Navy’s Aaron Weis on Use of Automated Red-Teaming in Addressing Cyber Vulnerabilities

Aaron Weis, chief information of the Department of the Navy and a 2022 Wash100 Award winner, said conducting regular automated red-teaming is far more effective than adopting a “checklist” approach when it comes to detecting and addressing cyber vulnerabilities, Defense One reported Tuesday.

It's a very compliance-driven mentality, like an audit… and it's wrong,” Weis told the publication of the checklist approach. “Cybersecurity is not a compliance problem.”

The Navy conducted an experiment using a tool called Nova from software startup Rebellion to perform automated red-teaming on networks and found that the process revealed which cyber vulnerabilities allow threat actors to gain wider access to networks and those that were the easiest to exploit.

“It can identify the system, understand its patch level, catalog its vulnerabilities according to what’s generally available, and then try to run an automated exploit against it, based on what it knows,” Weis said of the tool.

Share the Post:

Related Posts

Wash100 Award Popular Vote Week 8: Booz Allen Retains Lead as Industry Leaders Dominate Top 10

The Wash100 Popular Vote contest enters Week 8 with Andrea Inserra of Booz Allen maintaining her stronghold at the top. With 1,123 votes, Inserra continues to set the pace, while...

Wash100 Award Popular Vote Week 7: Booz Allen Continues to Lead as Competition Intensifies

The Wash100 Popular Vote remains a fierce battleground as Week 7 brings significant shifts in the rankings. Booz Allen Hamilton executives continue their impressive run, maintaining dominance in the top...

Wash100 Award Popular Vote Week 6: Booz Allen Executives Dominate as Inserra Takes the Lead

The Wash100 Popular Vote contest saw a dramatic shake-up in Week 6, with Booz Allen executives taking the top three spots. Public officials continue to gain support, while newcomers enter...