Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Kenna EOL and exposure governance: what vulnerability teams should rethink


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18936
Topic starter  

TL;DR: Cisco’s Kenna end-of-life notice highlights a broader vulnerability management problem: teams that depended on scanner-agnostic prioritisation now need a replacement governance layer before support ends in 2028, according to ArmorCode. The real issue is not product sunset but whether exposure programmes can keep independent risk ranking as AI and supply-chain findings continue to outpace remediation capacity.

NHIMG editorial — based on content published by ArmorCode: Kenna End of Life: How to Preserve Independent Vulnerability Management

By the numbers:

Questions worth separating out

Q: How should security teams migrate off a scanner-agnostic vulnerability platform without losing governance?

A: Start by separating the migration of data, workflows, and decision logic.

Q: Why do scanner vendors struggle to replace independent vulnerability governance?

A: Because the vendor that detects the issue often has the strongest visibility into its own telemetry and the weakest incentive to keep external findings equally weighted.

Q: What do security teams get wrong about high CVSS scores?

A: They often treat CVSS as a complete ranking signal.

Practitioner guidance

  • Preserve a scanner-agnostic decision layer Map every critical vulnerability source to a governance layer that can normalise findings from infrastructure, cloud, application, endpoint, and supply chain tools before prioritisation.
  • Test prioritisation against business-critical exposures Run side-by-side comparisons between vendor-native rankings and risk-based rankings that include exploitability, asset criticality, and threat intelligence.
  • Plan migration before the support deadline compresses options Build a migration roadmap that covers data export, workflow remapping, integration testing, and stakeholder sign-off well before June 30, 2028.

What's in the full article

ArmorCode's full blog covers the operational detail this post intentionally leaves for the source:

  • Cisco’s Kenna end-of-life milestones and support deadlines for migration planning
  • ArmorCode’s scanner-agnostic integration model across multiple security tool types
  • Unified Exposure Management workflows for remediation routing and ownership tracking
  • The AI Exposure Management and agentic AI architecture sections that go beyond vulnerability governance

👉 Read ArmorCode’s analysis of Kenna end of life and exposure governance →

Kenna EOL and exposure governance: what vulnerability teams should rethink?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 18527
 

Independent vulnerability governance is becoming a structural requirement, not a feature preference. Kenna’s exit matters because many programmes relied on a scanner-agnostic layer to prevent detection vendors from also controlling prioritisation. That separation matters even more now that multi-cloud, application, supply chain, and AI findings all compete for attention. The practitioner lesson is to protect the decision layer even if the tooling stack changes.

A question worth separating out:

Q: When should organisations invest in exposure management instead of point-tool consolidation?

A: When they have multiple scanners, cloud tools, application findings, or supply chain inputs that do not resolve into one trusted queue. In that situation, consolidating tools can reduce console sprawl, but only exposure management preserves the independent ranking and workflow control needed to actually reduce risk.

👉 Read our full editorial: Kenna end of life exposes the case for independent exposure governance



   
ReplyQuote
Share: