ITSM meets IT security: KIX and Greenbone close a security gap
The pressure on companies and government agencies is mounting rapidly. The number of cyberattacks and vulnerabilities is skyrocketing while regulatory requirements, such as NIS 2, are becoming more stringent. Meanwhile, the IT landscape is growing more complex due to shadow IT, outdated systems, and insufficient processes. Today, many organizations no longer know exactly which devices and software they own.
From Detection to Resolution: The Fully Automated Security Workflow
To address a critical gap in IT security management, KIX Service Software and Greenbone, two open-source pioneers, have formed a strategic technology partnership. Thanks to the deep integration of OPENVAS's vulnerability scanning technology into the KIX ITSM system, detected security vulnerabilities are automatically converted into structured tickets. The result is a seamless, digitally sovereign process — from automated scanning to comprehensive, auditable remediation.
Learn more in this double interview:
Why is the number of security vulnerabilities currently rising so sharply? Why is open source a crucial factor in building trust, especially in IT security? And how can organizations regain full control of their infrastructure? KIX CEO Rico Barth and Greenbone CEO Elmar Geese explain all of this and more in an exclusive interview.
The number of cyberattacks has been rising for years
Has IT security really worsened, or are we just talking about it more?
Elmar Geese: "The main problem is that the attack surface has grown significantly. In the early 2010s, around 10,000 new vulnerabilities emerged each year. Now, we’re at over 50,000. The old vulnerabilities don't just disappear. That’s why the total number is likely in the millions, with many unreported cases. On top of that: Attackers always have the upper hand and a strong economic incentive. They only need one vulnerability, while defenders have to cover everything at all times.
Rico Barth: But it’s also true that people are talking about it more today. After all, the issue is almost ubiquitous, and the potential damage is greater than ever before. This can happen through ransomware, where perpetrators demand large sums to unlock systems, or by embedding themselves in software to spy and strike later. We realize just how important this area is when we talk with our partners and customers. For them, the main focus is risk assessment, planning, and sustainable processes—in other words, the administrative and planning side of IT security."
What is causing the increasing number of security vulnerabilities?
Is it the developers' fault, or is it due to the growing complexity of software and hardware?
Elmar Geese: "It’s primarily due to increasing complexity. It's also due to the fact that software is permeating more and more areas of life. In some cases, software and hardware overlap, as with firmware updates. However, the vast majority of vulnerabilities are found in software, such as applications, operating systems, and configurations. Often, these issues involve inadequate access controls, buffer overflows, or invalid input. But other factors also play a role. These include outdated technology and the fact that cybercrime is now a business model partly sponsored by the state.
You don't rely solely on open source.
Through your companies, you advocate for open-source software. Is that a gold mine for critics in the security sector?
Rico Barth: That’s true. There will certainly never be a consensus on whether open or closed solutions offer greater security. At first glance, the criticism of open source is understandable—or rather, it’s inherent in the system's nature: its openness. Since all users can view the source code, people with malicious intent could also exploit vulnerabilities. However, it is precisely this openness that makes a decisive difference for us at KIX. Through community collaboration, security gaps can be identified and closed very quickly.
Elmar Geese: Regardless of whether the source code is public, software is always insecure. Our customers don't need a statement about what's theoretically safer or less secure; they need to know how to best protect themselves when using IT. That’s why we test solutions in a live environment — because that's where the truth ultimately lies. We and KIX have decided to offer our customers the benefits of open source because we believe openness provides added value. Even proprietary offerings contain open source, so they indirectly disclose source code, albeit more selectively than we do. However, no conclusions about the software’s security can be drawn from this. That’s what products like ours are for.
You two have recently entered into a technology partnership.
How would you explain the relationship between IT Service Management (ITSM) and vulnerability management, as well as the technology behind them, to non-technical people?
Elmar Geese: Our goal is to detect vulnerabilities before attackers can exploit them. Our OPENVAS application scans the entire IT landscape to do this, covering all assets from software to hardware. You can think of it this way: Imagine you live in a house with a swarm of robots designed to protect it from burglars. The robots swarm out and check every door, window, and lock. As soon as they discover a vulnerability and assess it as critical, they sound the alarm. Then, the security team determines what needs to be done. In our case, the house represents a company's or government agency's IT landscape.
Rico Barth: That’s where we come in as the owner, essentially. When OPENVAS detects a vulnerability, it is automatically reported to our IT service management software. A ticket is created, and the workflow begins. The incident is pre-classified as a security incident and is linked to the affected IT device or software product from KIX’s asset database. Then, it is sent to the relevant team for further review and handling. All essential information about the detected vulnerability is visible immediately on the ticket, eliminating the need for lengthy searches or guesswork. IT administrators can immediately see what is affected, who needs to be notified, and what the threat landscape looks like in the broader context of all assets. This way, we can prevent shadow IT while ensuring we don’t lose sight of the big picture.
You mention a lack of clarity.
How big has the problem of so-called shadow IT become?
Rico Barth: Quite big — unfortunately. The asset database links the planned and actual states of the IT landscape. Sometimes there are blind spots because, for example, a business department buys software or an IT device in a hurry without going through a central approval process. A comprehensive scan resolves these discrepancies in the asset inventory and integrates them into the standard IT support process. This is particularly helpful given the shortage of IT professionals, as it saves a lot of time on manual research and allows teams to focus on their core tasks.
Elmar Geese: Our clients often experience major surprises when we examine their network for the first time. Shadow IT is simply a problem of complexity — the larger the organization, the harder it is to maintain order.
Which companies and public institutions should pay particularly close attention to their IT security?
Rico Barth: "All regulated sectors, such as local, state, and federal government agencies; law enforcement agencies; hospitals; emergency services; and banks." However, all organizations and companies should think outside the box while keeping the requirements of NIS 2, the Cyber Resilience Act, and the BSI’s Basic Protection Framework in mind. This can significantly reduce the attack surface for hackers.
What other plans do you have for the security sector?
Elmar Geese: These days, cyberattacks are increasingly exploiting software vulnerabilities rather than stolen login credentials. As a result, we’re seeing a growing demand for our solutions and new features. This year, that includes primarily container scanning, agents, and further AI integration. We’re also excited to see how the market responds to our integration with KIX.
Rico Barth: Even though our focus is on ITSM, we’ve always kept security in mind with KIX. For example, we use data anonymization, encryption, and secure two-factor authentication. Similarly, integrating ISMS software is a key pillar of IT security, as is fully integrating planning and documentation for compliance checks to meet ISO 27001 requirements, for example. We intend to continue on this path in the future. Of course, we will continue to use open source. Openness and transparency are important to us because we consider them fundamental to building trusting relationships with our customers.