Vulnerability Coverage

I am also discussing this topic in another discussion post: Win11 24H2 April Security Update/Vuln Issues - #10 by Dave

In our company, I need to find a way to present vulnerability data in a consolidated format that is easy to access and use. We already have many tools in place, and our asset owners are understandably reluctant to use yet another platform just to review their vulnerabilities. That is why we have relied on Power BI from the beginning, since I implemented Rapid7 Nexpose in 2020 and later transitioned to InsightVM.

The Power BI dashboard has been well accepted, and users are familiar with searching for their assets and reviewing their findings there. As mentioned in my other post, I am currently building a new dashboard that incorporates Defender data. At present, the data remains separate, and I am analyzing the gaps between Rapid7 and Defender in detail.

The next logical step is to combine InsightVM and Defender data into a single source of truth. I hope to leverage our internal AI capabilities to make this possible without creating a significant amount of manual work. I am following the same approach for findings from Insight Cloud Security, including host and container vulnerabilities.