Organisations should prioritise continuous automated red teaming when they need deeper attack path validation from an initial foothold toward critical systems and data. It is most valuable when the question is not just what is exposed, but how an attacker could move through the environment. Exposure analytics remains important, but CART is stronger for testing realistic progression and objective reach.
Why the choice changes from coverage to attacker progression
Continuous automated red teaming is the better choice when you need to validate how an attacker could progress after the first foothold, not just whether assets or secrets are visible. Broader exposure analytics is excellent for discovery and prioritisation, but CART answers a different question: can an access path realistically be chained into reach of high-value systems, data, or control planes?
That difference matters when exposure alone is not a reliable indicator of exploitable risk. A credential, exposed endpoint, or misconfiguration may look severe in analytics, yet the practical question is whether it can be combined with weak segmentation, privilege gaps, or trust relationships to produce meaningful impact.
For teams building a broader identity and access posture, the visibility problem is often the same one documented in Ultimate Guide to NHIs: organisations can know that something is exposed without knowing whether it can actually be used to move laterally or reach privileged systems. CART helps test that progression.
When CART should take priority over exposure analytics
Prioritise CART when the environment has one or more of these conditions: critical systems are reachable through several hops, the attack surface is highly interconnected, or remediation decisions depend on proving exploitability rather than merely counting exposures. It is also the stronger choice when leadership needs a defensible answer on blast radius, not a long list of exposed assets.
- Use CART when you need to validate segmentation, trust boundaries, privilege boundaries, or tool access paths under realistic attacker movement.
- Use CART when exposure analytics is producing too many findings to distinguish theoretical risk from likely impact.
- Use CART when a small number of footholds could create outsized downstream consequence if chained correctly.
- Use CART when control validation matters more than inventory completeness.
Exposure analytics still has a strong role when the organisation is early in its programme, lacks reliable asset or secret visibility, or needs to establish baseline hygiene. In practice, the two approaches are complementary: analytics finds where exposure exists, CART tests whether that exposure matters operationally.
That is especially relevant in secret and credential-heavy environments. Research summarised in The 52 NHI breaches Report shows that compromised non-human identities often become the access mechanism for lateral movement, so prioritising progression testing is more useful than stopping at exposure counts alone.
What good looks like in a mature program
A mature program uses exposure analytics for breadth and CART for depth. The analytics layer should answer what is exposed, where the highest-risk secrets or access paths are, and which assets are most likely to matter. CART should answer whether those pathways can be traversed from an initial foothold, which dependencies make that possible, and what objective reach an attacker can achieve before detection or containment.
The best operating model is to link the two. Exposure analytics should feed CART hypotheses, and CART results should feed back into remediation priorities. If CART repeatedly shows that certain exposed paths do not lead anywhere meaningful, those findings can be deprioritised. If it shows that a small set of exposures unlocks critical reach, those issues deserve immediate treatment even if they appear low volume in the broader inventory.
For practitioner navigation, the most useful adjacent reference is 52 NHI Breaches Analysis, which reinforces how real-world compromise often depends on chained access rather than a single exposed item.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS Control 2 — Inventory and Control of Software Assets | Exposure analytics depends on knowing what assets and attack surface exist. |
| CIS Control 6 — Access Control Management | CART is strongest when validating whether exposed access paths can become real privilege and reach. | |
| Recommendation — Use asset inventory to seed exposure analytics and reduce blind spots before red team validation. Tighten access paths and least privilege where red team paths show objective reach. | ||
| NIST CSF 2.0 | ID.RA — Risk Assessment | The choice between analytics and CART is a risk prioritisation question about which exposure matters most. |
| Recommendation — Prioritise testing methods that best measure the highest-impact risk paths in your environment. | ||
| MITRE ATT&CK | TA0008 — Lateral Movement | CART is valuable when the security question is how an attacker can move after initial access. |
| Recommendation — Map red team findings to lateral movement paths and close the steps that enable progression. | ||
Practitioner Guidance
What to prioritise: If your main decision is remediation ranking, keep exposure analytics in the foreground. If your main decision is whether an exposed path can become a real incident, move CART ahead of broader analytics for that cycle.
Decision rule: Treat CART as the priority when a small number of pathways could reach crown-jewel systems, when segmentation is uncertain, or when leadership wants evidence of exploitability rather than exposure volume.
What to verify: Make sure the testing scope includes realistic footholds, privilege escalation opportunities, and the systems that actually matter to the business. CART is weak if it is only checking for noisy edge cases.
Practitioner takeaway: Exposure analytics tells you where risk might exist, but CART tells you whether the environment actually lets an attacker turn that exposure into reach.
Related resources from NHI Mgmt Group
- When should organisations prioritise AI red teaming over waiting for production incidents?
- Why do organisations need continuous automated red teaming instead of relying on periodic penetration tests?
- When should organisations prioritise red teaming over penetration testing?
- Should organisations prioritise just-in-time access over broader GRC automation?