

ImmuniWeb Discovery
By ImmuniWeb
Here is a brief overview of the typical implementation process for ImmuniWeb Discovery software:
Initial Setup: The process begins by entering your company name and main website URL. This is a straightforward step that requires minimal input from the user.
Payment and Activation: After payment is received, the service is activated. This typically takes up to three business days, during which discovered applications and digital assets will appear on the Discovery dashboard.
Dashboard Preparation: Within 3-4 days, the initial dashboard is prepared and populated with the discovered assets and security insights.
Ongoing Monitoring: Once set up, the system provides continuous monitoring of digital assets, dark web exposure, and compliance with security standards.
Time Commitment: For ongoing analysis, expect to spend approximately 1-2 hours per week reviewing new findings, which is manageable by a junior analyst or shared among team members.
The overall implementation process is designed to be quick and user-friendly, allowing organizations to start monitoring their security posture with minimal delay.
ImmuniWeb Discovery can be customized to fit specific business needs in several ways:
Customized Dashboard Views: Users can filter and sort the Discovery Dashboard to display different categories of security incidents, allowing for a tailored view that meets specific monitoring needs.
AI-Enabled Risk Scoring: The platform uses AI and machine learning algorithms to provide risk scoring that can be customized to prioritize specific threats and vulnerabilities relevant to the business.
Project Sharing and Management: Enhanced project sharing capabilities allow users to grant or revoke access permissions, enabling customized collaboration and management of security projects.
Tailored Security Ratings and Compliance Monitoring: ImmuniWeb Discovery provides actionable security ratings and compliance monitoring that can be adapted to specific regulatory requirements like GDPR, PCI DSS, and NIST.
Detection of Specific Assets: The platform can identify more than 250 types of digital and IT assets, allowing businesses to focus on assets that are most relevant to their operations.
Integration with DevSecOps: ImmuniWeb Discovery supports integrations with DevSecOps processes, allowing businesses to customize their security testing and monitoring within their existing workflows.
Custom Alerts and Notifications: Users can receive customized alerts about security events, misconfigurations, and weaknesses, ensuring that the most relevant information is prioritized.
These customization options make ImmuniWeb Discovery a flexible solution that can be tailored to the unique security needs and compliance requirements of different organizations.
ImmuniWeb Discovery offers various training and support options for new users to ensure they can effectively utilize the platform:
Webinars and Product Training: ImmuniWeb provides live webinars and product training sessions that cover various aspects of the platform, such as Dark Web monitoring, attack surface management, and legal responses to phishing. These sessions are designed to help users hone their skills and understand the platform's capabilities better.
Certification Opportunities: Participants in the webinars can qualify to become ImmuniWeb Certified Professionals, which may include earning Continuing Professional Education (CPE) credits.
24/7 Customer Support: ImmuniWeb offers continuous support via email and a web ticketing system. While urgent support tickets are not available for ImmuniWeb Discovery, normal-priority support tickets are addressed within four business hours.
Phone and Live Support: Additional support options include phone and live support, providing users with multiple channels to seek assistance.
These training and support options are designed to help users maximize the benefits of ImmuniWeb Discovery and address any challenges they may encounter while using the platform.
ImmuniWeb Discovery implements several security measures to protect data, ensuring a robust defense against potential threats:
Continuous Security Monitoring: The platform conducts 24/7 security monitoring, assessing security by more than 1,000 criteria to detect misconfigured or vulnerable IT assets.
Dark Web Monitoring: ImmuniWeb Discovery continuously monitors the Dark Web and Deep Web channels to detect stolen data, credentials, and compromised systems, helping prevent data breaches.
Compliance with Security Standards: The platform supports compliance with standards such as GDPR, PCI DSS, and NIST, ensuring that data handling processes meet regulatory requirements.
AI-Driven Risk Scoring: Leveraging AI and machine learning, ImmuniWeb provides enhanced risk scoring for security incidents and data leaks, allowing for better prioritization and response to threats.
Two-Factor Authentication (2FA): The platform offers 2FA support to enhance user authentication security.
Non-Intrusive Technology: ImmuniWeb Discovery uses production-safe, non-intrusive technology for asset discovery and monitoring, minimizing the risk of disrupting operations while ensuring data security.
Instant Alerts and Notifications: Users receive instant alerts about security incidents, data leaks, and other vulnerabilities, enabling timely responses to potential threats.
These measures collectively help organizations protect their data and maintain a secure digital environment.
ImmuniWeb Discovery releases updates on a seasonal basis, typically providing major updates several times a year. These updates are managed and communicated to customers through various channels:
Seasonal Updates: ImmuniWeb Discovery releases major updates seasonally. For example, notable updates have been released in December, September, and July, introducing new features and enhancements to the platform.
Communication Channels: Updates are communicated to customers through the ImmuniWeb website, newsletters, and direct notifications. Customers are also invited to educational webinars to learn about new features and functionalities.
No Additional Cost: Updates are provided to existing subscriptions at no additional cost, ensuring that customers continuously benefit from the latest advancements without incurring extra charges.
Webinars and Training: ImmuniWeb offers webinars and training sessions to showcase and explain new features. These sessions provide an opportunity for users to ask questions and request new product features or integrations.
These measures ensure that customers are kept informed about the latest developments and can take full advantage of the platform's evolving capabilities.
ImmuniWeb Discovery's policy on data ownership and portability includes the following key points:
Data Ownership: The data discovered and provided to the customer through ImmuniWeb Discovery is based on Open-Source Intelligence (OSINT). This means that the assets, data, and information are already accessible, visible, or otherwise discoverable on the Internet.
Customer Authority: During a Discovery project, the customer grants ImmuniWeb full authority to monitor various web, cloud, and other Internet resources on behalf of the customer or third parties for which the discovery is performed.
Data Portability: Customers can export vulnerability data and findings in various formats such as PDF or XLS. ImmuniWeb also provides API integrations to synchronize data flow with existing Security Information and Event Management (SIEM) systems or other internal systems.
Data Deletion: The dashboard and its functionality remain active while the customer pays for the subscription. After the subscription expires, data will be securely deleted 100 days later or upon the customer's written request. Once deleted, the data cannot be recovered.
Transparency and Compliance: ImmuniWeb ensures transparency in its data handling practices and complies with legal guidelines for gathering online cyber threat intelligence and purchasing data from illicit sources, as outlined by the U.S. Department of Justice.
These policies ensure that customers have control over their data while using ImmuniWeb Discovery and can manage it according to their needs and compliance requirements.
ImmuniWeb Discovery provides flexibility for organizations to scale their usage up or down based on changing needs. Here are the relevant terms and options related to scaling:
Subscription Model: ImmuniWeb Discovery operates on a subscription basis, allowing organizations to adjust their subscription plans as their needs change. This model provides the flexibility to scale services up or down depending on the organization's requirements.
Account Management: Customers can manage their account information and subscription details directly through the ImmuniWeb Portal. This includes modifying the scope of services or adjusting the level of monitoring and protection as needed.
Service Adjustments: Organizations can increase or decrease the number of assets or the extent of monitoring and testing services they require. This scalability ensures that businesses can tailor the platform's capabilities to match their evolving security landscape and budget constraints.
Customer Support: ImmuniWeb offers customer support to assist with any changes in service levels, ensuring that organizations can smoothly transition between different subscription tiers or service scopes.
These terms and options provide organizations with the ability to dynamically adjust their use of ImmuniWeb Discovery, ensuring that they can effectively manage their security needs as they grow or change over time.
Here are the terms and conditions for contract renewal and cancellation for ImmuniWeb Discovery:
Subscription Duration: The standard subscription duration for ImmuniWeb Discovery is one year. However, customers can reach out to ImmuniWeb if they need a different subscription length.
Renewal Responsibility: Customers are responsible for renewing their subscriptions on time. If a subscription is not renewed or is renewed with a delay, the customer must make backups of their data, as ImmuniWeb is not responsible for data retention beyond the subscription period.
Terms Changes: ImmuniWeb reserves the right to change the terms of service at any time without prior notice. Any changes will be posted online, and continued use of the service implies acceptance of the new terms.
These points outline the key aspects of renewing or canceling a subscription with ImmuniWeb Discovery, emphasizing the importance of timely renewal and awareness of potential changes in terms.
ImmuniWeb Discovery software meets several compliance standards to help organizations manage their cybersecurity and data protection requirements. The key compliance standards supported by ImmuniWeb Discovery include:
GDPR (General Data Protection Regulation): Ensures compliance with data protection and privacy laws applicable in the European Union and the UK.
HIPAA (Health Insurance Portability and Accountability Act): Addresses the security and privacy of health-related information in the United States.
PCI DSS (Payment Card Industry Data Security Standard): Ensures the secure handling of credit card information and transactions.
NIST (National Institute of Standards and Technology): Provides a framework for improving cybersecurity and managing risk.
New York SHIELD Act: Requires businesses to implement data security measures to protect the personal information of New York residents.
NYDFS (New York Department of Financial Services): Imposes cybersecurity requirements for financial services companies operating in New York.
Singapore PDPA (Personal Data Protection Act): Governs the collection, use, and disclosure of personal data in Singapore.
Singapore MAS (Monetary Authority of Singapore): Sets out requirements for financial institutions in Singapore to ensure cybersecurity.
These compliance standards help organizations ensure that their IT assets and data handling practices align with various regulatory requirements, reducing the risk of data breaches and legal penalties.