6 days vs. 1 hour to Fix the Same Vulnerability: Check Point's Exposure Gap Report AMA

Wait 5 sec.

Hi r/cybersecurity — we're Michael, Omer, Aarati and Jony from Check Point's Exposure Management team. We've just finished pulling together our Exposure Gap Report, and one number kept jumping out: the time it takes to remediate a critical exposure varies massively between teams. In one sector 30% are achieving remediation of critical threats in under an hour. In others it's over six days. What's interesting is that it doesn't come down to effort. Across the board, teams implement 82–92% of recommended fixes. People are doing the work. The difference is speed, and speed turns out to be a prioritization, ownership, and process problem far more than a tooling one. We're here for the next 24 hours to talk about what actually slows remediation down, what the fast teams do differently, and where exposure management helps vs. where it doesn't. Ask us anything about remediation speed, prioritization, validation, or how we put the report together. Who are we? Jony Fischbein, Global CISO @ Check Point - u/noissues_ciso_chkp Jony is Check Point’s Global CISO and a Forbes Technology Council member, which basically means he’s spent 25+ years trying to convince people that “security” is not the same as “turning it off and on again.” Former CISO, current CISO, perpetual problem‑solver — he advises global orgs on how not to get pwned. Michael A. Greenberg, Head of Product Marketing, Exposure Management @ Check Point - u/MG_CheckPoint_EM Michael has come full circle. He begun his cyber career at Check Point, then moved to XM Cyber, then Veriti (the remediation shop Check Point acquired specifically so people would stop finding problems and start fixing them), and now back at Check Point running the Exposure Management story. Omer Leen, Manager, Technical Customer Success @ Check Point - u/SafeRemediations_123 Omer is the one who actually sits with customers while the remediation happens, which he's been doing since his Veriti days and, before that, in roles spanning aerospace IT at Elbit Systems, data/CRM work at Teva, and technical customer success at Webz.io. Translation: he's spent his whole career being the human bridge between "the plan looks great on the roadmap" and "the plan is now live in your production environment and nothing broke." If remediation dragged at your org, Omer has probably already seen why. Aarati Regmi, Cyber Remediation Analyst @ Check Point Aarati is a Cyber Remediation Analyst on the Exposure Management team, which basically means she's the one actually closing the tickets everyone else on this AMA is talking about in theory. She cut her teeth as a SOC analyst before crossing over to the "now go fix it" side of the house. If your remediation SLA has ever mysteriously improved, there's a decent chance she was involved.   submitted by   /u/Check_Point_Intel [link]   [comments]