In the world of cybersecurity, where every second counts and every detail matters, the story of Lumen Technologies serves as a compelling case study in the power of accurate asset data. The telecommunications giant, with its rich history spanning nearly a century, embarked on a journey to rebuild its exposure management program, and the results are nothing short of remarkable. This transformation, fueled by the Axonius asset intelligence platform, has not only exposed a startling number of devices but has also fundamentally changed how Lumen approaches security, with far-reaching implications for the industry.
The Scale of the Challenge
Lumen's environment, with over 40 disconnected systems, is a microcosm of the struggles faced by many enterprises. The challenge was not just in the sheer volume of assets but in the lack of a unified view. As Geoff Krahn, Director of Product and Platform Security at Lumen, explains, "We were constantly in incident response calls with no idea who owned what." This is a common plight for many security teams, where asset inventories are often siloed and inconsistent, leading to a fragmented understanding of the overall security posture.
The Power of Trusted Data
The turning point for Lumen came with the implementation of Axonius. By reconciling data from various sources, the team uncovered a staggering 60 times more devices than they had initially known about. This revelation was not just a numbers game; it was a wake-up call for the entire organization. As Krahn notes, "It has really been an eye-opener for the organization as a whole how large our responsibilities are." This newfound visibility enabled Lumen to take bold decisions, such as migrating the majority of its infrastructure to the cloud, a move that reduced overall risk by 40%.
Beyond the Numbers
The impact of accurate asset data goes far beyond the numbers. It enables zero-day response capabilities, where critical vulnerabilities can be identified and addressed swiftly. For instance, when a zero-day vulnerability is discovered, Lumen's team can now pinpoint affected systems, determine their exposure status, and establish ownership within minutes. This near-instantaneous information is crucial for timely response and communication, as Krahn emphasizes, "Being able to get near-instantaneous information on how many assets are susceptible to a 0-day vuln, who owns them, are they externally exposed... is pivotal to timely response and communication."
The Shift to Risk-Based Exposure Management
The old model of "scan and spam" is being replaced by a more intelligent approach. By combining technical findings with asset context, business criticality, and control coverage, Lumen can now prioritize remediations based on their risk reduction potential. This shift from CVSS scores to a more holistic view of risk is a significant advancement, as Krahn explains, "Exposure management will allow us to evolve vulnerability management beyond scan and spam to intelligent risk-based requests driven by remediation actions that will deliver the most risk reduction."
The Broader Impact
The transformation at Lumen has had a profound impact on the organization's security strategy. It has led to a 10-fold increase in security investment, with leadership now having a clear understanding of the full scope of their responsibilities. Moreover, the board now relies on Axonius-generated reports for asset coverage, EDR deployment, and compliance insights, demonstrating the power of trusted data in driving strategic decision-making.
A Call to Action
Lumen's story serves as a powerful reminder of the importance of accurate asset data in cybersecurity. As Krahn suggests, "If an organization with dedicated security leadership and 40-plus inventory systems found its cyber asset management picture was off by a factor of 60, most enterprises should assume their own data carries similar gaps."
In my opinion, this case study highlights a critical aspect of cybersecurity that is often overlooked: the quality of asset data. It is not just about having a large inventory; it is about having a trusted, accurate one. The implications of this are far-reaching, impacting not just the security posture of an organization but also its strategic decisions and overall risk management. As we move forward, it is essential to recognize the value of accurate asset data and the transformative power it holds in the ever-evolving landscape of cybersecurity.
Personally, I find the shift from traditional vulnerability management to risk-based exposure management particularly fascinating. It represents a significant evolution in how we approach security, moving from a reactive to a proactive stance. This shift is not just about technology; it is about a cultural change, where organizations embrace a more holistic view of risk and take ownership of their security posture. What makes this particularly interesting is the potential for such an approach to become a standard across the industry, reshaping how we think about and manage cybersecurity.