ORDR Systems Control Engine and Rapid7 InsightVM
Managing Vulnerabilities with Rich Device Context
Information technology and cybersecurity teams need a proper vulnerability management program and solutions in place to continuously identify, accurately classify, prioritize, and remediate vulnerabilities.
However, there are challenges when extending vulnerability management to unmanaged and IoT devices such as building automation and security systems, medical devices, and manufacturing equipment. Unlike managed devices (for example, servers, workstations, and laptops), unmanaged and IoT devices can be difficult to locate and are potentially sensitive to active scanning. Additionally, IoT devices are often the most vulnerable since they typically lack the protection of security agents and are in service for many years without regular patching, if patching is even supported!
The exponential rise in known vulnerabilities, threat vectors, and connected devices means that organizations must adopt a two-pronged, modern approach to vulnerability management: ORDR Systems Control Engine (SCE) and Rapid7 InsightVM.
How ORDR and Rapid7 Address Complete Vulnerability Management
ORDR SCE IoT Device Security Made Simple ORDR SCE discovers every connected device, profiles device behaviors and risks, and automates remediation responses. ORDR integrates with numerous IT systems such as InsightVM, asset management, firewalls, switches, and SIEMs to create a unified view of devices, risks, threats, and network behaviors. | Rapid7 InsightVM Vulnerability Risk Management InsightVM not only provides visibility into the vulnerabilities in modern IT environments—including local, remote, cloud, containerized, and virtual infrastructure—but also clarity into how those vulnerabilities translate into business risk and which are most likely to be targeted by attackers. |
Architecture Overview: Device Discovery to Scan Execution
ORDR discovers connected devices (patient monitors, security cameras, environmental sensors, industrial PLCs, and more) over wired and wireless network infrastructure via the ORDR Sensor. ORDR SCE exchanges asset group definitions and scan results bidirectionally with Rapid7, so scans are tailored to what each device can safely tolerate:
Device Category | Rapid7 Scan Type Applied |
Patient Monitors | Light Scan |
Security Cameras | Deep Scan |
Environmental Sensors | Medium Scan |
Industrial PLCs | No Scan |
Data flow: Devices → ORDR Sensor (wired/wireless) → ORDR SCE ⇄ Asset Groups / Scan Results ⇄ Rapid7 InsightVM.
ORDR automatically discovers and classifies all devices with granular context including make, model, hardware and software version info through passive monitoring and deep packet inspection. ORDR seamlessly sends this device intelligence and context to a customer's InsightVM instance, giving Rapid7 a detailed understanding of which assets to scan and the type of scan suited to each device. Currently, organizations with devices that may be sensitive to active scans, such as hospitals or manufacturers, often exclude entire subnets from scanning to avoid service disruption, increasing the risk of missing critical vulnerabilities. ORDR allows customers to open these subnets to scanning by creating highly granular and accurate device inclusion and exclusion lists, enabling assessment without risk of disruption.
ORDR also learns from Rapid7's advanced scanning engine to augment ORDR's security analytics. ORDR incorporates Rapid7 scan results into ORDR's device risk score and visibility dashboard to display a comprehensive risk assessment of each connected device.
Benefits of Integrating ORDR SCE with Rapid7 InsightVM:
ORDR works with Rapid7 to seamlessly discover all connected assets including IoT, IoMT, and OT devices. The joint solution enables Rapid7 to perform the right scan at the right time regardless of the device type, location, criticality or role within the organization. Many vulnerable IoT/OT devices discovered by Rapid7 cannot be patched or updated. ORDR automates the application of compensating controls to safeguard these devices by sending protection policies directly to firewalls, switches, wireless, or NAC systems. Similarly, infected devices can be quickly isolated through existing network and security devices.
Comprehensive Coverage ORDR's identification and classification of lightweight, agentless devices allows administrators to quickly exclude specific IoT devices or categories from active Rapid7 scans, opening network segments to vulnerability scanning that had previously been excluded. | Smart Scheduling ORDR tracks utilization patterns for critical devices, allowing administrators to schedule vulnerability scans for times when devices are not in use, minimizing disruption and operational risk. |
Optimized Scanning Using ORDR's detailed insight into device types, scan sensitivity, and their critical role within the organization, Rapid7 scans can be tailored to each device. | Proactive Protection Rather than blocking or quarantining critical IoT devices after infection, ORDR's segmentation policies create barriers that protect vulnerable devices while still enabling essential services. |
Combining ORDR's unique device intelligence with Rapid7's advanced vulnerability intelligence provides organizations with the ultimate solution to efficiently manage risks while reducing service disruption and time to remediate.