enterprisesecuritymag

Enterprise Security Magazine

Cortex Xpanse by Palo Alto Networks
Evaluate and Assess Security with Cortex Xpanse

Matt Kraning, Chief Technology Officer, Cortex, Palo Alto Networks and Tim Junio, Senior Vice President of Products, Cortex, Palo Alto Networks, Cortex Xpanse by Palo Alto NetworksMatt Kraning, Chief Technology Officer, Cortex, Palo Alto Networks and Tim Junio, Senior Vice President of Products, Cortex, Palo Alto Networks
The most significant breaches in the last decade occurred due to overlooked and vulnerable IT assets rather than phishing attacks, says Matt Kraning, CTO of Palo Alto Networks. This alarming trend is quickly rising with the increasing popularity of a remote work culture (where every employee’s home serves as a virtual branch office) and increased reliance on the cloud. And, making the problem worse, attackers can scan the entire internet at machine speed to find and exploit vulnerable, publicly exposed assets, whether organizations know about those assets or not.

In this environment, even cybersecurity experts need help in understanding what IT assets are publicly exposed on the internet as their attack surface changes continuously on-premises, in the cloud, and in subsidiary networks. If you’re relying on manual processes, it can be impossible to maintain constant visibility on multiple cloud vendors, third-party partners, security flaws that emerge during M&A, and any remote network employees may be on.

Cortex Xpanse assists security experts with their various needs in attack surface management (ASM), infrastructure governance, cloud security, compliance, and more, by providing the same continuous visibility into a company’s security gaps as attackers have, so security teams can remediate issues before they are exploited. With an outside-in view of everything clients own, Xpanse provides an accurate and continuously updated inventory of all global internet-facing assets, allowing clients to discover, evaluate and mitigate attack surface risks and exposures.

Palo Alto Networks’ Cortex product suite is engineered to provide enterprise-wide visibility, prevention, detection, and response, and automation capabilities. The enterprise’s acquisition of Expanse Inc. in 2020 augmented Cortex’s abilities to collect and attribute data on the internet and expose untracked vulnerabilities that might compromise an organization.

Initially seeded in 2012 by DARPA (Defense Advanced Research Projects Agency), the ‘mad science’ arm of the U.S. Department of Defense, the Xpanse team realized that protecting exposed critical infrastructure is only possible when organizations have a complete, current, and accurate view of all their digital assets.

“Our foundation and value lie in helping our partners discover and defend IT systems that they didn’t even know existed but are nevertheless vulnerable to attack by malicious actors over the internet,” says Matt Kraning, CTO of Cortex at Palo Alto Networks.

Xpanse continuously discovers and monitors clients’ digital attack surfaces across their networks to ensure that security operations teams have no exposed blind spots. Additionally, since the path of least resistance for attacks lies in unmanaged systems with outdated or nonexistent security, Xpanse assesses information such as device types, connections to other assets and owners, and possible vulnerabilities. The solution scans 4.3 billion IP addresses to uncover gaps before attackers discover them. This helps firms prioritize their cyber risks and determine whether their exposed assets should be taken down, patched, or monitored.


Our foundation and value lie in helping our partners discover and defend IT systems that they didn’t even know existed but are nevertheless vulnerable to attack by malicious actors over the internet

Palo Alto Networks’ interaction with a Fortune 100 healthcare provider is an excellent example of how the Xpanse solution bolsters IT infrastructure. The client had over 2,000 workstations, which they were unaware of, directly exposing vulnerable remote access services to the public internet. Using Xpanse to detect and remediate these systems, they not only reduced the number of such systems by over 95 percent in less than a month but also attributed all internet-connected assets and monitored them under a single roof.

With a wealth of ASM knowledge at its behest, Palo Alto Networks wields Cortex Xpanse to streamline cybersecurity processes and inspire trust. The Cortex team comprises interdisciplinary experts from elite institutions bringing in a vast knowledge base that extends beyond just cybersecurity. Their expertise in building large-scale algorithms, researching data science, and working in military intelligence provides clients with fresh perspectives when solving their challenges.

Company
Cortex Xpanse by Palo Alto Networks

Headquarters
Santa Clara, CA

Management
Matt Kraning, Chief Technology Officer, Cortex, Palo Alto Networks and Tim Junio, Senior Vice President of Products, Cortex, Palo Alto Networks

Description
Cortex Xpanse provides a complete, accurate, and continuously updated inventory of all global internet-facing assets. This allows firms to discover, evaluate and mitigate cyberattack surface risks. Clients can also evaluate supplier risk and assess the security of acquired companies

Cortex Xpanse by Palo Alto Networks News

Palo Alto Networks Unit 42 Named a Leader in Cybersecurity Incident Response Services

Unit 42 receives highest possible scores in nine criteria including Innovation, Technology, Threat Intelligence, Cloud Environments, and IR Leadership and Team Structure

SANTA CLARA - Cortex Xpanse by Palo Alto Networks announced Palo Alto Networks® Unit 42® has been named as a Leader in The Forrester Wave™: Cybersecurity Incident Response Services, Q2 2024.

Wendi Whitmore, Senior Vice President and Head of Unit 42 at Palo Alto Networks, said:

"As the threat landscape intensifies and attacks increase in speed, scale, and sophistication, organizations need a strategic partner to help them prepare for and respond to incidents; Unit 42 is that and more. As trusted advisors and partners, we guide our clients through some of the world's most significant cybersecurity incidents, ultimately transforming their security posture by leveraging the full power of Palo Alto Networks AI-powered security platforms and solutions to prevent and reduce the likelihood of future attacks."

The Unit 42 team includes a global team of threat experts and seasoned IR consultants with a depth of experience ranging from complex ransomware investigations to insider threats, vulnerability exploitation and nation-state attacks.

In the last year, Unit 42 nearly doubled its number of Incident Response (IR) Retainer customers. This growth is a testament to the team's relentless pursuit of excellence, enabling them to more effectively navigate complex incident response investigations and help them respond and recover stronger than before. The global nature of the team enables Unit 42 to respond 24/7 to cybersecurity incidents quickly.

The Forrester report recognizes Unit 42 for the following reasons:

• "The combined team and offering under the Unit 42 product name has gone global and launched innovative IR offerings."

• "It also brought in top leadership talent, built up its global presence, and expanded its partner network over the last two years to complement its in-house products and services, allowing it to hold its own with the larger IR firms and big consultancies."

• "Investigations are enhanced by its threat intelligence capabilities, including embedded analysts for each response and dynamic battlecards guiding response or negotiation activities by specific threat actors."

• "[Unit 42 offering is designed to]…streamline the retainer management and IR processes, especially for those one-to-many breaches where a vulnerability in a tech product affects hundreds or thousands of customers."

• "Unit 42 recently launched Arcade, an IR client onboarding and retainer management platform designed to establish a customer's security profile, gain situational awareness of the customer's environment, and serve as a relationship hub."

Unit 42's incident response approach goes beyond responding quickly and effectively; it's about transforming an organization's security posture and enhancing overall cyber resilience. Utilizing Precision AI™ technology, Unit 42 automates detection, prevention and remediation, shifting security from reactive to proactive. Its team of experts helps clients mature their security strategies after an incident to reduce the likelihood of future attacks and ensure business continuity. To better prepare organizations for future threats, Palo Alto Networks leverages Unit 42 threat intelligence derived from thousands of IR engagements to inform a cycle of continuous improvement and technology development across its network, cloud and SOC platforms and solutions.

For more information about Unit 42's incident response services and to download a complimentary copy of "The Forrester Wave™: Incident Response Services, Q2 2024" visit https://start.paloaltonetworks.com/forrester-wave-incident-response or read the blog.

This is the second Forrester Wave this month in which Palo Alto Networks has been positioned as a Leader. In June 2024, Palo Alto Networks was also named a Leader in The Forrester Wave™: Extended Detection and Response, Q2 2024. In total, Palo Alto Networks currently is recognized in 23 cybersecurity product categories by the industry analyst community.

© 2026 Enterprise Security Magazine. All rights reserved. Headquartered in Fort Lauderdale, FL, USA.