go service then go ahead with Microsoft Defender for Cloud. This could be expensive in the long run but if the organization usage is slightly less than then this would suite the purpose. Also, it has the latest threat updates, so you're future proof in terms of potential treats.
Automation is crucial to managing sprawl and the additional complexity that comes with it. SOC management workbooks and process automation give significant flexibility.
The Security posture score and Security Alerts are neatly centralized and offer me crucial information quickly.
Defender for Cloud avoids the common compromise of simplicity for completeness (former Azure Security Center). The security warnings and advice go into great detail while remaining current and useful.
UI/UX. It can get a little messy when navigating around with all the flyouts in the Azure portal which can be frustrating, particularly when under time pressure.
The query languages for the queries and workbooks are another language that needs to be learned - it would be nice to have kept it closer to T-SQL or something like that to minimize the need to learn new syntax.
Adding cost estimations to the security recommendations would really improve the experience.
It is a great product that integrates nicely when running an Azure platform and even multi-cloud environment. Not looking for point-solutions but a suite that answers most requirements. It is very comfortable being able to use KQL, workbooks and automation that is native to the azure platform
CVM provides a very easy to understand and use interfaces. Dashboards and reporting are compiled nicely when risk meters are created. After initial setup of software cisco onboarding teams do an amazing job going over all areas of this software to provide best overall usability of the product. Against other tools setup and usability is at a higher standard
We run a flavor of multiple products and CVM enhances/complements those tools by pinpointing where the vulnerabilities are at on our network. Intune and Automox being products CVM works well with when its time to patch affected systems. Tenable we used prior to CVM and its product was too complex and clunky and always had issues with asset duplication. CVM simplified vulnerability scanning and made it a lot easier to manage compared to Tenable
I believe Microsoft Defender for Cloud stacks up well against the other tools we looked at. It is native to the Azure platform and provides the same insights as the other tools. We selected Microsoft Defender for Cloud because it integrates well with the Azure resources and gives the needed insight, security alerts and recommendations.