Skip to content

Is it 'Offensive' to be Considered a Governance Vendor?

CTEM, threat intelligence and AI pentesting are converging around one job: finding and prioritizing security risk so organizations know what to fix.

I walked 450 Blackhat booths last week. If you saw Bill Brenner's coverage, or the report itself, one thing may have jumped out at you: I included threat intelligence and offensive security vendors, as well as the continuous threat exposure management (CTEM) vendors, into the catch-all category Governance. Normally, Governance tends to mean Compliance vendors like Vanta and Drata (5 total at Blackhat), with a few Asset governance players (Axonius was 1 of 2), and the handful of Third Party Risk Managers (4, with Safe being the largest there).

Normally, I struggle with CTEM, as it isn't purely an AppSec play (AppSec being focused on your applications, not all of the systems in your environment), and it isn't just an enterprise security play (which I no longer have as a separate category, since it's so intermingled with Cloud, SaaS, and Networks.

Functionally, Governance is about knowledge: understanding what is right (and wrong) in your environment. Every other space? They're about action: stopping, configuring, improving (we can have a side argument about how effective they are).

CTEM (26 vendors) is an obvious fit for Governance: you're collecting all of your knowledge about what's wrong in your environment, and putting it into one place. But why Threat Intelligence and Offensive Security?

First, let's tackle just Threat Intelligence. There isn't a strong market here for TI: just about every TI vendor has pivoted, either into detection engineering and threat hunting (landing them into the Operations Bucket), or into some form of CTEM input (43 vendors). Even Filigran, the company behind OpenCTI, is now marketing themselves as Adversarial Exposure Validation.

All of the AI Pentesting vendors, of whom there were a lot? Their messaging was almost universally a CTEM message: we'll find the actual exposed vulnerabilities that matter, so you can prioritize fixing them.

That prioritization message is key: security leaders don't generally fix software; that's the product leader problem. Instead, we govern the product teams. Even if they can't articulate it, even the security vendor marketing teams understand this.

HOU.SEC.CON CTA

Latest