Ivanti has committed to adopting a secure-by-design approach to security as it gears up for an organizational overhaul in response to the multiple vulnerabilities in Connect Secure exploited earlier this year. CEO Jeff Abbott penned an open letter to Ivanti's customers and partners this week, saying "events in recent months have been humbling," before detailing the various changes Ivanti plans to make. "We will use this opportunity to begin a new era at Ivanti," Abbott's letter reads. "We have challenged ourselves to look critically at every phase of our processes, and every product, to ensure the highest level of protection for our customers. "We have already begun applying learnings from recent incidents to make immediate improvements to our own engineering and security practices. And there is more to come." Among the many changes to come at Ivanti HQ, one that will immediately catch the eye of security pros is its commitment to security by design – an approach the industry has long called for to be the norm. "Our focus is on embedding security into every stage of the software development lifecycle, with robust processes that anticipate and preemptively address potential vulnerabilities from product inception to deployment and beyond," Abbott explains. "Our approach will entail rigorous threat modeling exercises, ensuring that security is ingrained as a foundational element of our products. This proactive stance will serve as the cornerstone of our commitment, enabling us t...
Ivanti commits to secure-by-design overhaul after vulnerability nightmare
The Register
·Connor Jones
·Published Apr 4, 2024
·Updated
Affected Software
2 affected components
Ivanti Connect Secure
Ivanti Policy Secure
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses Ivanti's commitment to a secure-by-design approach in response to vulnerabilities in its products.
2
What security implications are discussed in this article?
The article highlights the need for a strategic overhaul in security practices following significant vulnerabilities found in Ivanti's Connect Secure.
3
What products or software are affected by the vulnerabilities mentioned?
The article specifically mentions vulnerabilities in Ivanti Connect Secure and Policy Secure.
4
Who is leading the organizational changes at Ivanti?
The organizational changes and commitment to security enhancements are being led by CEO Jeff Abbott.
5
What prompted Ivanti to adopt a secure-by-design strategy?
The adoption of a secure-by-design strategy was prompted by a series of vulnerabilities exploited in their software earlier this year.