enterprisesecuritymag

Enterprise Security Magazine

Skybox Security
Insights-Driven Cybersecurity Management

CIO VendorRavid Circus, Vice President, Products
Security leaders have long been on the hunt for the missing piece of the puzzle that will render a complete view of their enterprise’s state of security. The legacy security solutions they rely on are no longer viable amid today sophisticated cyberattacks. SkyboxTM Security breaks new ground by providing unprecedented visibility into an organization’s network topology, assets, security controls, vulnerabilities and potential attack vectors. Its automated, next generation firewall management across physical, multi-cloud, and industrial networks paves way for efficient security operations management. Enterprises can leverage the SkyboxTM Security Suite for complete rule lifecycle management and perform tasks like real-time change monitoring, firewall full-rule recertification, and automated provisioning.

“Within Skybox Security Suite, we unify security, network, and threat data from the broadest range of sources,” states Ravid Circus, Vice President, Products, SkyboxTM Security. Recognizing secure and regulatory compliant firewalls as a need of the hour, the company provides a SkyboxTM Firewall Assurance module that enables complete management of a firewall’s lifecycle. Users can execute tasks across multiple firewall systems and automate complex rule-sets. The module monitors and analyzes traditional and virtual firewalls, as well as security tags in the cloud, and identifies security policy violations and platform vulnerabilities. With Skybox, organizations are able to unify security policy management across their networks, wherever they are — on-prem, multi-cloud or ICS/SCADA. Skybox Firewall Assurance also zeroes in on baffling firewall changes that necessitate cleaning up, recertifying, and optimizing for rule-sets.

Skybox provides comprehensive, in-depth attack surface visualization with SkyboxTM Network Assurance and SkyboxTM Horizon, the company's proprietary visualization tool that graphically shows exposures that put the organization at risk. Enterprises can gain a clear view of the physical, multi-cloud, and industrial networks that support their business and operations.


Within Skybox Security Suite, we unify security, network, and threat data from the broadest range of sources


With Skybox, users can visualize and interact with hybrid network and security controls. They can analyze network paths from any source and destination including Amazon Web Services, Microsoft Azure, and VMware NSX networks. To ensure continuous network service, businesses can also examine network zones, routers, and switches for security violations, and troubleshoot in a virtual model.

As attack surfaces evolve continually, security leaders are driven to make changes in workflows to ensure network security and compliance. SkyboxTM Change Manager, a module dedicated to firewall change workflow and automation, plays a crucial role in change assessment as a prelude to implementation. It nullifies the probability of new risk emergence. The module matches firewalls with change requests and converts the requests into a closed-loop process for errorless implementation. It determines risks related to the proposed changes to proactively prevent attacks and compliance violations while maintaining maximum availability. Skybox Change Manager automates rule lifecycle management, tracks changes, and verifies if implementation matches intent. Subsequently, the module customizes workflows to cope with organizational requirements.

“More than 120 networking and security technologies underpin the Skybox Security Suite. We harness the power of various technologies using integrations,” states Circus. Skybox Security’s unique approach of threat-centric vulnerability management gives true risk visibility and provides the tools and context to prioritize and remediate vulnerabilities and threats, ensuring that vulnerability management is aligned with security policy requirements. Clients can prioritize and resolve imminent threats and plan ongoing risk reduction for potential threats that could escalate. Skybox Security’s team of security analysts, SkyboxTM Research Lab, delivers advanced threat intelligence and attack vector analysis to help pinpoint vulnerabilities. By offering an integrated platform of capabilities for firewall and security policy management, as well as vulnerability and threat management, Skybox gives organizations the context needed to ensure efficient, secure firewall management across the network, including on-prem, multi-cloud and industrial environments.

Skybox Security News

Skybox Security and Indegy Ventures into Cybersecurity for Networks

FREMONT, CA: Skybox Security will be integrating with Indegy to provide better protection to interconnected IT and OT (Operational Technology) networks.

Skybox Security a cyber risk management global leader, estimates that the various IT teams are not aware of the OT networks as most of them connect actual devices, equipment, and people physically in the industry. To provide better support, cyber-infrastructure, and security, the merger with Indegy proves more substantial. It not only gives proper support to the industry but also provides an overall view of all the processes that are happening on the dot. Read More

Skybox Security Appoints Cybersecurity Veteran Mordecai Rosen as CEO

Skybox closes $50m in financing to drive growth of its SaaS-based security platform

SAN JOSE, Calif - Skybox Security , a global leader in Security Policy and Vulnerability Management, today announced the appointment of Mordecai (Mo) Rosen as Chief Executive Officer, and the closing of $50 million in financing from CVC Growth Funds, Pantheon, and J.P. Morgan. Mr. Rosen is a seasoned security technology executive with over 25 years of experience and will focus on driving company growth and accelerating the adoption of the industry’s first Software-as-a-Service (SaaS) solution for Security Policy and Vulnerability Management.



“Mo brings a wealth of knowledge and a track record of success in leading cybersecurity and SaaS companies, and we have every confidence that he will lead Skybox to its next level of long-term growth and profitability.”

“CVC is incredibly pleased to bring on Mo as the new CEO of Skybox and to continue our long-standing financial support of the company. Skybox is the cornerstone of the security infrastructure of hundreds of the largest enterprises around the globe. With its new SaaS platform, Skybox Cloud, the company is well positioned for significant market growth,” said Jason Glass, Partner at CVC. “Mo brings a wealth of knowledge and a track record of success in leading cybersecurity and SaaS companies, and we have every confidence that he will lead Skybox to its next level of long-term growth and profitability.”

Before joining Skybox, Mr. Rosen was the President and CEO of Digital Guardian, a data loss prevention software company, where he significantly grew recurring revenue while simultaneously leading the organization to profitability. Before Digital Guardian, he served as the Corporate Senior Vice President and General Manager for Security at CA Technologies, now a Broadcom company.

“I was drawn to Skybox by its disruptive technology platform, blue chip customer base, and seasoned cybersecurity team,” said Mr. Rosen. “With our first to market SaaS offering, Skybox Cloud, we are well positioned to disrupt both the Security Policy and Vulnerability Management markets with a single integrated SaaS platform. I am thrilled to join Skybox at this exciting inflection point and lead the company to its next level of growth.”

Skybox Security Unveils Next-Generation of Continuous Exposure Management Platform

Significant Enhancements in Attack Surface and Vulnerability Management Solutions Empower Organizations to Mitigate Cyber Exposure Risk

SAN JOSE - Skybox Security, today announced the next generation of its award-winning Continuous Exposure Management Platform. This 13.0 release introduces significant advancements to its Attack Surface and Vulnerability Management solutions, revolutionizing how enterprises manage and mitigate cyber exposure risk.

"In today's complex threat landscape, organizations need to continuously manage their threat exposure based on the prioritized risks to their business," said Mordecai Rosen, CEO of Skybox Security. "The Skybox platform now supports each stage of an enterprise’s continuous exposure management (CEM) program, from mapping the attack surface, through contextualization and risk-based prioritization, to final remediation. Our latest enhancements enable organizations to further improve their security posture and significantly reduce the risk of a successful attack.”

Attack Surface Management Provides Complete Visibility

The Skybox Attack Surface Management solution offers a comprehensive inventory and mapping of assets, applications, and users. It conducts an analysis of attack paths and simulates potential attacks, resulting in a dynamic security model of the hybrid attack surface. The latest release, Version 13.0, introduces several significant enhancements, including:

New Attack Surface Map: This release introduces a powerful new visualization tool for the attack surface map. Customers can now effortlessly filter and highlight specific segments of their infrastructure. Assets can be grouped either manually or automatically for improved comprehensibility. Enhanced search functionality enables swift asset location and navigation. This new map provides unprecedented clarity and precision.

Enhanced Attack Path Analysis: Recognizing the significance of lateral attacks, threats from supply chain partners, and insider threats, Version 13.0 incorporates the threat origin (Internet, Partner, Insider) into its attack path analysis. Knowing the source of the threat enhances prioritization and decision-making for risk mitigation by providing better context.

LDAP Integration: Organizations can seamlessly incorporate Group Policy Objects (GPOs) from LDAP directories, such as Microsoft Active Directory, within the Skybox platform. This integration offers direct insights into security policy settings for users, organizational units, and computers.

Cloud Infrastructure Integration: Addressing the complexities of hybrid and cloud infrastructures, Version 13.0 centralizes cloud-related data, including AWS firewall rules and assets. This advancement enhances the platform's ability to navigate intricate infrastructures.

Deepening Exposure Insights with Vulnerability Management Skybox's Vulnerability Management solution aggregates data from over 25 third-party threat intelligence feeds, in addition to the in-house Skybox Threat Intelligence feed. This data aids in prioritizing threats based on exposure-related risk and provides prescriptive guidance for remediation. With Version 13.0, organizations gain the following capabilities:

Vulnerability Data Import: Customers can now consolidate their own vulnerability data from various sources within the platform, establishing a unified solution for various vulnerability management tasks. This streamlined approach incorporates vulnerability data from sources like penetration testing and in-house vulnerability assessments.

New Business-Focused "Solutions View": Version 13.0 introduces the "Solutions View," designed to identify essential compensating controls tailored to specific business units or applications. This functionality empowers organizations to maximize their security efforts by focusing on mitigations aligned with their unique requirements.

Celebrity Vulnerabilities: With Version 13.0, organizations can swiftly identify and address celebrity vulnerabilities listed in the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog. This proactive measure targets vulnerabilities that are frequently exploited by known threat actors.

SOAR Integration: Version 13.0 seamlessly integrates with Security Orchestration, Automation, and Response (SOAR) platforms through a set of focused REST APIs. This integration enhances investigation and remediation activities for the Security Operations Center (SOC).

Additional Enhancements Facilitate Compliance Efforts Updates to the Firewall and Network Assurance products include general user interface improvements and NIST 800-41 Access Policy updates. These enhancements expedite compliance testing, violation identification, and proactive resolution.

Skybox Security Report Reveals Over 30,000 New Vulnerabilities Published in Past Year

Annual Report Uncovers Major Gaps with Traditional Vulnerability Management Leading to Long Exposure Times and Increased Risk

SAN FRANCISCO - Skybox Security Research Lab today released its annual 2024 Vulnerability and Threat Trends Report, revealing that last year alone, over 30,000 new vulnerabilities were published — a rate of a new vulnerability published every 17 minutes. The report highlights a critical gap in remediation efforts, with the average time to patch exceeding 100 days, contrasted against the finding that 75% of new vulnerabilities are exploited in 19 days or less. These findings underscore the urgent need for continuous exposure management and modern vulnerability mitigation strategies to safeguard against the growing risks of cyber attacks.

Focus Gap: Half of all 2023 vulnerabilities are classified as high or critical severity

2023 witnessed a surge in vulnerabilities, with the National Vulnerability Database (NVD) recording a 17% year-over-year increase. Since the inception of the NVD thirty years ago, 234,579 CVEs have been cataloged, yet half of those have been discovered in just the past five years. The pace at which vulnerabilities are being published is accelerating, with a new vulnerability emerging approximately every 17 minutes, an average of 600 new vulnerabilities a week, according to Skybox Research Lab.

Skybox Research Lab found that over half of all newly discovered vulnerabilities were classified as high or critical. This overwhelming influx creates a “focus gap” for security teams. The sheer volume of threats makes it difficult to prioritize effectively, potentially leaving critical risks overlooked and organizations exposed. The rise in vulnerabilities stems from several ongoing industry concerns, including:

• A rapidly expanding attack surface with more interconnected devices.

• Increasingly intricate software with hidden vulnerabilities in third-party components.

• The positive trend of more resources dedicated to uncovering vulnerabilities naturally leads to a higher number being identified.

“The past year marked a watershed moment in cybersecurity, with organizations worldwide confronting an unprecedented surge in both the volume and complexity of cyber threats,” said Mordecai Rosen, CEO at Skybox Security. “Patching remains a crucial defense, but its limitations are clear in today’s fast-paced threat landscape. Effective vulnerability management goes beyond patching. It involves continuous identification, risk-based prioritization, leveraging existing controls for timely mitigation, and ethical cybersecurity practices. This comprehensive approach empowers organizations to navigate the complexities of modern threats.”

Mean time to remediation (MTTR) remains inadequate

This report further exposes a critical cybersecurity challenge: a shrinking window for vulnerability patching. The mean time to exploit (MTTE) plummeted to just 44 days in 2023, with a concerning 25% of vulnerabilities exploited the same day and a staggering 75% within 19 days. This rapid exploitation timeline stands in stark contrast to the lengthy 95-155 days from the CVE publication to remediation. This rapid exploitation timeline and the long delay in identifying malicious activity necessitate swift and effective response mechanisms from organizations. There is a very short window for remediation of new vulnerabilities, which leaves cybercriminals ample time to compromise networks if not acted upon quickly.

The time has come to move beyond just patching

Traditional vulnerability scanning methods struggle to keep pace with today’s surge in vulnerabilities. The sheer volume overwhelms even the most diligent security teams, making spreadsheet-based tracking and patching cycles ineffective. This is why organizations are increasingly turning to modern vulnerability management solutions.

To combat shrinking remediation windows, a modern vulnerability management approach integrated within a continuous exposure management program becomes crucial. Companies can reduce their risk and slim down their mean time to remediation (MTTR) by adopting:

• Continuous Vulnerability Identification: leveraging automated techniques to discover new vulnerabilities across systems and networks constantly.

• Risk-Based Prioritization: Not all vulnerabilities are created equal. Effective vulnerability management prioritizes threats based on factors like exploitability, potential impact on critical systems or data, and the existence of patches. This ensures the security teams focus on the most critical issues first.

• Leveraging Existing Controls: Vulnerability management solutions can help identify how these controls can be used to mitigate the risks posed by specific vulnerabilities, even before a patch is available.

• Ethical and Legal Compliance: Cybersecurity goes beyond technical measures. Effective vulnerability management ensures adherence to relevant data privacy regulations and responsible testing.

© 2026 Enterprise Security Magazine. All rights reserved. Headquartered in Fort Lauderdale, FL, USA.