Exposure and vulnerability
What this is
Exposure management is the practice of knowing, continuously, what an attacker could reach and what they could do with it. It covers three questions that are usually sold as one. What is exposed, which exposure matters most, and whether the controls meant to close it are actually running.
Why it matters
A penetration test is a photograph. It is accurate on the day it is taken, and an estate that adds a cloud service on Tuesday and a subdomain on Thursday has moved away from the photograph before the report is formatted. Nothing in the report is wrong. It is describing an organisation that no longer exists.
What replaced it is continuous, and it splits along those three questions, because the tools do. A tool that discovers assets does not know which ones matter to the business. A tool that ranks findings does not know whether the agent meant to remediate them is installed. Treating the three as one product is how an organisation ends up with three dashboards and no answer.
What it solves
- Assets that were never entered in the inventory, because nobody remembers creating them
- Finding counts that have grown past the point where a team can act on them
- The same vulnerability reported three times, under three names, by three tools
- Controls that were bought, deployed, and never verified in the field
In our portfolio
They are quoted together and they are sold together. None of them replaces another, which is the test each had to pass before it was taken on.
Next to this
Threat intelligence covers the part of your exposure that is outside your estate entirely. Credentials for sale, a lookalike domain, data offered on a forum. Cyberthint maps your external assets in order to know what to watch for. S4E monitors them in order to tell you what to fix.