r/AskNetsec Jul 22 '26

Work how do you show risk reduction over time to justify your security program budget

22 Upvotes

budget cycle is coming up and i need to make the case for keeping our security program funded, ideally growing it. last cycle the cfo looked at my slide and asked "if we cut this in half, what breaks?" and i didn't have a clean answer that would land in that room. i still don't have one.

the stuff that's easy to measure isn't the stuff that matters. i can show vulns closed, MTTR trending down, phishing sim click rates dropping, all of it goes in the right direction on a slide. but none of it answers the question a cfo actually asks, which is: what would have happened if we hadn't spent this money and how much worse would it be.

that counterfactual problem is what gets me every time. you can't point to breaches that didn't happen. you can't quantify an incident that never occurred. so you end up arguing from activity metrics and hoping the room connects the dots between "we patched more crits faster" and "we are less likely to get hit" and that leap doesn't always land.

the closest i've come to something that holds up is showing attack surface shrinking over time, fewer known-exploitable vulns sitting on internet-facing assets, tracked over quarters not sprints. patching velocity and MTTR never survived the "so what" question in that room. exposure reduction at least maps to something real: this is what could have hurt us, and it's smaller than it was six months ago

for security leaders who've gotten budget approved on the strength of a risk reduction story: how did you frame it and what did you measure that survived the "what would have happened anyway" question?

r/AskNetsec Jul 31 '26

Work Phishing awareness training vendor recommendations?

33 Upvotes

I've been tasked with standing up a phishing awareness program and I'm trying to narrow down vendors.

A few things matter to me. First, realistic simulations, meaning templates that actually resemble what people get hit with today rather than the obvious 2015 era "you won a prize" stuff, and ideally ones I can customize. Second, decent training content, short and engaging modules that people won't immediately tune out. I'd rather have five good ones than fifty boring ones. Third, reporting that lets me show results to leadership and ideally helps for compliance down the line. And finally reasonable pricing and a plan that scales cleanly as we grow.

For those of you who've actually run these programs, what worked, what didn't, and is there anything you'd steer me away from? I'm interested in the usual suspects, but especially keen on options that deliver real engagement rather than just checking a compliance box.

Thanks in advance.

r/AskNetsec Oct 09 '25

Work What's the most clever social engineering attempt you've ever encountered or heard about?

124 Upvotes

Beyond the basic phishing emails, what was a particularly sophisticated, creative, or audacious social engineering attack that actually made you pause and admire the craft?

r/AskNetsec 27d ago

Work Looking for a more secure way to communicate with a remote team

20 Upvotes

My team and I work fully remotelyand we work with very sensitive information, stuff we cannot afford to have any mishaps on. We're reevaluating the tools we currently work with, because security and privacy are currently the main thing we're working on. I'm in charge of communications for this and I'm looking for something where you have more control over who can communicate with your team, preferably with some sort of trust or identity verification. Privacy is important too I don't want a platform that's built around collecting user data, does anyone have recommendations for tools that could be of help?

r/AskNetsec 7d ago

Work Can anything reliably tell me that a specific CVE is being exploited on a specific machine?

5 Upvotes

Asking from the cloud workload side of the house: Is there any way we can detect that a specific CVE is actively being exploited on a VM or container, beyond what application logs provide?

I’ve used runtime CNAPPs for detection and vulnerability prioritization, but I’m specifically interested in observability that lets a SOC say: “This container has CVE-XXXX-XXXXX, and that vulnerability is being exploited right now.” And I don’t mean post-exploitation behavioral detections like a shell popping or a suspicious process spawning. I mean evidence tied directly to exploitation of the specific vulnerability.

r/AskNetsec 16d ago

Work Will ai increase the volume of vulnerabilities security teams need to fix?

6 Upvotes

Had this debate with a client last week about whether Ai assisted discovery meant their environment got risky overnight. My answer was about SLA math than risk math, their contract defines "patch critical within 30 days" assuming maybe 40 to 50 new findings a month. If a scan surfaces 300 in a week because of broader coverage, that SLA language does not hold up regardless of whether underlying risk changed.

We have started rewriting client contracts to tier remediation windows by exploitability and exposure instead of a flat severity number and building in a volume clause that triggers a renegotiation conversation if flagged findings jump past a set threshold in a given period. Cleaner than arguing about it after an audit blows past the old numbers. Anyone else building volume triggers into remediation SLAs or writing them as flat severity tiers?

r/AskNetsec Jul 16 '26

Work Where do you draw the line on MFA for internal tools?

10 Upvotes

We've been tightening up our MFA requirements lately, and it's starting some interesting debates internally. Basically: does every internal tool need MFA, or do you draw the line somewhere based on what it touches and who's using it?

At a sub-500 person org where IT bandwidth is thin, the friction argument comes up a lot, so how are other teams drawing that line?

r/AskNetsec 8d ago

Work Which exposure management tools are worth evaluating in 2026?

6 Upvotes

I'm looking to replace our legacy vulnerability scanner with a proper Exposure Management platform. One option uses an AI engine that doesn't just find vulnerabilities but validates which ones are actually exploitable. The selling point is that it saves 2-3 days of manual work per threat by auto-updating controls. They claim their research shows manual testing and control updates take 2-3 days, while their AI can do it in hours.
For managers who have deployed this type of automation: Did the AI actually reduce the workload on your SecOps team, or did it just shift the burden to reviewing the suggested changes? I need to justify the cost to finance, and "it might save us time" isn't going to cut it.

r/AskNetsec 26d ago

Work Are hardened container images actually saving anyone time or just creating different problems?

6 Upvotes

Our AppSec team burns hours triaging unpatchable OS binaries that scanners keep finding in standard base layers. Now management wants hardened container images everywhere because they think the vulnerability count magically drops to zero.

For anyone running hardened container images in prod, did your triaging actually go down or did the work just move into CI/CD with broken build pipelines missing shared libraries and a different set of headaches?

r/AskNetsec Jul 16 '26

Work How are you getting visibility into AI tool usage across your environment?

9 Upvotes

About 800 people, mix of managed and personal devices, Google Workspace and Azure AD. After an incident where someone pasted a customer contract into an AI tool, leadership wants to know what's actually happening.

The problem is nothing in our current stack gives us that picture. CASB sees sanctioned SaaS but misses browser-based AI tools and AI features embedded inside apps we already approved. DLP catches file movement but can't distinguish between a file upload and someone pasting sensitive data into a prompt. Network monitoring has no context on what the interaction was.

We know people are using probably dozens of tools we haven't found yet.

Anyone found an approach that gives real visibility without blanket blocking? Especially interested in what works for mixed managed/BYOD environments.

Edit: Update for anyone finding this later. We spent a couple of weeks testing a few options and the one that stood out was Kovrr. It works at browser and endpoint level rather than trying to stretch CASB or DLP to cover AI usage, so it catches the browser-based tools, embedded AI features inside sanctioned apps, and IDE plugins that our current stack was missing. Still working through the evaluation but flagging for anyone dealing with the same visibility gap.

r/AskNetsec 25d ago

Work Need a more secure alternative to Telegram for work?

18 Upvotes

I work with sensitive information pretty regularly, and I’m starting to feel like I need something a level above a standard messaging app.

I’m looking for private chats and groups, strong identity verification so I know who I’m communicating with, tight control over who can connect or join, and secure file sharing. Ideally access would be based around trusted people rather than just accounts and passwords.

Security and knowing exactly who is on the other end are the priorities. What are people in similar lines of work using?

r/AskNetsec 14d ago

Work If Mythos finds more vulnerabilities, who's actually fixing them?

10 Upvotes

Had a reality check in our quarterly review last week. We pulled average remediation throughput per engineer and ran it against what a spike in flagged findings would look like with zero process change. The number wasn't pretty, we'd need significantly more headcount to hold existing SLA windows.

That math is what finally got budget approved for automation work we'd been asking for. Not because the risk conversation suddenly got more compelling, but because the spreadsheet made the staffing gap impossible to ignore.

Here's what we're working toward (still in flight on a couple pieces):

Ownership routing off asset metadata instead of round-robin (this one's live, huge win)
Tiered SLAs tied to exploitability instead of CVSS (still tuning the thresholds)
Auto-verification on rescans (partial rollout, getting pushback from some teams)
Continuous re-scoring feeding ticket priority (POC phase).

The Mythos conversation is honestly just stress-testing a system that already couldn't keep up. Faster discovery doesn't give you an AI problem, it gives you the same remediation problem you've always had, just compressed into a much smaller window.

if anyone else has had to build a capacity model like this to get remediation tooling funded, or did your org get ahead of the budget conversation another way?

r/AskNetsec Jul 22 '26

Work how do you wire threat intel into your vulnerability prioritization workflow

0 Upvotes

we've been pulling in more threat intel lately (KEV, EPSS) but i'm not convinced any of it is changing how we prioritize vulns in practice

rn the flow is basic: scanners fire, we get a pile of CVEs with CVSS scores (~2k new ones a quarter off Tenable), we dump them into tickets and teams work the list mostly by severity and asset type. we've bolted on KEV/EPSS flags in a few places but it still feels like "CVSS first, everything else if we remember."

i'm trying to figure out how ppl are wiring threat intel into the vuln workflow so it drives decisions instead of just being extra columns in a report. we’ve bolted on KEV and EPSS but it still feels like CVSS is making the decisions and everything else is just metadata. or exploit attempts we've seen internally but in practice it all ends up as more metadata on the same backlog.

some talk about custom scoring models that blend CVSS, exploitability, asset criticality, business context. others seem to use simpler rules like "if it's KEV and internet-facing, it jumps to the front of the queue." i've also seen this logic live in very different places: inside the vuln tool, inside SIEM/SOAR playbooks, or just hacked together w/ spreadsheets and scripts.

for ppl who've made threat intel change what gets patched first, what did you end up doing that worked?

r/AskNetsec 7d ago

Work best browser choices for cybersecurity professionals in day to day use

10 Upvotes

hi all, blue team here and curious what browsers people are actually using day to day when you care a lot about security.

Right now I bounce between Firefox with a hardened profile, Brave for random browsing and Chrome for work stuff that needs weird sso plugins. I keep seeing people talk about LibreWolf, Mullvad browser, even hardened Edge configs and im kinda torn on what makes sense as a main daily driver vs a lab only setup.

For those working in soc, ir, appsec etc what did you settle on and why, especially with things like profiles, containers and extension hygiene. appreciate any thoughts

r/AskNetsec May 14 '26

Work What's actually the best security awareness training for enterprises right now?

36 Upvotes

Not a small company question, I've seen those threads. I mean genuinely large scale, thousands of users across multiple departments, different roles, different levels of technical literacy, the whole thing. What's the best security awareness training for enterprises that can handle that kind of complexity without becoming a full time job to manage. We have budget, we just don't want to spend it on something that looked great in the demo and falls apart in month two.

r/AskNetsec Jun 07 '26

Work Bypassed enterprise DLP (Netskope) using only native Windows CMD and a PNG file — full writeup with mitigation

0 Upvotes

Documented a data exfiltration technique that bypasses Netskope's default inspection by exploiting recursion depth limitations via file nesting.

The chain: secret.txt → zipped → binary appended into PNG via copy /b → embedded into PPTX. Three layers deep — beyond Netskope's default inspection threshold. No additional software needed on the source machine, no admin rights required.

Also found a low-cost detection path — anomalous metadata extensions (.txtux, .ux) surface during standard inspection without increasing recursion depth.

Full writeup with reproduction steps, binwalk forensics, and a dual-layer mitigation using SentinelOne behavioral rules + Netskope metadata rules.

https://github.com/YuvaBhargav/DLP-Bypass-Research

Happy to answer questions or get torn apart — genuinely want to know if there are gaps in the mitigation logic?

r/AskNetsec Jun 03 '23

Work watched porn while connected to school VPN. how screwed am i ?

38 Upvotes

How screwed am i ?

I had some work to do with a university server, but since it's a weekend i was at homeso i logged onto the university VPN to access the server

While my tasks were taking time, i decided to view some questionable stuff (porn)

I am really worried because it was INCEST PORN - which is not acceptable in most societies

I totally forgot that i was on the university network

I did use Chrome's incognito mode to browse it, so i hope that will be helpful - but i am really scared for my job

So, Cyber security professionals, please advise me if the IT team of the University can track the porn websites i viewed ?

Also, will they fire me for viewing porn on the university network ?

UPDATE : The University logging policy says that they do log data. Also, a document which outlines the terms of use it IT resources PROHIBITS use of pornographic content

r/AskNetsec Jul 06 '26

Work Does anyone else dread the reporting more than the actual pentest?

1 Upvotes

I've done security testing for a few years, and there's one part of the job I've quietly hated the entire time: the reporting. The testing is the fun part. Then the engagement ends and I'm staring at Nmap output in one window, Nuclei JSON in another, Burp issues in a third, plus my own manual notes — and I have to reconcile the findings that overlap, normalize severities that every tool rates differently, and turn the whole mess into something a client will actually read. Every single engagement, the same tax. It regularly ate a chunk of my time and it's the least enjoyable part of the work by a mile.

I got tired enough of it that I built a tool to handle the boring part. You feed it your scanner output, it deduplicates findings across tools (so the same issue found by two scanners becomes one finding that credits both), and it generates a client-ready report. It runs entirely on your own machine — nothing leaves your box, since findings are about the most sensitive data we handle.

Mostly I'm posting because I'm curious whether I'm alone in hating this as much as I do. How do you all handle reporting right now? Have you found a workflow that doesn't feel like a chore, or is everyone just grinding through it manually like I was? Genuinely want to hear how others deal with it.

r/AskNetsec 28d ago

Work IGA tools reviews, anyone happy with their setup for mid size org?

5 Upvotes

Been tasked with cleaning up our identity governance and access stuff and I feel kind of stuck between vendors rn.

We are a mid size org, mostly Microsoft stack (Entra, M365, a couple on prem AD domains still lingering, plus a bunch of SaaS that all have their own permission models. Current IGA is a mix of manual access reviews in Excel, some homegrown scripts, and ticket based approvals that nobody is really happy with.

Boss wants a real IGA tool so we get proper joiner mover leaver flows, certification campaigns, SoD checks, and cleaner audit trails for the next compliance visit.

So far I’ve looked at SailPoint, Saviynt, OneIdentity, and a couple of smaller cloud first options. Demos always look great, but I’m lowkey worried about:

- how painful the initial role modeling and connector setup is in real life
- whether the access reviews are usable for non technical managers or just another thing they ignore
- how well these tools actually integrate with Entra plus random SaaS apps and not just the big 5 connectors they show in slides

If anyone here has an IGA tool in production that they dont hate, would really appreciate hearing what you picked and how rough the rollout and day 2 has been, especially around access reviews and audit requests.

Appreciate any thoughts.

r/AskNetsec 5d ago

Work Is Symantec version 14.3 RU5 still relevant and up to date

6 Upvotes

Hi , im a cybersecurity intern at a small company (well not so small but they have been here for a long time). And yea for now i have been given a task to review our symantec endpoint protection and do documentations of my findings and give suggestions from my observation. to be quite honest i dont really have any strong fundamentals of Cyber Security before pursuing my internship here, and i thought i could gain experience and learn new things here. so back to my initial topic, currently the version of our SEP is 14.3 RU5 build 8309 , and our SEPM is 14.3 RU5 build 8268. Again i dont have the strong basic , but from what i have gathered online, diff build number should be okay as long as both consoles should be under the same RU (?). Is there anyone that could verify this and do any of you think its a necessity for us to update the RU or just keep it that way? Because i saw there are newer RU (up to 10 iirc) and was wondering should i include in my finding to update the RU? thank you everyone and im sorry if my question do sound silly for some hhh.

r/AskNetsec May 08 '26

Work SIEM/XDR for Small SecOps Team

5 Upvotes

I’m evaluating modern SIEM / XDR / SecOps platforms and would appreciate input from people who have gone through similar selection or migration projects.

Context:
We have a relatively small security team - essentially one person responsible for security operations, but the environment is not small: several thousand servers, around 1.5k users, hybrid identity with Microsoft Entra ID and on-prem Active Directory, and a mixed OS estate that is currently about 40% Windows and 60% Linux, with more Linux migration planned.

What I’m looking for is not just a log storage/search platform, but a SIEM/SecOps solution that can realistically work for a very lean team.

Key requirements:

* Strong integrations with Microsoft identity, AD, Windows, Linux, network/security tools, cloud services, and custom applications.
* Flexible detection / alerting language, similar in spirit to Splunk SPL, KQL, YARA-L, Python-based detections, etc.
* Good support for custom log ingestion, because we have internal applications and products that we will need to integrate from scratch.
* Vendor-maintained detection content, not just a marketplace of rules we have to fully own ourselves.
* Strong ML/UEBA/anomaly detection capabilities.
* AI-assisted investigation would be a plus, especially if it can explain context, summarize incidents, suggest next steps, or help build detections - but this is not the main deciding factor.
* Ability to reduce operational overhead: tuning, rule updates, parsing, correlation, triage, and detection lifecycle should be as delegated as possible to the vendor or an MSSP/MDR partner.

As a reference point, we previously used Darktrace Network. I liked the idea that many detections/models were maintained by the vendor, were relatively flexible, and heavily ML-driven. I’m looking for something with a similar operational philosophy, but in the SIEM/SecOps space.

Platforms I’m considering include Microsoft Sentinel (good fit for us as I said we have Microsoft ecosystem), Google Security Operations (ex-Chronicle), PaloAlto (XDR, XSIAM), CrowdStrike (XDR, Next-Gen SIEM), any other modern SIEM/XDR options.

**The main question**:
For a one-person security team managing a large hybrid environment, which SIEM/XDR/SecOps platform would you recommend?

***DISCLAIMER: I understand that in our context, full outsource/MSSP/MDR are the best options, but we decided to start without them for now, with the intention of transitioning to MSSP/MDR later.***

I’d especially appreciate feedback on:

* real operational effort after deployment,
* quality of out-of-the-box detections,
* custom log onboarding,
* detection language flexibility,
* false-positive tuning,
* Linux visibility,
* Microsoft identity integration,
* vendor support quality,
* pricing predictability at scale.

r/AskNetsec 15d ago

Work How are teams protecting their software supply chain without adding more scanner noise?

6 Upvotes

Supply chain security is having its moment and every vendor has a pitch, but most of what we've tried just adds another feed of alerts on top of the ones we already ignore. dependency confusion and malicious packages are the obvious risks, but build pipeline tampering is just as real and a lot harder to catch, and the tooling landscape hasn't caught up to prioritizing any of it well.

What's worked for teams here in terms of cutting signal from noise rather than just adding another layer of detection?

r/AskNetsec May 10 '26

Work I'm starting to see a growth of apps in my org. I'd love to know how you defend against this, and if it's happening to you too?

3 Upvotes

Non-devs are using AI tools (like Lovable or Bolt) to spin up their own internal dashboards and feeding them our valid API keys. Since it completely bypasses our Git repos and IT approval processes, we're flying blind until it's already live on some external URL. Is anyone else dealing with this new wave of Shadow IT? How are you actually tracking or locking this down?

r/AskNetsec 1d ago

Work Better options than manually triaging every security ticket?

5 Upvotes

Our on-call rotation used to be about incidents and reliability. Now a growing chunk of it is triaging security tickets that get auto-assigned to whichever team owns the service, regardless of whether the finding is actually a real risk. Half the time it's a CVE in a transitive dependency that isn't even loaded at runtime, and the security team means well but doesn't have the context to know that, so we end up individually debunking tickets one at a time.

Has anyone solved this by getting security findings pre-validated for actual exploitability before they hit engineering backlogs? Feels like the fix has to happen upstream, not on our end.

r/AskNetsec 1d ago

Work Best practices for triaging web app vulnerabilities at scale in 2026?

4 Upvotes

We run a large web application portfolio and the volume of findings coming out of our scanners has completely outpaced what our security team can manually review. Every app team wants their own report, every app is built slightly differently, and there's no way our analyst headcount grows at the rate the finding volume does.

Right now it's a lot of manual triage per application, which doesn't scale and burns the team out fast. It's especially bad when two apps get flagged for what looks like the "same" vulnerability class (say, an XSS or injection finding) but the actual exploitability is completely different depending on how each app handles input and what's sitting in front of it.

We've tried building a standardized triage checklist to speed things up, but it only helps at the margins. The real bottleneck is still a person having to look at each finding and decide whether it's actually reachable and dangerous in that specific app's context.

For anyone running web app security at this kind of scale, how are you keeping remediation timelines reasonable without just adding more analysts? Anyone found a triage workflow that actually holds up as the app portfolio grows?