Reactive vs. Proactive Cybersecurity: What's the Real Difference, and Why Does It Matter to Business?
A company detects unauthorized access to its network on a Tuesday morning. The IT team spends the next 48 hours putting out fires, isolating servers, reviewing logs, and explaining to management what happened. That is reactive cybersecurity in its purest form: responding after the damage has already been done.
Proactive cybersecurity raises a different question. Instead of asking, “How do we fix this?”, ask, “How did we know this could happen, and why didn’t we act sooner?” The difference may seem semantic, but it completely changes the cost, impact, and reputation associated with an incident.
What Exactly Is Reactive Cybersecurity?
Reactive security is based on detection and response after the fact. An antivirus program that blocks malware after it has already been executed, a SOC that analyzes an alert after the attack, a recovery plan that is triggered once the ransomware has already encrypted files. It’s not useless—far from it—and without these layers, any incident would be much worse.
The problem is that this model assumes the attack will occur first and the defense will react afterward. And it is during that window of time—between when the attacker gains access and when the company becomes aware of it—that almost all of the actual damage occurs: data theft, lateral movement across the network, and extortion.
The IBM study (Cost of a Data Breach Report 2026) estimated the average time to identify and contain a breach at 247 days. That’s more than eight months during which an attacker can move freely within a company’s systems, while the company remains unaware that it has been compromised.
What Changes with a Proactive Approach
Proactive cybersecurity doesn't wait for an alert. It looks for the conditions that make an attack possible before anyone can exploit them—such as credentials leaked on forums, unpatched vulnerabilities, fraudulent domains impersonating the brand, and exposed digital assets that no one even remembers exist.
This requires something that many companies still lack: continuous visibility into their own exposure, not just a one-time snapshot once a year. A penetration testing The annual report describes the security status on the day the test was conducted. Three months later, that photo is no longer useful, because the infrastructure, vendors, and exposed credentials change every week.
This is where the concept of continuous threat exposure management. It is, quite simply, a shift in approach: it involves moving away from hunting down vulnerabilities one by one and instead continuously managing everything an attacker could see and exploit from the outside.
| Reactive Cybersecurity | Proactive Cybersecurity | |
| When it takes effect | After the incident | Before it happens |
| What it detects | Alerts and damage that has already occurred | Exposures, leaks, and potential attack vectors |
| Frequency | On-demand | Continuous, 24/7 |
| Cost of Failure | High: rescue, recovery, reputation | Low: Risk is addressed before damage occurs |
| Real-life example | SOC analyzes a post-attack alert | Kartos detects leaked credentials before they are used |
| Main limitation | By the time it takes effect, the damage has already been done | Requires investment in continuous monitoring |
Why the Difference Matters to the Business, Not Just to IT
Let's be straightforward here: the debate between reactive and proactive approaches is not just a technical discussion confined to the IT department. It is a business decision with a direct impact on the income statement.
A security incident doesn't just cost the amount of the ransom or the cost of technical repairs. It costs in downtime, customers switching to competitors, fines if personal data is involved, and trust which takes years to rebuild. Being proactive does not eliminate the risk, but it does drastically reduce the window of time during which an attacker can operate undetected.
Furthermore, there is an economic argument that many executives overlook: prevention is cheaper than remediation, and in cybersecurity, the difference is enormous. Hiring continuous cyber monitoring costs a fraction of what it costs to manage a data breach that has already occurred—including lawyers, crisis communications, and upset customers.
How Continuous Exposure Management Is Applied in Practice
The theory behind CTEM is all well and good, but what really matters to a company is how it translates into day-to-day operations. At Enthec, that’s exactly what we focus on, with Kartos, our continuous cyber monitoring platform for businesses.
Kartos constantly monitors what an attacker would see if they decided to investigate an organization. Among the vectors it continuously monitors are:
- Credentials leaked on the dark web: employee usernames and passwords exposed on illegal forums or marketplaces before anyone can use them.
- Fraudulent domains: domain registrations similar to the company’s, intended to impersonate the corporate identity or deceive customers.
- Vulnerabilities in public services: open ports, outdated services, or insecure configurations visible from outside the perimeter.
- Sensitive information exposed: internal code, documents, or data that have ended up in public repositories or third-party forums without anyone noticing.
For personal use, Enthec offers Qondar, designed for executives, at-risk professionals, or anyone who wants to know if their digital identity, credentials, or personal data have ever been compromised. The logic is the same as in Kartos, adapted for an individual rather than an entire organization.
The two approaches are complementary
It would be a mistake to frame this as an either/or choice. No serious company would eliminate its ability to respond to incidents. What changes with a proactive system is the starting point: rather than the attack itself being the first warning sign, the company already knows where it is vulnerable and has been able to close those doors in advance.
The ideal combination is clear. Maintain a capacity to respond when something slips through the cracks (because it always happens) and combine that with continuous monitoring to keep the list of "somethings" as short as possible.
Organizations that invest only in reactive measures spend their time putting out fires without asking themselves why they keep happening. Those who invest only in prevention without a response plan are in for some unpleasant surprises when something they didn't see coming goes wrong.
The Real Cost of Waiting
Let's go back to the example from the beginning. That company that discovered the unauthorized access on a Tuesday morning had likely been exposed for weeks or months without realizing it.
If your company still manages cybersecurity solely on a reactive basis, it’s worth asking yourself how much of your actual exposure you’re unaware of right now. An initial assessment of your exposure surface using Kartos is usually enough to answer that question with concrete data, not assumptions.
Frequently Asked Questions
Does proactive cybersecurity replace antivirus software or firewalls?
No. They are complementary layers. Antivirus software and firewalls are still necessary as internal barriers; proactive monitoring provides visibility into what is happening outside the perimeter, before that risk reaches those barriers.
Is CTEM the same as a penetration test or a security audit?
Not exactly. A penetration test assesses security at a specific point in time. CTEM involves continuous monitoring, with constant updates to the attack surface—not a snapshot that becomes outdated within weeks.
What size of company needs continuous cyber monitoring?
Any organization with a significant digital presence, employees with corporate credentials, or customer data to manage. The risk depends not only on the organization’s size, but also on its surface area and how attractive that information is to an attacker.
How much does it cost to implement proactive cybersecurity versus reactive cybersecurity?
The cost of continuous monitoring is significantly lower than that of managing a breach that has already occurred. According to the IBM Cost of a Data Breach Report 2026, the average cost of an incident exceeds $4.99 million globally. Investment in preventive monitoring typically represents a fraction of that figure.
The relevance of cybersecurity in telecommunications
Sending an email, holding a video meeting, or saving files to the cloud are actions we take for granted in our businesses. But behind this apparent simplicity lies a complex network that sustains telecommunications: networks, devices, providers, data…
And in that sea of constant information, cybersecurity has become an absolutely essential element for business continuity.
We're no longer just talking about protecting computers or servers, but the telecommunications infrastructure that shapes our lives. From data centers to employees' smartphones, cybersecurity in telecommunications is a key component of ensuring digital, economic, and social stability.
In an environment such as telecommunications, where the exhibition area is vast and dynamic, a solution such as Kartos is advisable and essential to ensure business continuity and protect reputation and user trust.
Unlike other more reactive approaches, our Kartos solution uses a continuous Threat Exposure Management (CTEM) model.. This means it helps organizations maintain a constant and up-to-date view of all their exposed assets, detect vulnerabilities, and anticipate possible attacks.
Why is cybersecurity so critical in telecommunications?
Telecommunications are the nervous system of our digital society. and cybersecurity in telecommunications is a structural priority for all sectors.
According to the Kaspersky Security Bulletin 2025 report, 20.7% of users in the telecom sector suffered device threats during the past year, and almost 10% of organizations experienced ransomware incidents. According to Check Point data gathered from analyses of the Spanish market, telecommunications ranks among the three most attacked sectors in the country.
A highly exposed sector
Telecommunications is one of the world's sectors that is attacked the most. It's no coincidence: Operators manage massive volumes of data, critical network infrastructure, and connections with millions of users. Any security breach can have devastating consequences: service interruptions, theft of sensitive data, espionage, or even attacks on national infrastructure.
Threats are constantly evolving
Cybercriminals never rest. New techniques, exploits, and ways to break into systems are developed daily. From ransomware attacks targeting service providers to signal interception or large-scale identity theft, having an antivirus or firewall is no longer enough.
It is necessary to have tools that proactively analyze and identify weaknesses before they are exploited, and maintain constant surveillance of the digital ecosystem. As we propose with Kartos, continuous threat management makes a substantial difference.
The most relevant threats to the telecom sector in 2026
The threats facing telecom operators in 2026 are all the more dangerous because they intersect and amplify each other:
- APT (Advanced Persistent Threats) Groups: actors with state resources seeking stealthy and prolonged access to critical infrastructure for espionage or sabotage.
- Supply chain attacks: The reliance on multiple suppliers and integrated platforms makes each external supplier a potential entry point.
- Targeted ransomware: Specific campaigns against operators with a high impact on service continuity and high blackmail power.
- SIM swapping and SIM-enabled fraud: Telephone line impersonation to access bank accounts, emails, and corporate systems.
- High-intensity DDoS: Denial-of-service attacks that seek to disrupt critical services and extort operators.
- AI-powered attacks: The use of artificial intelligence by attackers to create more credible phishing campaigns, automate vulnerability scanning, and generate corporate deepfakes.
As Leonid Bezvershenko, senior researcher at Kaspersky GReAT, points out, these threats "do not disappear, but rather intersect with operational risks stemming from automation, quantum cryptography, and satellite integration."
You may be interested in→ 6 online threats that can affect your business.
Towards a more preventive and strategic approach
The traditional security model, based on reacting once an incident occurs, is no longer enough.. In an environment as changing as the digital one, prevention and anticipation are essential.
The regulatory framework in 2026: NIS2 and its impact on telecommunications
Regulatory pressure on cybersecurity in telecommunications has intensified significantly in 2026. The NIS2 Directive (EU Directive 2022/2555) is the main legal framework that obliges telecommunications operators to strengthen their security measures.
Explore this topic further in the following post-> NIS 2: How does it affect businesses and what measures should be taken to comply with the regulations?
What does NIS2 require of telecommunications operators?
Telecommunications are classified as essential entities underNIS2, which implies the strictest requirements of the directive:
- Mandatory notification of serious incidents within a maximum of 24 hours.
- Implementation of verifiable and auditable risk management measures.
- Direct responsibility of the governing bodies, with the possibility of disqualification for managers.
- Penalties of up to 10 million euros or 2% of global annual turnover.
- Extension of security requirements to the entire supply chain of ICT providers.
In Spain, although the transposition of NIS2 is still going through parliamentary procedures with estimates of entry into force throughout 2026, the competent authorities have already initiated supervisory procedures.
To delve deeper into the regulatory requirements that affect organizations in the sector, we recommend you check out our article on GRC in cybersecurity: Governance, risk and regulatory compliance.
CTEM: continuous management against threats
The traditional IT security model involved periodically reviewing systems, searching for flaws, and applying patches. However, in today's context, this methodology is insufficient. The key is constant vigilance.
Continuous Threat Exposure Management (CTEM) is a more dynamic and adaptive approach. It allows companies to:
- Know what assets are exposed on the Internet (servers, domains, applications, etc.).
- Detect misconfigurations or vulnerabilities before they are exploited.
- Prioritize what to fix first based on the actual level of risk.
Our tool, Kartos, is explicitly designed to implement this model. Its noninvasive approach allows monitoring without the need to install agents and offers a clear view of any organization's external security posture.
Artificial intelligence as a defensive ally
By 2026, AI has become a central element in both attacks and defense. The WEF Global Cybersecurity Outlook 2026 states that 94% of cybersecurity industry leaders identify AI as the main driver of change for this year.
In telecommunications, offensive AI has a particularly significant impact, enabling the automation of network endpoint scanning, the generation of customized phishing campaigns at scale, and the cloning of executive identities for B2B fraud. The defensive response requires applying that same processing capacity to detect traffic anomalies, correlate signals distributed across complex infrastructures, and reduce incident response time.
What your company can do now
If you work in a company that relies on digital infrastructure (which is practically all of them), there are some steps you can start considering today:
1. Perform an exposure diagnosis
The first step is knowing which assets of your organization are visible from outside the perimeter and what condition they are in. Do you have domains similar to yours registered by third parties? Are employee credentials circulating on specialized forums? Do any of your providers have expired certificates with active access to your network?
Kartos lets you get this picture of the external exposure without affecting your internal systems, in a matter of hours. You can find more information about how to detect CVE vulnerabilities on your digital surface without touching your internal network.
2. Implement a CTEM strategy
Monitoring must be continuous and automated. Threats don't wait for you to schedule an audit. The CTEM model ensures that any change to your attack surface—a new lookalike domain, a compromised credential, a misconfiguration—is detected and prioritized in real time.
Also discover how the perimeter cybersecurity approach complements your existing infrastructure to strengthen access.
3. Protect key people
The executives and security officers of the operators are deliberate targets. Their digital identity, credentials, and online reputation are attack vectors that remain outside the corporate perimeter.
Qondar, our personal digital protection platform, extends the logic of CTEM to the individual digital assets of key people in your organization.
4. Teach your team
No tool can replace the human factor. Make sure your team understands the risks and knows how to respond.
Cybersecurity in telecommunications as a guarantee of continuity
In a world where everything is digital, ensuring cybersecurity in telecommunications is not an add-on or a discretionary expense; it is the core of any business continuity strategy. Exposure to threats is constant, regulatory penalties are increasing, and the consequences of an incident can be irreversible for an organization's reputation and operations.
The question is no longer whether your organization will be targeted. The question is whether you will have enough visibility to detect it before it causes harm.
Kartos helps companies in the telecommunications sector regain control of their external digital security. No installations, no intrusion, no human operation to introduce delays. Just your domain, and a complete, continuous view of everything an attacker could see and exploit.
Do you want to know what's exposed in your organization right now?
Request a Kartos demo and get a clear, actionable view of your external security posture→ Contact Enthec
Account Hijacking: What It Is, How It Happens, and What to Do If Your Accounts Have Been Compromised
If one day you try to log in to your email and your password no longer works, or you receive a login notification from a country you've never been to, you may have been the victim of an account takeover—in other words, someone has taken control of something that belongs to you without your permission.
This is no minor issue. Fraud related to account theft and takeover results in combined losses of more than billions of euros each year for individuals and businesses. And the trend, far from improving, continues to worsen.
What exactly is account hijacking?
Account hijacking, also known as account takeover, is the process by which an unauthorized third party gains access to and control over someone else's digital account. This could be an email account, a social media account, a banking platform, a subscription service, or any other platform where you have saved login credentials.
Once inside, the attacker can do virtually anything, such as read your private messages, carry out financial transactions, impersonate you to your contacts, sell access to the account on the black market, or use it as a point of entry to compromise other related systems.
What makes this type of attack particularly dangerous is that, in many cases, the victim doesn't realize it right away. The intrusion may go unnoticed for days or weeks before the damage becomes apparent.
How Account Hijacking Occurs
There are several ways attackers can gain control of someone else's account. Knowing what they are is the first step to avoiding them.
Data Breaches and Exposed Credentials
One of the most common causes. When a company experiences a security breach, your users' credentials (email addresses and passwords) may end up being posted on forums or sold on the dark web. If you reuse the same password across multiple services, a single data breach can compromise several of your accounts at once.
Credential stuffing attacks
This method takes advantage of precisely that. Attackers use lists of leaked credentials and automatically test them on hundreds of different platforms. If the username and password match on any of them, they gain access without having to hack anything.
Phishing and Direct Deception
Fake emails, messages, or websites that impersonate legitimate services remain a highly effective entry point. The goal is simple: to get you to enter your information into a form that is actually sending that information directly to the attacker.
To learn more, check out our post:> Phishing: What It Is and How Many Types There Are.
Malware and Spyware
Some malicious programs install themselves on the victim's device and capture keystrokes, passwords saved in the browser, or session cookies—all without the user noticing anything unusual.
Social engineering.
Sometimes no technical sophistication is needed to carry out a social engineering attack. A call from someone posing as technical support, an urgent “account verification” message, or a seemingly harmless conversation can be enough to trick someone into voluntarily handing over their credentials.
Signs That Your Account May Have Been Compromised
There isn't always a clear warning. However, there are Signs You Shouldn't Ignore:
- Login notifications from unknown locations or devices.
- Changes to your profile information that you didn't make.
- Messages sent from your account that you don't remember writing.
- Unable to log in because the password or recovery email address has been changed.
- Transactions you don't recognize.
- Contacts who tell you they've received strange messages from you.
If you notice any of these symptoms, take action immediately.
What to Do If Someone Has Taken Control of Your Account
1. Try to regain access as soon as possible
Most platforms have an account recovery process that uses a backup email address, phone number, or security questions. Use it right away.
2. Change the related passwords
If you've reused that same password on other services, change them all immediately. Start with your email account, which is usually the master key to all your other accounts.
You might be interested in:> How to manage business passwords and credentials easily and securely to avoid online threats
3. Enable two-step verification
If you hadn't enabled it before, do so now. And if you already had it enabled, check to make sure that your verification methods are still the same and haven't been changed.
4. Check the devices with active access
Many apps and websites let you view active devices and sessions. Close any that you don't recognize.
5. Let the people around you know
If the attacker has been able to send messages or emails from your account, notify your contacts so they don't click on any links they've received from you in the last few days.
6. Report the incident
In Spain, you can report it to the National Cybersecurity Institute (INCIBE) via its cybersecurity helpline (017) or file a report with the National Police or the Civil Guard.
How to Prevent Account Hijacking
Prevention remains the best strategy. Some basic measures are very effective:
- Use unique and strong passwords for each service. A password manager can help you manage them.
- Enable multi-factor authentication for all services that support it.
- Keep your devices up to date and protected with anti-malware solutions.
- Be wary of emails or messages that ask you to verify your credentials immediately.
- Check periodically to see if your data has appeared in any known data breaches.
This last point is more important than it seems. Knowing that your credentials are exposed before the attacker uses them it gives you time to act.
Continuous monitoring as an additional layer of protection
For both individuals and businesses, having a solution that continuously monitors the exposure of credentials on the web, the dark web, and other intelligence sources provides a real advantage against account hijacking.
We have been working in this field since Enthec, using two tools for Continuous Threat Exposure Management. Kartos, designed to protect organizations, and Qondar, designed for individuals. Both tools allow you to detect in real time whether a person’s or a company’s data has been exposed, so you can take action before any damage occurs.
Because one of the problems with account takeover is precisely that: by the time you realize what has happened, the attacker has already been in for hours or days.
Do you want to know if your credentials—or your organization's—are currently exposed? Find out how Enthec can help you stay in control of your digital footprint before others do it for you.
Keys to Supplier Evaluation: How to Manage Third Parties in Your Company
Supplier evaluation is one of the most critical processes in modern business management. It's not enough to simply choose the best partners at the start of a business relationship; you must continuously review their performance, security practices, and alignment with your organization's standards.
Each vendor represents a potential entry point for external threats. Therefore, a rigorous assessment process must, in addition to classic operational criteria, include a thorough analysis of third-party cybersecurity risks.
With Kartos Third Parties, Enthec's platform for third-party risk management, you can obtain an automated, real-time risk assessment of your suppliers without requiring intrusion or human intervention.
What is supplier evaluation, and why is it important?
Supplier evaluation is the process by which a company analyzes and rates the performance of the third parties with which it works.
It's not just about choosing suppliers but also about regularly reviewing their performance to ensure they meet the quality, cost, and deadline standards you need, among other things. However, we must not forget that effective supplier management is incomplete without a cybersecurity analysis, since each supplier is a potential entry point for external threats.
If a supplier doesn't meet expectations, it can lead to delays, increase costs, or even affect your company's reputation. Therefore, a good evaluation system helps to:
- Choose the most suitable suppliers from the start.
- Reduce risks in the supply chain.
- Ensure the quality of products or services.
- Avoid unnecessary costs.
- Comply with standards and regulations.
Now that we know why it's important, let's examine how you can implement this process in your company.
Supplier evaluation criteria: What should you measure?
Not all suppliers are the same or equally important to your business. Therefore, defining supplier evaluation criteria that adapt to your needs is essential. Here are some of the most commonly used:
1. Quality of the product or service
The first criterion to evaluate is quality. Whether a technology service provider or a parts manufacturer, their quality should match your expectations. To measure it, you can review aspects such as:
- Materials used.
- Quality certifications.
- Results of audits or inspections.
- Defect or failure rate.
2. Compliance with deadlines
A supplier that delivers late can cause problems in production or in the provision of your services. To evaluate this criterion, you can measure, for example, their percentage of on-time deliveries or their ability to respond to emergencies.
3. Price and payment terms
Cost is a key factor in any business, but the cheapest provider is not always the best option. Evaluate:
- Value.
- Flexibility in payments and financing.
- Transparency in additional costs.
4. Responsiveness and after-sales service
A good supplier not only meets deadlines but also responds when problems arise. To assess this, clear aspects such as customer service should be considered.
5. Sustainability and social responsibility
More and more companies value suppliers that are responsible for the environment and society, taking into account the use of sustainable materials, compliance with environmental regulations, and good labor and inclusion practices.
6. Cybersecurity
Before starting a business relationship, companies should consider key cybersecurity criteria, including the maturity of their cybersecurity strategy, threat protection, and cybersecurity solutions for handling security breaches.
For a complete assessment, Kartos provides a real-time platform that automates the detection of third-party and umpteenth risks, ensuring effective risk management throughout the business relationship.
Supplier evaluation procedure
You already have clear criteria, but how can you implement a supplier evaluation procedure effectively? Here is a step-by-step guide:
1. Define the evaluation criteria
Not all suppliers must meet the exact requirements. For example, a software vendor will have different criteria than a raw material vendor. Therefore, it is essential to determine which aspects are a priority in each case before starting the evaluation.
2. Gather objective information
To properly evaluate suppliers, you need objective data. Some ways to get information are:
- Audits or inspections.
- Satisfaction surveys.
- Internal records of incidents.
- Supplier documentation (certifications, licenses, etc.).
3. Assign a score
A simple way to evaluate suppliers is to assign a score to each criterion, for example, from 1 to 5. You can create an evaluation chart and calculate a weighted average based on the importance of each criterion.
If a provider scores low, you may need to look for alternatives or renegotiate terms.
4. Make decisions and follow up
Once you've earned your scores, decide which providers will continue to work with you and which ones need improvement. It's a good idea to do regular reviews, such as every six months or a year, to ensure the supplier still meets the standards.
Supplier evaluation: a practical example with weighted criteria
To illustrate how this process works in practice, let's look at an example of an assessment applied to a technology service provider with access to sensitive corporate data.
In this case, the most heavily weighted criteria would be cybersecurity (30%), service quality (25%), and meeting deadlines (20%), compared to criteria such as price (15%) or sustainability (10%).
If a supplier scores 4/5 for quality, 5/5 for on-time delivery, but only 2/5 for cybersecurity, the weighted average may place them below the minimum acceptable threshold, despite their good operational performance. This is precisely the type of situation that the third-party risk analysis with Kartos allows you to detect before it becomes an incident.
Best Practices for Managing Suppliers
For effective supplier management, here are some key tips:
- Negotiate clear agreements. Set up well-defined contracts to avoid misunderstandings.
- Foster long-term relationships. It is not just about evaluating but about building relationships of trust.
- Digitize the process. Use management software to keep better control of information.
- Continuously monitor the security of your suppliers. Make sure they meet data protection standards.
- Don't rely on a single supplier. Diversify to reduce risk in the event of failures or unforeseen events.
Evaluating service and product providers is not a simple process but a key tool for optimizing your company's performance. An inefficient supplier can generate risks to your business, while a reliable and well-managed one can become a great ally.
Implementing a supplier evaluation procedure with well-defined criteria and continuous monitoring will improve quality, reduce risks, and ensure your company's sustainable growth.
With Kartos, you can simplify and improve this process, ensuring regulatory compliance, mitigating security risks, and protecting information in your supply chain.
Frequently asked questions about supplier evaluation
How often should I evaluate my suppliers?
The minimum recommended frequency is semiannual or annual. Depending on the supplier's criticality level, suppliers with access to sensitive data or a critical role in the supply chain should be monitored continuously, not just during periodic reviews.
What criteria are prioritized in the evaluation of technology service providers?
For technology providers, cybersecurity and regulatory compliance should have the greatest weight in the evaluation, followed by the quality of service and response times to incidents.
How can I assess a provider's cybersecurity without accessing their systems?
There are specialized platforms, such as Kartos, for monitoring third-party external attack surfaces that allow you to assess a supplier's cybersecurity posture non-intrusively by analyzing their public digital exposure outside their infrastructure.
What regulations require a formal supplier evaluation process?
The NIS2 Directive, the DORA Regulations and the GDPR establish explicit obligations regarding the management of third-party risks. Having a documented evaluation procedure is a key requirement for regulatory compliance.
Can I use a supplier evaluation template or example as a starting point?
Yeah. An evaluation template with weighted criteria and a scoring scale is a good starting point, but it must be adapted to the specific characteristics of each sector and supplier type. Most importantly, the process must be systematic, documented, and reviewed regularly.
CISA's KEV Catalog: How the Most Secure Organizations Prioritize Vulnerabilities
There is a clear difference between organizations that react to cyberattacks and those that anticipate them. The former wait for something to go wrong; the latter already know what they’re going to patch before the attacker comes knocking.
One of the tools that sets them apart from one another is the CISA’s KEV catalog (Known Exploited Vulnerabilities), a resource that, when used properly, can completely change the way a company manages its vulnerabilities.
What Is CISA's KEV Catalog, and Why Does It Matter?
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) maintains a public list of vulnerabilities that are already being actively exploited by malicious actors. These are not theoretical flaws or hypothetical risks; they are real vulnerabilities, with evidence of their use in actual attacks.
The catalog of known exploited vulnerabilities It is updated continuously. Every time CISA adds a new entry, it is issuing a warning. Therefore, for any security team, this catalog is not just a technical reference, but a list of priorities that should not be ignored.
A signal that extends beyond U.S. borders
Although the directive requiring action on this catalog, the Binding Operational Directive (BOD) 26-04, primarily affects U.S. federal civilian agencies, its usefulness knows no bounds. Any company, regardless of size or industry, can use CISA’s KEV catalog as a guide to decide which vulnerabilities to address first.
The underlying message is simple: if malicious actors are already exploiting a vulnerability, that vulnerability moves to the top of the list, ahead of others with higher CVSS scores but no evidence of active exploitation.
The Problem with Setting Priorities Without Real Data
One of the most common pitfalls in vulnerability management is relying solely on the severity score. The CVSS system assigns a numerical score to each vulnerability, which is useful but incomplete.
Theoretical Severity vs. Actual Risk
A vulnerability with a CVSS score of 9.8 may go months without being actively exploited. Meanwhile, another flaw with a CVSS score of 6.5 is already being used by ransomware groups to compromise production systems. If the security team prioritizes its backlog solely by severity, it may be devoting resources to the wrong problem.
This is where the KEV catalog offers something that CVSS cannot: real-world exploitation contextl. Knowing that a vulnerability is being exploited right now immediately changes its priority, regardless of its score.
Volume as an Obstacle
The volume of threats continues to grow exponentially; in 2025 alone, more than 48,000 new vulnerabilities (CVEs) were published. According to industry analyses, this represents an all-time high, equivalent to discovering an average of 132 new security flaws every day. No security team can patch them all at the same rate they appear. Prioritization is the only way to stay afloat.
The KEV catalog acts as a filter: from among those tens of thousands of vulnerabilities, it identifies those for which there is reliable evidence of active exploitation. This transforms an unmanageable list into something actionable.
How More Mature Organizations Use the KEV Catalog
Organizations with a stronger security posture do not treat the KEV catalog as a simple to-do list. Instead, they integrate it into an ongoing process of identification, assessment, and response.
Continuous monitoring of the catalog
Catalog updates are frequent and sometimes urgent. In June 2026, for example, CISA added two new vulnerabilities: a path traversal in Cisco Catalyst SD-WAN Manager and a symbolic link tracking vulnerability (symbolic link following) in the LiteSpeed plugin in cPanel. Both already had evidence of active exploitation at the time they were included.
Organizations that detected these additions immediately were able to take action before the problem spread. Those that did not have an alert system for KEV catalog updates found out later—or not at all.
Cross-referencing the catalog with one's own knowledge
Knowing that a vulnerability exists in a specific product is only useful if you know whether that product is present in your own environment. That is why the best-prepared companies continuously cross-reference entries in the KEV catalog with their asset inventory.
This process, which is part of what is known as Continuous Threat Exposure Management, allows us to answer a specific question: Is there anything nearby that’s on the CISA list?
Consider the context before taking action
Not all vulnerabilities in the KEV catalog affect every environment in the same way. A flaw in a product that the organization does not use is, for all practical purposes, irrelevant. But a flaw in a critical system exposed to the internet requires an immediate response.
The most advanced organizations don't just detect vulnerabilities—they put them into context. They assess whether the affected asset is exposed, what data it handles, what impact its compromise would have, and what mitigation options exist beyond the patch (which sometimes cannot be applied immediately without disrupting operations).
You might be interested in:> Real-Time Vulnerability Management: A Step Forward in Cybersecurity.
CTEM: The Framework That Brings It All Together
CTEM This approach makes it possible to turn CISA’s KEV catalog into something actionable within an organization. It’s not about conducting a vulnerability assessment once a year; it’s about maintaining constant visibility into the attack surface and taking action commensurate with the actual risk.
This approach structures the process into five phases: scope definition, asset and vulnerability discovery, prioritization based on actual risk, validation, and mobilization for remediation. The KEV catalog directly feeds into the prioritization phase.
Kartos and Qondar: Cyber Surveillance Focused on Actual Risk
At Enthec, we have developed two cyber surveillance solutions designed specifically within this CTEM framework. Kartos, aimed at businesses, provides continuous visibility into an organization’s external exposure, detecting compromised assets, leaked credentials, exploitable vulnerabilities, and active threats before they result in an incident.
Qondar offers the same features, but for individual users, protecting the digital identities of people exposed to specific risks.
Both solutions integrate threat intelligence sources to provide contextualized and prioritized alerts. The goal is not to create a fuss, but to highlight what really matters at any given moment.
Would you like to know your organization's actual exposure? Contact us and find out what an attacker sees when searching for vulnerabilities in your company.
CISA's KEV catalog is one of the most valuable and accessible threat intelligence tools available today. Its value lies not in the volume of entries, but in the quality of the intelligence it provides. These vulnerabilities are not theoretical; they are the ones attackers are exploiting right now.
Organizations that know how to leverage the catalog of known exploited vulnerabilities as part of a continuous exposure management process have a real advantage over those that manage security reactively. The difference isn't in having more tools, but in knowing what to look for and when to act.
And in cybersecurity, that is what separates those who contain incidents from those who fall victim to them.
The importance of blacklists in cybersecurity
Blacklists are one of the most widely used cybersecurity tools for blocking digital elements identified as malicious or suspicious. Understanding what a blacklist is, how it is built, and its limitations is essential for any organization that wants to strengthen its security posture.
What is a cybersecurity blacklist?
A cybersecurity blacklist is a database that collects IP addresses, domains, email addresses, applications, and other digital elements identified as malicious or suspicious. When an item on a blacklist attempts to access a protected system, the request is automatically rejected.
Blacklists are used by security solutions such as firewalls, intrusion detection and prevention systems (IDS/IPS), antivirus software, email gateways, and cyberintelligence platforms. Public lists are maintained by cybersecurity organizations, internet service providers, and specialized companies and are constantly updated to reflect the real-time threat landscape.
Alongside public blacklists, organizations can develop private blacklists tailored to their risk context, incorporating internal findings or data from threat intelligence (CTI) platforms.
If you want to stay informed about the cybersecurity sector, access our publication→ The 7 cybersecurity trends you should know.
Types of blacklists in cybersecurity
There can be as many types of blacklists as there are categories of threats detected. The most prominent are:
IP blacklist
The IP blacklist is a list of IP addresses identified as potentially dangerous. These IP addresses are often associated with malicious activities, such as sending spam, carrying out DDoS attacks, and spreading malware. IP blacklists are used to automatically block traffic from these IP addresses. IP blacklists are used to automatically block traffic from these IP addresses. When an IP address is blacklisted, any attempt to connect from that IP address to a protected system is rejected. IP blacklists are maintained and updated by cybersecurity organizations and Internet service providers. They are constantly updated to reflect new threats as they are discovered or to exclude those that have disappeared. While IP blacklists are a valuable tool in preventing cyber threats, they are not infallible. To avoid blocking, cybercriminals change IP addresses on a recurring basis.
Spam domain blacklist
The spam domain blacklist is a list of domain names identified as sources of spam. These domains may be associated with the distribution of unsolicited emails, phishing, malware, and other malicious activities. Spam domain blacklists are used by email security systems and spam filters to automatically block emails from these domains. When a domain is blacklisted, any email sent from that domain to a protected system is marked as spam or rejected. Like all other public blacklists, spam domain blacklists are maintained and updated by cybersecurity organizations, email service providers, and security software companies. They are also constantly updated, as cybercriminals frequently change domain names to circumvent them.
Main public blacklists in 2026
Knowing which blacklists are considered essential helps organizations prioritize their reputation monitoring. These are the most widely used in the industry:
| Blacklist / DNSBL | Type | What it detects | Main use |
|---|---|---|---|
| Spamhaus (SBL/XBL/ZEN) | IP / domain | IPs spam, botnets, proxies comprometidos | Corporate email filters |
| Barracuda (BRBL) | IP | IPs that send spam | Mail servers |
| SURBL | Domain/URL | Domains in spam and phishing bodies | Email gateways |
| MXToolbox | IP / domain | Overall reputation, DNSBL check | Systems administrators |
| Google Safe Browsing | URL | Phishing, malware, unwanted software | Browsers, APIs |
| PhishTank | URL | Community-validated phishing pages | Web security, SIEM |
How is a blacklist created, and how does it work?
Blacklists are compiled through comprehensive collection and analysis of data on known threats.
The blacklisting process includes:
- Data collection. Data is collected from multiple sources, such as security incident reports, threat intelligence feeds, and internal analysis.
- Data analysis. The collected data is analyzed to identify malicious patterns and behaviors. This includes analysis of IP addresses, domains, emails, and applications associated with malicious activity, such as spam or cyberattacks.
- Creation of the blacklist. Once malicious items are identified, they are added to the blacklist.
- Constant updating. Blacklists should be constantly updated to reflect new threats as they are discovered and to correct detected errors.
Once the blacklist has been compiled, it is used to automatically block access to the organization's systems by the digital items on the blacklist.
Main benefits of blacklisting
The use of blacklists for system protection is a solution that provides numerous benefits, among which are:
Easy implementation
Blacklists are relatively simple to implement, making them an attractive option for many organizations. These lists can be easily configured into most security systems, such as firewalls and intrusion detection systems. The ease of implementation allows organizations to quickly improve their security posture without requiring significant resources.
Proactive protection
Blacklists provide proactive security protection by identifying and blocking known threats before they can cause harm. By restricting access to suspicious entities, these lists act as a shield, preventing threat actors from exploiting vulnerabilities. This proactive approach allows organizations to anticipate threats and prevent them from materializing, rather than simply reacting to them once they have occurred.
Complementing security strategies
Blacklists are a valuable complement to other security strategies. They are effective in blocking known threats, but cannot protect against unknown or zero-day threats. Therefore, they are useful when used in coordination with other techniques, such as anomaly detection and threat intelligence. Together, these strategies provide defense-in-depth, protecting against a wider range of threats.
Reduction of malicious traffic
Blacklists are very effective in reducing malicious traffic. By blocking IP addresses, domains, and email addresses associated with malicious activity, blacklists significantly reduce unwanted or harmful traffic. This not only improves security but also increases network efficiency by reducing unnecessary traffic.
Limitations of blacklisting
Blacklists are a simple and effective tool for protecting systems; however, they have limitations that make it necessary to integrate them into a broader set of tools.
The main limitations of blacklists are:
False positives
Often, blacklists include erroneous collections or analyses that block legitimate traffic, a phenomenon known as a false positive. These false positives harm both the organization blocking legitimate traffic and the organization from which it originates. To address false positives, many organizations use a combination of blacklisting and whitelisting. Whitelists, in contrast to blacklists, contain items considered safe and allowed. The combination of the two list types allows for more granular control and reduces the risk of false positives.
Need for constant updating
To circumvent blacklist blocking, cybercriminals recurrently change IP addresses, domains, or anything that could be blacklisted. Therefore, to remain effective, blacklists require constant updates to their databases to reflect new threats as they are discovered, at a high resource cost.
How to find out if your IP address or domain is on a blacklist?
Being blacklisted can seriously affect corporate email deliverability, brand reputation, and the performance of digital services. The most common signs are:
- Company emails end up in recipients' spam folders.
- Emails are rejected or bounce back.
- Customers or partners report that they are not receiving your communications.
- Reputation monitoring tools generate alerts.
How to get off a blacklist: step-by-step process
If your IP address or domain has been blacklisted, acting quickly is crucial to minimizing the impact. Follow this process:
| Passed | Action | Detail |
|---|---|---|
| 1 | Identify the blacklist | Use tools to find out exactly which list(s) you have been included on. |
| 2 | Investigate the cause | Analyze logs, outbound traffic, and configurations to find the source of malicious behavior (malware, compromised account, bulk sending without consent). |
| 3 | Fix the problem at its root. | Clean the infected system, revoke compromised credentials, correct SPF/DKIM/DMARC settings, and apply patches. |
| 4 | Request deletion | Follow the delisting process for each blacklist (web form or email). Attach evidence of correction. |
| 5 | Monitor after delisting | Configure automatic alerts to detect future inclusions. Implement continuous IP and domain reputation monitoring. |
The average resolution time varies depending on the blacklist and the severity of the incident, but it typically ranges from 24 hours to several days after the delisting request. The key to minimizing this impact is continuous monitoring of the reputation of corporate IPs and domains.
Advanced blacklist management with Kartos
Kartos' tool, developed by Enthec, makes it easy for its clients to create private blacklists based on findings and analysis results, using in-house artificial intelligence solutions.
In this way, in addition to the protection offered by public blacklists, Kartos customers also benefit from private blacklists that respond to the specific context of their organization, depending on their exposed assets, compromised credentials, similar domains, open breaches, and any element identified during the continuous monitoring of their external attack surface.
Kartos also eliminates one of the main problems with traditional blacklists: false positives. Its automated analysis engine validates each finding before adding it to the list, ensuring that only truly malicious items are blocked.
Do you want to know if your organization appears on any blacklists and how to protect your digital reputation? Contact us to learn how Kartos can help you detect exposed vulnerabilities, create private blacklists, and eliminate false positives within your cybersecurity strategy.
How to manage passwords and business credentials easily and securely to prevent online threats
Digital threats are no longer a remote possibility; they are an everyday reality for any company, regardless of its size or sector. And in this landscape, knowing how to manage passwords securely has become one of the most critical decisions in any cybersecurity strategy.
In 2025, Outpost24's threat intelligence team analyzed over 6 billion passwords stolen by malware. Their conclusion was clear: Attackers are not looking for sophisticated technical vulnerabilities. They simply take advantage of predictable, reused, and never-updated passwords to gain access "through the main entrance" of organizations.
In this article, we explain best practices for securely managing passwords at an enterprise level, the most relevant trends for 2026, and how a continuous monitoring solution like Kartos can protect your organization from leaks that have already occurred without your knowledge.
The problem of passwords in companies
Passwords remain the first line of defense against cyberattacks. But they are also the most exploited link. According to the Sophos Active Adversaries Report 2026, identity-related attacks accounted for 67% of incidents investigated globally in 2025. The main causes were compromised passwords, weak or non-existent MFA schemes, and insufficiently protected identity systems.
Consequences of poor management
Poor password management can have devastating consequences for businesses:
- Loss of sensitive data. A single unauthorized access can compromise key information.
- Reputational damage. Customers and partners lose trust in a company that fails to protect their data.
- Financial costs. From fines for non-compliance to recovery costs after an attack.
Therefore, adopting a secure password management system is not optional, but essential.
You may be interested in our content→ 5 tips to improve your company's access management.
How to manage passwords securely?
Here are the best practices for securing business credentials:
1. Implement strong password policies
Passwords must meet specific criteria to be secure:
- Be at least 12 characters long.
- Include a combination of uppercase, lowercase, numbers, and symbols.
- Avoid using personal information or common words.
A good policy should also require regular password changes and prohibit password reuse.
2. Train your employees
Your employees are the first line of defense against cyberattacks. Provide regular training on:
- The importance of strong passwords.
- How to identify phishing attempts.
- Best practices for protecting your devices and accounts.
3. Use a password management system
A centralized password management system is a practical solution for securely storing and protecting credentials. These tools allow:
- Generate unique and strong passwords.
- Store encrypted credentials.
- Securely share access between employees.
4. Implement multi-factor authentication (MFA)
MFA adds an extra layer of security by requiring a second authentication factor, such as a code sent to the phone or a fingerprint. Even if a password is compromised, access will not be possible without this second factor.
5. Move towards passkeys: the passwordless future
In 2026, the debate is no longer whether to adopt passkeys, but when. The UK's NCSC formalized its official recommendation in April 2026 to use passkeys instead of passwords whenever possible. Google, Apple, and Microsoft have already established them as their preferred login method.
Passkeys are based on the FIDO2 standard and employ public-key cryptography. A private key remains on the user's device, protected by biometrics or a PIN, while the public key is stored on the server. A password is never transmitted over the network.
6. Continuously monitor and audit
Threats are constantly evolving, and many vulnerabilities go undetected immediately. Continuous monitoring of credential status and conducting regular audits are essential to identifying vulnerabilities before they are exploited.
One particularly critical aspect is that your organization's credentials may be circulating on the dark web without your knowledge. Only active monitoring of the external attack surface allows for timely detection.
Kartos: Continuous credential monitoring for companies
Implementing best practices is necessary, but not sufficient. Cyber attackers don't wait for your company to fail in a protocol; they actively search for compromised credentials circulating on the dark web, and most organizations don't realize it until the damage is done.
Kartos is Enthec's CTEM (Continuous Threat Exposure Management) platform, designed to give companies complete, real-time visibility into their external attack surface.
What is Kartos?
Kartos is a Continuous Threat Exposure Management (CTEM) solution that automatically, non-intrusively, and in real time monitors your organization's exposure to external threats. Unlike a traditional password manager, Kartos acts as an intelligence system that detects what has already happened before you find out the hard way.
What does Kartos detect?
- Leaked employee credentials circulating on the dark web, underground forums, and illegal marketplaces.
- Phishing campaigns that impersonate your brand or corporate domains.
- Exposure of sensitive organizational data in open sources and repositories.
- Third-party risks: suppliers and partners with compromised credentials who can serve as a gateway to your network.
- Potential threats in real time, without false positives and without the need for human intervention (HumInt).
Benefits of using Kartos
Among the most notable benefits:
- Risk reduction. Minimize the probability of unauthorized access.
- Regulatory compliance. It helps to comply with data protection regulations such as the GDPR.
- Time saving. Automate tasks such as password generation and auditing.
- Tranquillity. Knowing that your credentials are protected allows you to focus on growing your business.
Why choose Enthec to protect your credentials?
At Enthec, we understand that security shouldn't be complicated. That's why we have developed solutions tailored to both companies (Kartos) and individuals (Qondar). While Kartos focuses on password management and enterprise protection, Qondar offers a personalized experience for individual users who want to protect their data.
Both tools share a common goal: to help you continuously manage your exposure to threats and stay one step ahead of cybercriminals.
Are your corporate credentials already exposed without your knowledge? With Kartos, you can detect and act before an attacker does. Contact our team today and request a personalized demonstration.
Relevance of perimeter cyber security for your business
For decades, perimeter cybersecurity has been the cornerstone of organizations' digital defenses. The idea was simple: erect a solid barrier around the internal network and prevent external threats from penetrating it. However, the rise of remote work, the widespread adoption of cloud computing, and the increasing sophistication of cyberattacks have forced a fundamental rethinking of this model.
Currently, the security perimeter is no longer a clear line. It is a dynamic, distributed, and, in many cases, invisible surface. Understanding what perimeter security is in cybersecurity, its limits, and how to extend it is now a strategic priority for any CISO.
What is perimeter security in cybersecurity?
In cybersecurity, perimeter security refers to the measures and technologies implemented to protect the boundaries of an organization's internal network. Its main objective is to prevent unauthorized access and external threats, ensuring that only legitimate users and devices can access the network.
Perimeter security is crucial because it acts as the first line of defense against cyberattacks, acting as a barrier. By protecting network entry and exit points, the risk of external threats compromising data integrity, confidentiality, and availability is reduced.
Basic concepts of perimeter cybersecurity
- Network perimeter: A logical boundary that separates the internal (trusted) network from external networks such as the Internet.
- Perimeter security: A set of controls and tools that protect the perimeter against external access and attacks.
- Zero Trust: A model that assumes that no user or device is trusted by default, even within the network.
- Extended Cybersecurity: Strategy that extends surveillance to the external perimeter: web, dark web, social networks, and third parties.
Key components of perimeter security
A robust cybersecurity perimeter model relies on five fundamental technologies that work in a coordinated manner:
-
- Firewalls act as a barrier between the internal and external networks, filtering traffic based on predefined rules.
- Intrusion detection and prevention systems (IDS/IPS) monitor network traffic for suspicious activity and can block attacks if necessary.
- Virtual Private Networks (VPNs): They allow secure, encrypted connections between remote users and the internal network. With the implementation of remote work, the use of VPNs in companies has become widespread.
- Web security gateways: They filter web traffic to block malicious content and unauthorized sites.
- Authentication and access control systems: They verify users' identities and control which resources they can access.
- SIEM: It centralizes and correlates security events from multiple sources to detect patterns and incidents.
If you want to stay up to date→ 7 cybersecurity trends you should know about.
Network Perimeter Security Guidelines
Implementing the technological components is not enough. Perimeter cybersecurity only works if the organization systematically applies three operational guidelines:
-
Robust authentication
Authentication guarantees that only authorized users and devices can access network resources. It involves verifying users' identities before granting them access, which helps prevent unauthorized access and potential threats.
Different authentication methods include:
- Passwords. The most common method can be vulnerable if strong, unique passwords are not used or stored securely.
- Two-factor authentication (2FA). It adds an additional layer of security by requiring a second factor, such as a code sent to the user's mobile phone.
- Biometric authentication. It uses unique physical characteristics, such as fingerprints or facial recognition, to verify the user's identity.
- Digital certificates. Used primarily in enterprise environments, these certificates provide a secure and official way to authenticate devices and users.
It is imperative that the organization implement strong password policies, enforce that they be complex and changed regularly, and ensure accountability for ensuring these policies are known and followed. In addition, it is important that access attempts are monitored to detect and respond to suspicious or failed access attempts.
Integrated security solutions
Integrated security solutions are essential for network perimeter security, combining multiple technologies and tools into a single platform to provide more comprehensive and efficient protection. They enable organizations to manage and coordinate multiple security measures from a single point, making it easier to detect and respond to threats. Integrated solutions are recommended because they improve an organization's operational efficiency by centralizing security management and reducing complexity. They also provide a unified view of network security, making it easier to identify and respond to threats. They are also scalable, allowing organizations to adapt to new threats and security requirements without deploying multiple standalone solutions. Integrated security solutions include:
- Next generation firewalls (NGFWs): offer advanced traffic filtering, deep packet inspection and intrusion prevention capabilities.
- Intrusion Detection and Prevention Systems (IDS/IPS) monitor network traffic for suspicious activity and can block attacks in real time.
- Web and email security gateways protect against web- and email-based threats such as malware and phishing.
- Security information and event management (SIEM) systems collect and analyze security data from multiple sources to identify patterns and alert on potential incidents.
- Virtual Private Networks (VPNs) provide secure, encrypted connections for remote users.
For proper integration of the solutions, it is advisable to implement them gradually to minimize interruptions, provide continuous training on the tools for the responsible personnel, and keep the solutions updated and monitored.
Shared security
Shared security is a collaborative approach to network perimeter security that has gained momentum since the expansion of cloud services. It involves cooperation among service providers, customers, and partners to protect the network infrastructure. This model recognizes that security is a joint responsibility and that each party has a crucial role in protecting data and resources. The main characteristics of shared security are:
- Mutual responsibility: Both service providers and customers have specific responsibilities for network security. For example, providers may be responsible for physical and infrastructure security, while customers must manage the security of their applications and data.
- Transparency and communication: open, transparent communication among all parties involved is essential for effectively identifying and mitigating potential threats.
- Common policies and procedures: Establishing security policies and procedures that are consistent and understood by all parties helps to ensure a coordinated response to security incidents.
For security sharing to be truly effective, the responsibilities of each party involved need to be clearly defined and delineated. In addition, communication channels must be established to enable the rapid and continuous exchange of information about threats and best practices. Regular audits periodically assess the effectiveness of security measures, and adjustments can be made as necessary.
Limitations of perimeter cybersecurity
As technologies have evolved, the original strict concept of perimeter security, limited to the internal environment, has presented some important limitations that affect its effectiveness in protecting organizations, such as:
| Limitation | Why does it happen? | Real risk |
| Third-party risk | Suppliers and partners with access to the internal network are held to lower security standards. | Gateway for attackers |
| IT Complexity | Legacy systems, hybrid cloud, and multiple platforms create an extensive attack surface. | Blind spots and invisible gaps |
| Sophisticated attacks | Social engineering, zero-day attacks, and offensive AI evade static perimeter defenses. | Intrusion without alarms |
| Armor cost | The continuous upgrading of hardware, software, and specialized personnel creates a cycle of rising costs. | Underprotection in SMEs |
| Diffuse perimeter | Remote work and the cloud eliminate the physical perimeter: data is no longer inside the castle. | Obsolete model without adaptation |
Extended cybersecurity as an enhancement to perimeter cybersecurity
Traditional cybersecurity perimeters only protect what's inside. But by 2026, the most dangerous threats will originate from outside: leaked credentials on the dark web, domain spoofing, exposed vulnerabilities in external assets, or compromised vendors.
Extended cybersecurity, also called extended perimeter security, is the strategy that covers the outer space. It recognizes that threats can originate both inside and outside the corporate network and acts accordingly by implementing proactive security measures before they reach the inner perimeter.
Advantages of extended perimeter cybersecurity
- Continuous monitoring of the outer perimeter(web, deep web, dark web, social networks).
- Detection of leaked corporate credentials before they are used by an attacker.
- Real-time third-party risk management, without depending on specific audits.
- Real-time alerts on open gaps and exposed vulnerabilities.
- Brand protection against domain impersonation and external phishing.
Cyber intelligence solutions are the driving force behind this strategy. They use artificial intelligence and machine learning to analyze large volumes of external data and detect ongoing threats before they impact the organization. The most advanced solutions also incorporate continuous and automated third-party risk management.
Extends corporate perimeter cyber security strategy with Kartos
Kartos is the Cyber Intelligence platform developed by Enthec to extend the security perimeter that organizations control.
By simply entering the organization's domain, Kartos provides real-time information on exposed vulnerabilities and open breaches in nine threat categories outside its IT perimeter.
Furthermore, it allows organizations to continuously and automatically control third-party risk, providing real-time data.
If you would like to learn more about extended cybersecurity, you can download our white paper Extended Cybersecurity: When Strategy Builds the Concept.
For more information on how Kartos can extend your organization's perimeter security strategy, contact us.
How to detect CVE vulnerabilities on your digital surface without touching your internal network
Detecting a threat before it's exploited is one of the most important priorities for any organization with a digital presence today. But how can you achieve this without compromising your internal network? Is it possible to have real visibility into your vulnerabilities without performing intrusive or invasive scans? The answer is yes, and tools like Kartos by Enthec are making it possible.
Kartos is an advanced solution for Continuous Threat Exposure Management (CTEM), designed specifically for businesses. It enables you to identify, prioritize, and address digital weaknesses before an attacker can exploit them as an entry point.
Through an external, non-intrusive, and fully automated approach, Kartos continuously scans your digital footprint, including domains, subdomains, exposed applications, cloud assets, public configurations, and other relevant information. All without the need to install agents or access your internal network.
Are you interested in learning how you can reduce your risk of cyberattacks without modifying your current infrastructure? Discover how Kartos can help you take the next step toward a more confident and proactive posture.
What is a CVE, and why should you pay attention to it?
Before getting into the subject, it is essential to understand what a CVE is.. The acronyms correspond to Common Vulnerabilities and Exposures. It's an international standard that classifies and labels known security flaws in software and hardware. Each vulnerability is given a unique identifier, such as CVE-2024-12345, making it easier to track and resolve.
Why are they so relevant to your company? Because when a CVE is published, cybercriminals also become aware of it. Many rely on these lists to find organizations that have not yet patched their systems or that remain publicly exposed.
CVE and cybersecurity are terms that should always be used in conjunction. It's not enough to know them; you have to manage them proactively.
If you'd like to learn more about CVEs, we recommend checking out our content: What is a CVE?
CVSS Severity Levels: How a CVE is Classified
| Level | CVSS Score | Meaning | Urgent action |
|---|---|---|---|
| None | 0.0 | No real impact | No action required |
| Low | 0.1 - 3.9 | Limited impact | Monitor |
| Half | 4.0 - 6.9 | Exploitable with conditions | Plan patch |
| High | 7.0 - 8.9 | Significant impact | Patch urgently |
| Critical | 9.0 - 10.0 | Exploitable remotely, without authentication | Immediate action |
How does the CVE system work? Vulnerability lifecycle
Understanding how the CVE system works is essential for managing them effectively. From the moment a vulnerability is discovered until it appears in the databases, the process follows these stages:
- Discovery: A researcher, user, or vendor identifies a vulnerability in a system.
- Report: A CNA (CVE Numbering Authority), such as MITRE, Microsoft, Oracle, or NIST, is notified.
- ID Assignment: The CNA assigns a unique identifier CVE-YEAR-NUMBER.
- Publication: The CVE is published on the official CVE list and in the NIST National Vulnerability Database (NVD).
- Enrichment: NVD adds CVSS scores, attack vectors, CWE configurations, and references.
- Management and patching: Manufacturers release updates; security teams prioritize and apply fixes.
¿Why proactively manage CVEs? Key advantages
- Reduction of exposure time: Identifying CVEs before they are exploited drastically reduces risk.
- Regulatory compliance: ENS, NIS2, and GDPR require active vulnerability management. Ignoring a critical CVE can lead to penalties.
- Resource optimization: Prioritizing by CVSS score allows you to focus efforts on the failures with the greatest real impact.
- Reputation and trust: Companies that proactively manage CVEs earn greater trust from customers and partners.
- Defense against known threats: More than 60% of cyberattacks exploit CVEs with available but unapplied patches.
How to detect CVE vulnerabilities from the outside: without touching your internal network
There is a widespread belief that detecting vulnerabilities requires performing internal scans, installing agents, or accessing the company's network. However, this is no longer true. Thanks to modern approaches such as CTEM, you can map your entire exposure without touching a single line of your private network.
How does the external CVE detection model work with Kartos?
At Enthec, we've developed Kartos, a solution that simulates an external attacker's perspective to detect CVEs on your digital surface. The process is structured in three phases:
- Asset discovery: Kartos maps everything exposed on the internet that belongs to your digital footprint, including IPs, domains, subdomains, SSL certificates, web endpoints, public metadata, open configurations, and cloud buckets...
- Correlation with CVE databases: The identified assets are automatically cross-referenced with public databases such as NIST NVD, MITRE CVE List, and ExploitDB to detect if they are affected by any known vulnerabilities.
- Prioritization and real-time alerts: Kartos not only detects but also classifies CVEs by their real risk level and alerts you with concrete, actionable recommendations.
Advantages of this approach
No intrusions, no friction
One of the most significant benefits is that it does not interfere with your internal operations. . Since it doesn't require network permissions or software installation, implementation is quick and secure. It also reduces IT or technical department resistance, as nothing in the corporate environment is disrupted.
View from the attacker's perspective
A common mistake in cybersecurity is focusing solely on what happens "inside." However, attackers don't start inside your network: they begin outside. Having visibility into how a cyber attacker perceives you allows you to act before he does.
Smart prioritization
Not all CVEs are equally dangerous. Some are theoretical, while others have already been discovered to have known exploits. Kartos not only detects vulnerabilities but also identifies the most critical ones, helping you make more efficient and informed decisions.
What role does CVE play in modern cybersecurity?
Business cybersecurity in Spain and around the world is facing a growing problem: the escalation of cyberattacks.. Every year, we learn of new cases that occur worldwide. In this context, reacting is no longer enough; we must anticipate.
That's where the concept of CVEs as a risk indicator comes in. Knowing which CVEs affect your digital infrastructure is a crucial first step toward developing a robust defense strategy. But just as important is discovering them early and consistently.
In other words, CVE management is the foundation of an active security posture.
The CTEM approach and its application with Kartos
What is CTEM
CTEM, or Continuous Management of Threat Exposure,is an approach that goes beyond one-off audits. It involves continually assessing the attack surface to identify vulnerabilities and remediate them before they can be exploited.
Why Kartos stands out
Compared to other more technical tools or those focused on internal network scans, Kartos adopts a 100% external philosophy, adapted to the real world.. It detects relevant CVEs in your visible assets, alerts you in real time, and provides concrete, actionable recommendations.
Additionally, it's scalable, enabling you to protect everything from startups to large corporations without requiring infrastructure or internal team adjustments.
What if I'm an individual? There's a solution, too.
If you are a self-employed professional or a user concerned about your digital footprint, Enthec has also developed Qondar, a solution designed for individuals. It provides visibility into your personal digital exposure, ideal for executives or professionals at risk of targeted cyberattacks.
CVE vulnerabilities are present in almost every connected infrastructure, and waiting for them to be exploited is a luxury no company can afford. Cybersecurity tools like Kartos enable you to adopt a proactive and practical approach, with agile implementation, and without the need to alter your internal network through perimeter-based cybersecurity.
Detecting CVEs from the outside is not only possible, but is an increasingly recommended practice in the field of cybersecurity.
Request a free Kartos demo today and see for yourself how you can reduce your exposure to threats without changing a single line on your servers. Contact us!




















