THANK YOU FOR SUBSCRIBING


Joel Schluter, CEO and Co-founderThe global crisis has ramped up remote work and compelled companies to increasingly embrace digital infrastructures, including Software-as-a-Service (SaaS) apps, cloud platforms, and other cloud-based services, leaving them more vulnerable to cyber threats. While traditional perimeter protection (firewalls, anti-virus software, intrusion detection systems, API security methods, and so on) remains pertinent in identifying vulnerabilities and potential threats, it is no longer sufficient to keep attackers from gaining access to corporate networks.
The bottom line is that in order to safeguard their digital infrastructure, companies must adopt effective cybersecurity measures now more than ever. Nobody understands this better than VIRTIS—a leading cybersecurity firm that eradicates the exposure gap in Web App and API security by offering 24/7, fully managed shielding protection service. Founded in 2008, VIRTIS has been transforming the dynamics of the web application and API protection (WAAP) landscape through its fully managed platform. Alongside, the company leverages its scanning tools and pen testing to discover and remediate the vulnerabilities in clients' networks. VIRTIS conducts 12/7 threat analysis and leading-edge exploitation research and offers continuous custom shields development, deployment, and optimization.
According to Joel Schluter, CISO and Co-founder of VIRTIS, the upswing in intense and diverse cyber threats requires networks, servers, data, and perimeters to be highly secure. However, all too often, CISOs struggle with the plethora of tools available at their disposal to discover vulnerabilities and end up with tool fatigue. "They don't want to purchase more tools just to discover new problems but rather focus on remediation of the existing ones," Schluter says. To this end, VIRTIS offers its fully managed service that covers everything from discovering the perimeter and assets, cataloging the associated vulnerabilities to providing continuous monitoring and maintenance of assets as well as real-time application reporting and logging. "We take care of everything on behalf of our clients and they do not have to invest extensively in tools, developers, and resources," says Schluter.
VIRTIS utilizes penetration testing to find the exploitable applications and accordingly provides a plan to fix the vulnerabilities, followed by ongoing monitoring and maintenance of the assets. If the client already has a list of penetration tests and vulnerabilities, VIRTIS imports that into its security operation center and begins remediation right away. Whether the clients' focus is complex web applications, platforms, or frameworks in Azure, AWS, GCP, or on-premise, VIRTIS is capable of handling unique needs with its deep expertise.
VIRTIS caters to clients from a multitude of sectors, including healthcare, banking, finance, oil and gas, government, retail, telecom, power and utilities, IT, e-commerce, and agricultural research. Apart from its award-winning products, the company provides advisory services, including risk assessment and management, while ensuring HIPPA, PCI-DSS, and GDPR compliance. "We protect business-critical and high-value assets across multiple industries that are looking to lower the risks associated with their outward-facing web assets such as websites, web apps, APIs, and customer portals. Our diverse team is skilled to work any company and at every level," mentions Schluter.![]()
Unlike traditional methods that leave organizations exposed, we protect app-destined traffic through our global shield network, deploying unique custom shields to neutralize all existing vulnerabilities
Groundbreaking Proprietary Shielding Technology
More often than not, vulnerabilities occur within the application code itself that requires stateful remediation for session management and application logic flaws. Traditional WAFs (web application firewalls) can't address these effectively, leaving the data assets exposed. To this end, VIRTIS leverages its full-service web application and API security platform, which enables the faster development of new applications and extends the life of legacy applications through its stateful, serverless proxy shielding technology (VIRTIS Vi). "Unlike traditional methods that leave organizations exposed, VIRTIS protects app-destined traffic through its global shield network, deploying unique, custom shields to neutralize all existing vulnerabilities," explains Schluter. "Without changing a single line of the source code, our interception proxy transforms the application code instantly, counteracting all application vulnerabilities. Risk acceptance is no longer needed. We lower the risk of code remediation and offer faster resolution than anyone else in the industry," Schluter adds.
"Without changing a single line of the source code, our interception proxy transforms the application code instantly, counteracting all application vulnerabilities. Risk acceptance is no longer needed"
VIRTIS has enterprise customers championing how it approaches Web App & and API protection. “Virtis’ 24/7 fully managed service combined with their global shielding technology is the only Web App & API protection service that fully protects what they say they protect,” states Dan Bowden, VP & CISO Sentara Healthcare, Global Top 100 CISOs 2020.
What's equally important in addressing application vulnerabilities is understanding the application communication flows. As such, VIRTIS first blueprints the client's application and then understands their application patterns to segment those communications.
VIRTIS eliminates the need for excess tools, resources, and skilled staff to operate and run the web application firewall services, both cloud-based and on-premise, as it can seamlessly conduct a comprehensive analysis of assets to determine the security posture of clients. "We are operating our streamlined, automated platform at an 80 to 1 ratio—it would 80 people to our 1 automated service to achieve the same results, making us the most cost-effective solution in the industry," asserts Schluter.
Comprehensively Modernizing Vulnerability Management
Whether it's protecting its clients from cyber threats proactively or helping them when they are under attack and need urgent assistance, VIRTIS deploys its incident response team to resolve the issues in a safer, faster, and more cost-effective manner. VIRTIS recently protected a client against unique threat traffic coming from specific IT addresses and regions outside the U.S., which penetrated their firewall and exposed ten applications. VIRTIS was already managing a few of their applications. The company expanded its service to protect those applications by discovering the vulnerabilities and fixing them quickly alongside blocking malicious traffic. Compared to the average remediation time of 4-6 months to rewrite application code, VIRTIS eliminated the risks posed by the breached applications within two hours. "In a matter of hours, we deployed custom shields to stop the ongoing breach and removed the threat from adversely impacting those internet-facing applications," states Schluter.
When it comes to customer onboarding, VIRTIS follows a straightforward process wherein its skilled engineers leverage the various discovery tools, including multiple scanners, to examine clients' applications and then build a catalog of issues or vulnerabilities within those applications. This is followed by offering a remediation plan around managing those vulnerabilities, which, once accepted by the client, makes way for the "fix phase," wherein VIRTIS creates the shields and deploys them to secure the application. "Moving into the monitoring, managing, and reporting phase, we continually scan those applications for new vulnerabilities in case the code is changed, or new vulnerabilities are released. We then go ahead to create new plans for fixing them," explains Schluter. Besides, VIRTIS conducts ongoing monthly reporting entailing the newly uncovered vulnerabilities as well as the blocked attacks and incidents the company has prevented over these years. From a threat intelligence perspective, the company analyzes behavioral patterns not only in infrastructure but also in networks and people, looking at deviations from those behaviors and evaluating the associated risks.
Going the Extra Mile
What differentiates VIRTIS from its competitors is its team of forward-thinking cybersecurity experts, engineers, SOC and SIEM analysts, pen testers, and security researchers, alongside its outcome-based approach and boutique, white-glove customer service. As a woman-owned firm, VIRTIS attends several events in support of women's empowerment.
VIRTIS also prides itself on partnering only with world-class cyber security solution providers and is currently focused on signing up large Managed Security Service Providers (MSSPs) as resellers to assist their customers. "Moving ahead, we aim to strengthen our current relationship with MSSPs and partner with more payment system providers to protect their customers against fraud and loss of revenue," notes Schluter.
Company
Virtis
Management
Joel Schluter, CEO and Co-founder and Michelle Wilner, CEO, Dan Bowden, VP & CISO Sentara Healthcare, Global Top 100 CISOs 2020
Description
VIRTIS is a full-service, woman-owned cybersecurity firm that is transforming the dynamics of the web application and API protection (WAAP) landscape. The company leverages its scanning tools and pen testing to discover and remediate the vulnerabilities in clients' networks. VIRTIS conducts 24/7 threat analysis and leading-edge exploitation research and offers continuous custom shields development, deployment, and optimization. VIRTIS caters to clients from a multitude of sectors, including healthcare, banking, finance, oil and gas, government, retail, telecom, power and utilities, IT, e-commerce, and agricultural research