VulnOps: A CISO’s Guide to Starting Implementation

VulnOps: A CISO’s Guide to Starting Implementation

🎙 Ed Skoudis 👥 70K 📅 August 12, 2026 ⏱ 29 min 👁 1K 📄 expert opinion 🧭 2026-08-15
Available in: English (current) Français

Keywords

VulnOpsvulnerability managementAICISOpatch management

Summary

Ed Skoudis, a SANS fellow, presents a 30-minute webcast on VulnOps, a new operating model for vulnerability management in the age of AI-driven vulnerability discovery. He argues that traditional vulnerability management is overwhelmed by the sheer volume of vulnerabilities discovered by AI, leading to a ‘vulnerability storm’. VulnOps, a term coined by Gadi Evron, Heather Adkins, and Bruce Schneier, applies DevOps principles to vulnerability patching, creating continuous, automated pipelines. The presentation covers the problem, the VulnOps model, and practical tips for implementation, including asset inventory, building a lab, appointing a VulnOps lead, and adopting new metrics like exposure hours. Skoudis emphasizes the need for governance-in-the-loop and canary rollouts to balance speed and safety. He also discusses the importance of communicating the urgency to boards and securing funding. The talk concludes with seven actionable tips for CISOs to start implementing VulnOps.

140 words

Critical Evaluation

Value of the Information & Strength of the Argument

The presentation provides valuable insights into the challenges posed by AI-driven vulnerability discovery and offers a structured approach to address them. The argumentation is solid, drawing on industry trends and expert opinions. Skoudis effectively explains the need for a new operating model and provides concrete steps for implementation. However, some claims, such as the projected shape of the vulnerability storm, are speculative and lack empirical evidence. The emphasis on practical strategies and metrics is a strength, making the content actionable for cybersecurity leaders.

Scientific Rigor, Source Quality, Title Accuracy

The presentation is scientifically rigorous in its use of industry sources, referencing the VulnOps paper by Evron, Adkins, and Schneier, and the upcoming CSA paper by Rich Mogull. The title accurately reflects the content, which is a guide for CISOs. The speaker’s credibility as a SANS fellow adds to the reliability. However, the lack of formal citations and reliance on anecdotal evidence from conferences and personal conversations limits the scientific rigor. The content is well-structured and aligns with the stated purpose.

179 words

Title / Content Match

The title accurately reflects the content, which provides a guide for CISOs on implementing VulnOps.

Quality & Reliability

8/10

The speaker is a recognized expert in cybersecurity, and the content is based on industry trends and practical experience. However, some claims are speculative and lack empirical data.

Key Moments

Cited Sources

  • SANS VulnOps Field Guide — Mentioned as released this morning, available via QR code
  • VulnOps Operating Model (upcoming paper) — Mentioned as a draft by Rich Mogull from CSA, to be released soon
  • VulnOps paper by Evron, Adkins, and Schneier — Coined the term VulnOps, published October 2025

Concurring Sources

  • SANS VulnOps Field Guide — Mentioned as a resource for further details
  • VulnOps Operating Model (upcoming paper) — Mentioned as a forthcoming publication by Rich Mogull

Contribution & Novelties

This presentation offers a practical, CISO-focused guide to implementing VulnOps, a relatively new concept. It provides actionable steps, metrics, and communication strategies for boards. The emphasis on governance-in-the-loop and canary rollouts is a novel contribution to the discussion.

Pour aller plus loin :

  • Vulnerability management — Overview of traditional vulnerability management.
  • DevOps — The model that inspired VulnOps.
  • CISA Known Exploited Vulnerabilities — Resource for prioritizing vulnerabilities.

67 words

Radar Profile

The radar profile shows high scores in information quantity, quality, and reliability, with a slightly lower technical level, indicating a well-rounded presentation suitable for a broad audience of cybersecurity professionals.

Reliability 8/10

💬 No comments were provided for analysis.