What should CVE be when it grows up?

August 5, 2025 | 1:00 pm ET / 10:00 am PT

At Security BSides Las Vegas, IST Senior VP Bob Lord moderated a panel on the future of the CVE program. What are the challenges it faces? What governance models should be considered?

 

At Security BSides Las Vegas, IST Senior Vice President for Digital Security Strategy Bob Lord moderated a conversation with Github Senior Security Manager Madison Oliver, CISA Senior Technical Director Chris Butera, Cisco Security Principal Engineer in the Threat Detection and Response Business Group Jerry Gamblin, and runZero Vice President of Security Research Tod Beardsley to discuss the possible paths forward for the CVE program.

The CVE Program is a pillar of the cybersecurity ecosystem. For more than a quarter century, it has provided an authoritative source of data about vulnerabilities for software users. It is also critical for continuing to drive security into the design and development process. However, over the last 18 months, both the CVE Program and the US National Vulnerability Database have faced funding challenges. At the same time, developments in the European Union have led to the creation of the EU Vulnerability Database. Congress has taken note, and in June, members requested a formal audit of the program. What are the challenges facing the CVE Program? How should these be communicated to policymakers in a way that maintains the critical function and avoids a fractioning of the ecosystem? What are new governance models that should be considered?

Panelists: Jerry Gamblin, Madison Oliver, Bob Lord, Tod Beardsley, Chris Butera

Panelists

Event Type

Topics

Share

Facebook
Twitter
LinkedIn
Print
MENU

GET IN TOUCH

Email: [email protected]
Send us a message: Contact

JOIN THE CATALINK MAILING LIST