Resource Library
Solution BriefsVisibilityRiskFebruary 5, 2024

Rapid7 and ORDR Solution Brief

SOLUTIONS BRIEF RAPID7

ORDR Systems Control Engine and Rapid7 InsightVM

Managing Vulnerabilities with Rich Device Context

Information technology and cybersecurity teams need a proper vulnerability management program and solutions in place to continuously identify, accurately classify, prioritize, and remediate vulnerabilities.

However, there are challenges when extending vulnerability management to unmanaged and IoT devices such as building automation and security systems, medical devices, and manufacturing equipment. Unlike managed devices (for example, servers, workstations, and laptops), unmanaged and IoT devices can be difficult to locate and are potentially sensitive to active scanning. Additionally, IoT devices are often the most vulnerable since they typically lack the protection of security agents and are in service for many years without regular patching, if patching is even supported!

The exponential rise in known vulnerabilities, threat vectors, and connected devices means that organizations must adopt a two-pronged, modern approach to vulnerability management: ORDR Systems Control Engine (SCE) and Rapid7 InsightVM.

How ORDR and Rapid7 Address Complete Vulnerability Management

ORDR SCE

IoT Device Security Made Simple

ORDR SCE discovers every connected device, profiles device behaviors and risks, and automates remediation responses. ORDR integrates with numerous IT systems such as InsightVM, asset management, firewalls, switches, and SIEMs to create a unified view of devices, risks, threats, and network behaviors.

Rapid7 InsightVM

Vulnerability Risk Management

InsightVM not only provides visibility into the vulnerabilities in modern IT environments—including local, remote, cloud, containerized, and virtual infrastructure—but also clarity into how those vulnerabilities translate into business risk and which are most likely to be targeted by attackers.

Architecture Overview: Device Discovery to Scan Execution

ORDR discovers connected devices (patient monitors, security cameras, environmental sensors, industrial PLCs, and more) over wired and wireless network infrastructure via the ORDR Sensor. ORDR SCE exchanges asset group definitions and scan results bidirectionally with Rapid7, so scans are tailored to what each device can safely tolerate:

Device Category

Rapid7 Scan Type Applied

Patient Monitors

Light Scan

Security Cameras

Deep Scan

Environmental Sensors

Medium Scan

Industrial PLCs

No Scan

Data flow: Devices → ORDR Sensor (wired/wireless) → ORDR SCE Asset Groups / Scan Results Rapid7 InsightVM.

ORDR automatically discovers and classifies all devices with granular context including make, model, hardware and software version info through passive monitoring and deep packet inspection. ORDR seamlessly sends this device intelligence and context to a customer's InsightVM instance, giving Rapid7 a detailed understanding of which assets to scan and the type of scan suited to each device. Currently, organizations with devices that may be sensitive to active scans, such as hospitals or manufacturers, often exclude entire subnets from scanning to avoid service disruption, increasing the risk of missing critical vulnerabilities. ORDR allows customers to open these subnets to scanning by creating highly granular and accurate device inclusion and exclusion lists, enabling assessment without risk of disruption.

ORDR also learns from Rapid7's advanced scanning engine to augment ORDR's security analytics. ORDR incorporates Rapid7 scan results into ORDR's device risk score and visibility dashboard to display a comprehensive risk assessment of each connected device.

Benefits of Integrating ORDR SCE with Rapid7 InsightVM:

ORDR works with Rapid7 to seamlessly discover all connected assets including IoT, IoMT, and OT devices. The joint solution enables Rapid7 to perform the right scan at the right time regardless of the device type, location, criticality or role within the organization. Many vulnerable IoT/OT devices discovered by Rapid7 cannot be patched or updated. ORDR automates the application of compensating controls to safeguard these devices by sending protection policies directly to firewalls, switches, wireless, or NAC systems. Similarly, infected devices can be quickly isolated through existing network and security devices.

Comprehensive Coverage

ORDR's identification and classification of lightweight, agentless devices allows administrators to quickly exclude specific IoT devices or categories from active Rapid7 scans, opening network segments to vulnerability scanning that had previously been excluded.

Smart Scheduling

ORDR tracks utilization patterns for critical devices, allowing administrators to schedule vulnerability scans for times when devices are not in use, minimizing disruption and operational risk.

Optimized Scanning

Using ORDR's detailed insight into device types, scan sensitivity, and their critical role within the organization, Rapid7 scans can be tailored to each device.

Proactive Protection

Rather than blocking or quarantining critical IoT devices after infection, ORDR's segmentation policies create barriers that protect vulnerable devices while still enabling essential services.

Combining ORDR's unique device intelligence with Rapid7's advanced vulnerability intelligence provides organizations with the ultimate solution to efficiently manage risks while reducing service disruption and time to remediate.

Frequently asked questions
How can we gain visibility into unmanaged IoT and OT devices on our network?
ORDR automatically discovers and classifies both managed and unmanaged connected devices across your infrastructure without requiring agent installation. The solution uses passive monitoring to identify devices and their vulnerabilities, eliminating blind spots that traditional IT-only tools miss.
What's the best way to prioritize vulnerabilities across mixed IT and IoT/OT environments?
The Rapid7 InsightVM and ORDR integration prioritizes vulnerabilities by actual business risk and context rather than just severity scores. By combining InsightVM vulnerability data with ORDR's device intelligence, security teams can focus remediation efforts on exposures that matter most to their specific infrastructure.
Can we streamline our vulnerability remediation workflow for connected devices?
Yes—the integrated solution accelerates remediation decisions by providing device context alongside vulnerability data, eliminating the need to manually correlate information across tools. Security teams can move directly from risk assessment to actionable remediation plans with integrated visibility and prioritization.

This resource is published by ORDR, the connected asset security company. ORDR delivers AI-powered visibility, risk assessment, and automated protection for IoT, OT, and IoMT devices across healthcare, manufacturing, government, and financial environments. Browse all resources →