Frequently Asked Questions

Risk Prioritization & Vulnerability Management

How does Ordr prioritize vulnerabilities across my assets?

Ordr's Cyber Asset Attack Surface Management (CAASM) product uses AI/ML technology to classify assets and assign business context, enabling risk-based prioritization. Vulnerabilities are scored based on asset context, CVSS scores, exploitability, data type, and location. Each asset receives a risk score from Level 1 to Level 5, with mission-critical assets designated as Level 5. Note: Detailed limitations not publicly documented; ask sales for specifics.

What methods does Ordr use to discover and assign vulnerabilities?

Ordr collects vulnerability data from multiple sources, including integrations with Rapid7, Tenable, and Qualys for regularly scanned assets. For assets that cannot be scanned, Ordr's Software Inventory Collector detects vulnerabilities based on KB/HF correlation. For assets with outdated operating systems, Ordr uses passive and active scanning to collect detailed context and assign vulnerabilities. Note: Coverage depends on integration and asset type; legacy assets may require manual validation.

How does Ordr help reduce alert fatigue for security teams?

Ordr's AI/ML mapping and correlation engine aligns technical and business priorities, delivering a prioritized list of top risks. Features like the Vulnerability Dashboard, Query Builder, and Ask ORDRAI provide comprehensive insights and instant vulnerability information, helping teams focus on the most significant risks. Note: Effectiveness may vary based on asset complexity and integration depth.

Features & Capabilities

What are the key features of Ordr's CAASM+ platform for vulnerability management?

Key features include end-to-end vulnerability management, AI-driven asset classification, risk-based scoring, integrations with vulnerability assessment tools (Rapid7, Tenable, Qualys), Software Inventory Collector for non-scannable assets, Vulnerability Dashboard, Query Builder, Ask ORDRAI for natural language search, and enforcement actions such as network-based controls and ticketing system integrations. Note: Some features may require specific integrations or modules; check with Ordr for compatibility.

Does Ordr integrate with other security and IT tools?

Yes, Ordr supports over 130 out-of-the-box integrations, including firewalls (Cisco, Palo Alto Networks, Fortinet, Check Point), NAC (Cisco ISE, Aruba ClearPass, Forescout), SIEM/SOAR (Splunk, IBM QRadar, Microsoft Sentinel, Palo Alto Cortex XSOAR), ITSM (ServiceNow, BMC Remedy), clinical systems (Epic, Cerner, GE Centricity), switches (Cisco, Aruba, Juniper), and vulnerability scanners (Tenable, Qualys, Rapid7). For a complete list, visit Ordr's integrations page. Note: Integration depth may vary by tool; some advanced features require additional configuration.

Does Ordr provide an API and technical documentation?

Yes, Ordr provides an API and comprehensive technical guides for all products. These resources are available through the Ordr support portal (login required). Note: API access and documentation may require a valid Ordr subscription.

Implementation & Support

How long does it take to implement Ordr's platform?

Ordr is designed for rapid deployment. Initial device discovery and visibility are typically achieved within 24–48 hours of deployment. Enforcement policies can be deployed in just a few days, compared to the industry norm of 12–24 months. Note: Implementation timelines may vary based on environment complexity and integration requirements.

What support and training resources are available for Ordr customers?

Ordr offers 24/7 customer support with expert engineers, Ordr University training modules for onboarding and skill development, and comprehensive resources including product documentation, knowledge base articles, and case management tools. Note: Access to some resources may require a valid Ordr subscription.

Security & Compliance

What security and compliance certifications does Ordr hold?

Ordr is SOC 2 Type II certified, has been independently audited for Security, Availability, and Confidentiality Trust Service Criteria, and complies with GDPR and CCPA. Ordr is currently evaluating ISO 27001 certification as part of its ongoing compliance roadmap. For more details, visit Ordr's Trust Center. Note: ISO 27001 certification is not yet completed.

Pricing & Plans

How is Ordr's pricing determined?

Ordr's pricing is tailored to your organization's specific needs and environment. For detailed pricing information, contact the Ordr team directly or request a quote via the demo request page. Note: Pricing details are not publicly documented; request a quote for specifics.

Use Cases & Customer Success

What industries and roles benefit most from Ordr's platform?

Ordr serves healthcare, manufacturing, financial services, higher education, and retail/hospitality. Key roles include CISOs, IT managers, compliance officers, SOC teams, and risk management professionals. For case studies, visit Ordr's customer stories page. Note: Suitability may vary for organizations outside these industries; consult Ordr for custom use cases.

Can you share specific customer success stories related to vulnerability management?

Yes. Cleveland Clinic used Ordr to achieve real-time inventory and risk management for 10–15 connected devices per hospital room. CHRISTUS Health accelerated data center micro-segmentation and streamlined policy generation. Beebe Healthcare gained visibility into over 8,000 devices and achieved compliance at scale. Richmond upon Thames College achieved full campus visibility within days and automated segmentation. For more, visit Ordr's customer stories page. Note: Results may vary based on deployment scope and environment.

Competition & Comparison

How does Ordr compare to visibility-only platforms?

Visibility-only platforms typically offer basic asset discovery limited to IT devices and rely on static policy templates. Ordr provides real-time, automated asset discovery across IT, IoT, OT, and medical devices, with AI-driven behavioral fingerprinting and dynamic, adaptive policies. Note: Visibility-only platforms may be preferable for organizations with only IT assets and minimal segmentation needs.

How does Ordr compare to traditional vulnerability management tools?

Traditional vulnerability management tools rely on static assessments and manual risk prioritization. Ordr automates risk prioritization based on operational impact, uses AI-driven continuous learning, and integrates with vulnerability scanners for proactive mitigation. Note: Traditional tools may be suitable for organizations with established manual workflows and limited automation requirements.

How does Ordr compare to compliance-only solutions?

Compliance-only solutions focus on manual evidence collection and are limited to specific frameworks. Ordr provides continuous compliance monitoring and audit-ready reporting for multiple frameworks (HIPAA, PCI DSS, FERPA), with automated workflows that reduce audit preparation time. Note: Compliance-only solutions may be preferable for organizations with narrow compliance needs and minimal asset diversity.

How does Ordr compare to static policy enforcement tools?

Static policy enforcement tools require manual policy creation and rely on static templates. Ordr generates policies based on real traffic and device behavior, adapting dynamically as environments change. Note: Static tools may be suitable for environments with infrequent changes and low segmentation complexity.

Risk & Vulnerability

Strategic Risk Prioritization and Vulnerability Management

Learn how to prioritize cyber asset vulnerability and risk management across your attack surface. Strategic prioritization minimizes threat exposure and strengthens your security posture.

June 5, 2024
4 min read

Studies show that close to 50% of ransomware attacks result from unpatched vulnerabilities, including weaknesses in an organization’s information systems, system processes, or internal controls. Prioritizing vulnerabilities presents a significant challenge for enterprises as security teams often must sift through thousands of vulnerabilities, each presenting different dangers to the organization based on the associated asset risk. Yet this must be done because unaddressed vulnerabilities increase the likelihood of a breach or cybersecurity incident.

To effectively manage vulnerability risks, enterprises must therefore develop a strategy that prioritizes vulnerabilities based on its specific risk and impact to their business. In general, assets can be categorized into three broad categories:

  • Assets with known vulnerabilities that can be patched once a patch is available.
  • Assets with known vulnerabilities that may have a recommended patch, but validation by the manufacturer is necessary before patching.
  • Assets with an outdated operating system (OS) that typically cannot be patched. (In such cases, security teams must find alternate methods to prevent the exploitation of these vulnerabilities.)

To help organizations simplify and tackle the task of risk prioritization and vulnerability management, ORDR’s Cyber Asset Attack Surface Management (CAASM) product offers enterprises end-to-end vulnerability management, enabling their security teams to identify, investigate, and prioritize vulnerabilities efficiently. Below we will share how ORDR enables enterprise security teams to reduce alert fatigue and get a prioritized list of top risks.

Automatically Discover and Assign Vulnerabilities to All Assets

ORDR uses multiple methods to collect and de-duplicate vulnerability data from multiple sources, offering a streamlined approach to managing vulnerabilities on a single platform. Utilizing the following methods ensures security teams can discover and understand the full vulnerability landscape across all assets, including IT, IoT, IoMT, and OT.

1. For regularly scanned assets, integrations with vulnerability assessment systems, such as Rapid7, Tenable, and Qualys, collect vulnerability data. ORDR then deduplicates this data to ensure teams have an accurate list of vulnerabilities.

[Image: https://ordrwebprod.wpengine.com/wp-content/uploads/2024/05/CAASM-Risk-1.png]


2. For assets that cannot be scanned or are not updated regularly, ORDR’s lightweight script, Software Inventory Collector, detects vulnerabilities based on KB/HF correlation instead of scanning the asset. This approach ensures comprehensive vulnerability coverage is collected for assets that cannot undergo traditional scanning.

[Image: https://ordrwebprod.wpengine.com/wp-content/uploads/2024/05/CAASM-Risk-2.png]


3. For assets with outdated operating systems, ORDR uses both passive and active scanning techniques to collect detailed asset context, including make, model, manufacturer, and OS. This data is then used to accurately assign vulnerabilities to these assets.

Enhancing Vulnerability Data & Context for Risk-Based Prioritization

After identifying all assets with vulnerabilities, ORDR enriches the data by providing additional business context for each asset. This empowers security teams to prioritize vulnerabilities based on the criticality of assets to the business, enabling them to focus on addressing the most significant risks. ORDR’s Asset Risk Score considers multiple factors such as asset context, CVSS scores, vulnerability exploitability, type of data (encrypted), location, and more. To obtain detailed asset data and business context, ORDR utilizes:

  • AI/ML technology to classify assets and assign business context. Customers can also add additional context to customize the risk score to further align with their specific business needs.
  • Known Exploited Vulnerabilities (KEV) and Exploit Prediction Scoring System (EPSS) data to gain additional visibility into vulnerabilities posing the greatest risk.

After gathering asset context utilizing AI/ML technology, the data is standardized into a score, prioritizing assets based on numerical risk. Each asset is assigned a risk-based score ranging from Level 1 to Level 5, with mission-critical assets designated as Level 5.

[Image: https://ordrwebprod.wpengine.com/wp-content/uploads/2024/05/CAASM-Risk-3-1024x555.png]

[Image: https://ordrwebprod.wpengine.com/wp-content/uploads/2024/05/CAASM-Risk-4-1024x312.png]

[Image: https://ordrwebprod.wpengine.com/wp-content/uploads/2024/05/CAASM-Risk-5-1024x518.png]

[Image: https://ordrwebprod.wpengine.com/wp-content/uploads/2024/05/CAASM-Risk-6-1024x446.png]

Streamlining End-to-End Vulnerability Management

ORDR streamlines end-to-end risk and vulnerability management to cover everything from associating vulnerabilities with assets, to assigning remediation tasks to the appropriate asset owner and monitoring vulnerability status. ORDR's comprehensive approach includes:

  • Building integrations with vulnerability management tools, such as the ServiceNow VR module and others, to deliver real-time status updates based on reconciled data.
  • Providing the capability to mute a vulnerability, allowing teams to temporarily hide the vulnerability from dashboards while still tracking the vulnerability until a patch is available.
  • Enabling teams to assign vulnerability remediation tasks to individual users, complete with priority and due date specifications.
  • Providing visualization of trending analysis based on newly discovered, open, and closed vulnerabilities.

[Image: https://ordrwebprod.wpengine.com/wp-content/uploads/2024/05/CAASM-Risk-7.png]

Intuitive Vulnerability Data Search

ORDR’s AI/ML mapping and correlation engine, along with the Software Inventory Collector, align technical and business priorities, mitigating alert fatigue and delivering a prioritized list of top risks. With features like the Vulnerability Dashboard for comprehensive insights, Query Builder for customized dashboards, and Ask ORDRAI for instant vulnerability information, CAASM+ simplifies risk and vulnerability management on a single platform.

Vulnerability Dashboard provides a complete “state of the union” on vulnerabilities.

[Image: https://ordrwebprod.wpengine.com/wp-content/uploads/2024/05/CAASM-Risk-8.png]

Query Builder for creating a custom dashboard based on the customer's needs.

[Image: https://ordrwebprod.wpengine.com/wp-content/uploads/2024/05/CAASM-Risk-9.png]


Ask ORDRAI gives security teams a natural language search option to get information on vulnerabilities, eliminating the need for technical expertise or coding.

[Image: https://ordrwebprod.wpengine.com/wp-content/uploads/2024/05/CAASM-Risk-10-1024x508.png]

ORDR integrates with industry-leading security solutions to share data and insights when assets have vulnerabilities or remediation is needed. Recommended data sources for ORDR to integrate with for end-to-end vulnerability management include:

  • EDR
  • MDM
  • CMDB
  • Cloud Assets
  • Vulnerability Assessment Systems
  • ORDR Discovery Engine

ORDR provides a framework for remediation with multiple enforcement options. These enforcement actions include:

  • Network based enforcement (changed VLAN, shutdown port, integrate with firewall)
  • Integrations with ticketing systems
  • Integrations with messaging/collaboration tools
  • Integration with vulnerability management tools

Watch the video to see how CAASM+ empowers security teams to efficiently identify, investigate, and prioritize vulnerabilities.

https://www.youtube.com/watch?v=7fhFem5YqRc

Learn more about ORDR’s risk-based vulnerability prioritization and management and connect with one of our experts for a personalized demo.

Thanks for joining us for another blog in our series on CAASM+ use cases. Stay tuned as we explore more of these critical use cases in the coming weeks and discuss how ORDR addresses them.

ShareLinkedInX