Cymulate, the industry pioneer in SaaS-based Continuous Security Validation (CSV) announced the next generation Extended Security Posture Management (XPSM) platform leveraging its native, Offensive Security technology and capabilities to widely support customers security and business needs.

The combination of these new capabilities follows several product launches over the last six months and provides end-to-end validation of an organisation's cyber security posture. 

XSPM incorporates four fundamental pillars tied together with analytics to provide meaningful security posture insights: Attack Surface Management, Continuous Automated Red Teaming, and Breach and Attack Simulation alongside an Advanced Purple Teaming framework.

Attack Surface Management (ASM)

ASM tools scan domains, sub-domains, IPs, ports, and other assets for internet-facing vulnerabilities

Helping organisations understand how hackers might get an initial foothold, ASM tools scan domains, sub-domains, IPs, ports, and other assets for internet-facing vulnerabilities. These functions alongside Open-Source Intelligence (OSINT), which could be used in a social engineering attack or a phishing campaign.

Combined with Vulnerability Prioritisation Technology (VPT), these capabilities empower security teams to efficiently prioritise vulnerabilities and mitigation steps, ensuring a shorter time to remediation.

Continuous Automated Red Teaming (CART)

Moving beyond reconnaissance to answering: "how can an adversary breach my defences?" CART tools attempt to penetrate the organisation by analysing the exposed vulnerabilities and autonomously deploying attack campaigns that penetrate the network.

After gaining the initial foothold, an attack subsequently propagates within the network in search of critical information or assets, for example by triggering a well-crafted phishing email.

BAS and Advanced Purple Teaming

BAS tools launch simulated attack scenarios out of the box, correlate findings to security controls (email and web gateways, WAF, endpoint, etc.), and provides mitigation guidance. These tools are primarily used by blue teams to perform security control optimisation.

Advanced Purple Teaming Framework expands BAS into the creation of advanced and custom attack scenarios

Advanced Purple Teaming Framework expands BAS into the creation and automation of advanced and custom attack scenarios. These tools easily follow the MITRE ATT&CK framework to model a threat actor, enabling security practitioners to create complex scenarios from predefined resources to custom binaries and executions.

Customised scenarios can be used to exercise incident response playbooks, proactive threat hunting, and automate security assurance procedures and health checks.

Cymulate’s XSPM platform

"With the threat landscape evolving at such a rapid pace, Cymulate's SaaS-based Extended Security Posture Management (XSPM) is better suited to cater to customers' needs," said Eyal Wachsman, CEO, and Co-founder of Cymulate.

"We're now continuing our vision to help organisations stay in control of their security posture while minimising resources, as well as allowing security professionals and leaders to know and control their cybersecurity posture in a dynamic environment."

The XSPM platform provides out-of-the-box, expert, and threat intelligence-led risk assessments that are simple to deploy and use for all maturity levels, and constantly updated. Deployable within minutes, Cymulate enables security professionals to continuously challenge, validate and optimise their cybersecurity posture end-to-end, across the MITRE ATT&CK framework.

Download PDF version Download PDF version

In case you missed it

Executive protection demand spiking after UnitedHealthcare shooting
Executive protection demand spiking after UnitedHealthcare shooting

The practice of executive protection changed forever on Dec. 4, 2024, when UnitedHealthcare CEO Brian Thompson was shot outside a Manhattan, New York, hotel.  The shocking ev...

What will be the big topics of discussion at ISC West 2025?
What will be the big topics of discussion at ISC West 2025?

If recent physical security events are a guide, the topic of artificial intelligence (AI) will be everywhere at the upcoming ISC West 2025 exhibition in Las Vegas. Cybersecurity so...

Climax releases an advanced smart telecare solution with voice control
Climax releases an advanced smart telecare solution with voice control

GX-MAX-DT35B Smart Care Medical Alarm comes with a brand-new case design. The battery level and the cellular signal strength will be indicated through the white bar on the top cove...

Quick poll
Which AI-powered capability will dominate in the years ahead?