Kenna Security
Risk-based vulnerability management platform vendor
Kenna Security, now operated as part of Cisco following its acquisition, is a risk-based vulnerability management platform that ranks vulnerabilities by real-world exploitability and business impact rather than by generic CVSS severity…
Definition
Kenna Security, now operated as part of Cisco following its acquisition, is a risk-based vulnerability management platform that ranks vulnerabilities by real-world exploitability and business impact rather than by generic CVSS severity alone. It ingests scan data from third-party vulnerability scanners alongside threat intelligence feeds on active exploitation, then applies a data science-driven scoring model to tell security teams which of the thousands of findings in a typical environment actually pose meaningful risk right now.
Overview
Kenna Security helped popularize the risk-based vulnerability management category, built on the premise that any large organization accumulates far more vulnerability findings than it can realistically patch, and that CVSS severity scores alone are a poor proxy for which ones attackers will actually exploit. The company built its platform around a predictive model, developed with data science research originating from work at companies including Cisco, that estimates the real-world probability a given vulnerability will be exploited in the wild. Mechanically, Kenna does not run its own vulnerability scans; instead it integrates with existing scanners such as Tenable, Qualys, and Rapid7, ingesting their raw findings alongside data from threat intelligence sources tracking active exploitation, malware kits, and exploit code availability. It correlates each finding against asset criticality data (how important is this system to the business) and exploitability signals to produce a Kenna risk score, which reorders remediation priorities so that a moderately severe but actively exploited vulnerability on a critical asset outranks a theoretically more severe but never-exploited one on a low-value system. Within the market, Kenna is frequently mentioned alongside Balbix and Brinqa as a pioneer of risk-based prioritization, distinguishing itself from pure scanners by acting as an aggregation and scoring layer rather than a data-collection tool. Since its acquisition, Kenna's technology has been integrated into Cisco's broader security portfolio, including its SecureX and Vulnerability Management offerings, positioning it as part of a larger security operations suite rather than a standalone point product. In practice, large enterprises with multiple vulnerability scanners across different business units use Kenna to normalize and consolidate findings into one prioritized queue, feeding remediation teams a manageable, risk-ranked list instead of the raw union of every scanner's output. Security operations teams also use Kenna's risk trend reporting to track whether an organization's overall exposure is improving over time, which is useful for demonstrating program effectiveness to leadership. The main limitation is that Kenna's value depends entirely on the quality of the scanner data feeding it, since it does not generate its own vulnerability findings; organizations without existing scanning infrastructure gain little from Kenna alone. Its acquisition by Cisco has also shifted its positioning toward customers already invested in the Cisco security ecosystem, which can make it a less natural fit for organizations building a vendor-agnostic security stack. Prospective buyers should also confirm which specific Kenna capabilities remain available as an independent module versus which are now bundled only within larger Cisco security suites.
Key Features
- Aggregates findings from multiple third-party vulnerability scanners
- Risk score based on real-world exploitability, not just CVSS severity
- Ingests threat intelligence on active exploitation and exploit kits
- Correlates findings with asset criticality for business-context ranking
- Now integrated into Cisco's broader security operations portfolio
- Risk trend reporting to track program effectiveness over time
- Normalizes findings across scanners into a single prioritized queue
- Pioneer of the risk-based vulnerability management category
Use Cases
Alternatives
Frequently Asked Questions
From the Blog
Zero Trust Security Explained
Zero Trust means never trust, always verify. Learn how this model replaces the old network perimeter and secures modern cloud and remote work setups.
Read More Cloud & CybersecurityDevSecOps: Building Security Into Your Pipeline
DevSecOps builds security into every stage of software delivery instead of bolting it on at the end. Learn the practices, tools, and culture that make it work.
Read More Cloud & CybersecurityCommon Web Security Vulnerabilities (OWASP Top 10)
The OWASP Top 10 ranks the most critical web application security risks. Learn what each one is, how attackers exploit it, and how to defend against it.
Read More Cloud & CybersecurityWhat Is Zero Trust Security?
Zero Trust security assumes no user or device is trusted by default. Learn its core principles, how it replaces the old perimeter model, and how to adopt it.
Read More