TL;DR: Security teams can still miss what attackers are exploring between confirmed scans and reports because scanners see surfaces, not intent, according to INTIGRITI. As AI compresses discovery and exploitation timelines, the gap between documented scope and what is actually exposed becomes a governance problem, not just a tooling problem.
At a glance
What this is: This analysis argues that security programs over-rely on confirmed reports and scans, leaving a blind spot between what is documented and what attackers are actively exploring.
Why it matters: For IAM and security practitioners, the issue matters because exposure, privilege, and access boundaries can drift faster than report cycles, especially where identity, OAuth, and external-facing controls intersect.
By the numbers:
- Lack of credential rotation is cited as the top cause of NHI-related attacks by 45% of organisations, ahead of inadequate monitoring and logging at 37% and over-privileged accounts at 37%.
👉 Read INTIGRITI's analysis of the between-reports visibility gap
Context
The between-reports problem starts when teams treat scans, inventories, and confirmed findings as the full security picture. In practice, those tools tell you what has already been proven, not what is being explored, chained, or quietly drifting out of control across identity, external exposure, and access boundaries.
This matters in identity-heavy environments because attackers often test exposed systems through secrets, OAuth connections, service accounts, and forgotten administrative paths before a formal report exists. Between reports, the question is not only whether a vulnerability was confirmed, but whether access paths and trust relationships are becoming easier to abuse.
AI increases the pace of discovery and reduces the time available to interpret weak signals. That makes the gap between documented scope and attacker interest more dangerous, and it is now typical for mature programs to discover that blind spots persist even when their reporting cadence looks healthy.
Key questions
Q: What breaks when security teams rely only on scanning and pre-runtime checks?
A: Scanning and pre-runtime checks can identify weaknesses, but they do not stop a live AI-driven attack once execution begins. If a model or agent can already reach the workload, the attacker can still open connections, access files, and continue chaining actions. Without runtime enforcement, the control only produces visibility, not containment.
Q: Why do external exposure and identity trust need to be reviewed together?
A: Because many real-world exposure paths are created by trust relationships, not just by open services. OAuth links, SSO boundaries, service accounts, and forgotten admin paths can extend reach in ways a simple asset list will not show. Reviewing them together helps security teams see where valid access has become operationally unsafe.
Q: How do teams know if between-reports visibility is improving?
A: Look for earlier, more specific investigation triggers, not just more alerts. Useful signals include repeated probing of the same asset, recurring attention from researchers, and faster escalation when a surface keeps resurfacing. If those signals reach the right owners before the next report, the programme is getting ahead of attacker interest.
Q: Who is accountable when exposure drifts between reporting cycles?
A: Accountability should sit with the owners of the asset, the identity trust relationship, and the response process that turns weak signals into action. Frameworks such as NIST CSF and NIST SP 800-53 support that accountability model because they tie monitoring, access control, and response together instead of treating them as isolated tasks.
Technical breakdown
Why scanners miss attacker intent
Scanners and inventories are designed to confirm known conditions, such as reachable services, exposed assets, and validated vulnerabilities. They are poor at capturing attacker intent, which is exploratory, selective, and opportunistic. An attacker may probe a surface repeatedly because it looks forgotten, chained, or reachable from the internet, even if no direct vulnerability has been formally reported. That means coverage metrics can improve while real exposure remains unchanged. In identity and access terms, the same problem appears when tools record existence but not behavioural context around credentials, tokens, OAuth trust, or overexposed admin paths.
Practical implication: treat scan results as one input, not the control objective, and add signal sources that capture exploration before confirmed compromise.
The reality gap between documented scope and exposed scope
Documented scope is what the organisation believes it owns and governs. Exposed scope is what an outsider can actually reach, chain, or influence right now. Those two sets diverge because of M&A leftovers, orphaned subdomains, shadow environments, exposed admin interfaces, and third-party trust glue such as SSO redirects or OAuth boundaries. This is an identity problem as much as an asset problem, because trust relationships can extend beyond the inventory that security teams think they are managing. The gap matters most when access is technically valid but operationally forgotten.
Practical implication: reconcile external exposure, identity trust, and asset ownership together, not as separate review streams.
Why AI compresses the path from discovery to exploitation
AI shortens the time between finding something interesting and testing whether it can be abused. That makes the period between reports more dangerous because fewer human review cycles fit between discovery, validation, and exploitation. The result is a smaller decision window for security teams and a larger premium on early, proof-safe signals. In practice, this does not replace scanners or ASM and EASM tooling. It means those tools need an earlier layer of context, so teams can see what is being explored before the next confirmed event arrives.
Practical implication: prioritise earlier detection and triage signals so attackers do not define the next report for you.
NHI Mgmt Group analysis
Between-reports visibility is now a governance gap, not a tooling gap. Security teams have invested heavily in scans, inventories, and dashboards, yet attackers still operate in the interval between confirmed outputs. That interval is where intent, repetition, and weak signals accumulate before a formal finding exists. The practical conclusion is that exposure management must account for pre-report exploration, not just confirmed vulnerabilities.
The named concept here is between-reports visibility. It describes the ability to detect what is being investigated, probed, or quietly drifting out of control before a report formalises the problem. This is especially relevant where IAM, OAuth, and external attack surface meet, because trust relationships can look valid while remaining poorly governed. Practitioners should treat this as a control design issue, not a reporting enhancement.
Identity and access boundaries are part of exposure management, even when the article looks like pure surface-area analysis. Forgotten admin paths, third-party glue, and exposed credentials all sit at the intersection of asset visibility and identity governance. That makes NHI, secret, and OAuth oversight central to the problem, because attackers often exploit the trust layer rather than the hostname. The conclusion for IAM leaders is that inventory without lifecycle control leaves an exploitable gap.
AI does not create the blind spot, but it makes the blind spot operationally intolerable. Faster discovery means more assets, more paths, and more partial signals arrive before human interpretation catches up. That shifts the programme burden toward earlier triage, stronger ownership, and clearer escalation thresholds. Security leaders should expect reporting models that stop at confirmed outcomes to lose relevance as attacker speed increases.
The next maturity step is proof-safe context, not more noise. If a signal cannot be acted on safely, it is easy to ignore, but if it cannot be generated before the next report, it is too late. The better programme pattern is to combine external exposure, identity trust, and investigation context into one operational view. Practitioners should use that model to decide what gets investigated first.
What this signals
Between-reports visibility should become a programme metric, not an occasional investigation outcome. If teams can see repeated exploration earlier, they can separate genuine exposure from background noise and avoid letting attackers define the next priority queue.
Identity teams should expect the boundary between asset management and IAM to keep blurring. As OAuth trust, service accounts, and external exposure become more tightly coupled, the programme needs joint ownership across exposure management, secret governance, and access review.
The strongest path forward is a control model that turns weak signals into action before formal reporting catches up. That means linking exposure data, identity trust, and escalation thresholds into one workflow instead of waiting for the next scanner cycle to reveal the problem.
For practitioners
- Implement pre-report signal collection Add sources that capture exploration patterns, repeated probing, and weak external signals before a finding is confirmed. Use those signals to trigger triage for assets that keep resurfacing as likely targets, especially where internet reachability or identity trust is involved.
- Reconcile identity trust with exposed assets Review OAuth connections, SSO boundaries, service accounts, and externally reachable admin paths in the same workflow as asset ownership. That prevents the organisation from treating identity trust as separate from exposure management, which is where the between-reports gap often forms.
- Shorten escalation paths for weak signals Define what constitutes an actionable pre-confirmation signal and who must respond before the next report cycle. If a team cannot move from first exploration to investigation quickly, attackers will keep the advantage in the interval that matters most.
Key takeaways
- The core problem is not missing reports, but missing the period before a report exists.
- Identity trust, OAuth links, and externally reachable admin paths are part of exposure management, not separate concerns.
- AI compresses attacker timelines, so earlier signal layers are now essential for practical defence.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | TA0007 , Discovery; TA0006 , Credential Access | The article focuses on attacker exploration before confirmed findings and on identity-trust abuse. |
| NIST CSF 2.0 | DE.CM-1 | Continuous monitoring is central to closing the between-reports visibility gap. |
| NIST SP 800-53 Rev 5 | AU-6 | Audit review and analysis support earlier detection from weak security signals. |
| OWASP Non-Human Identity Top 10 | NHI-08 | The topic intersects with secret and identity trust gaps that attackers exploit between reports. |
| NIST Zero Trust (SP 800-207) | Zero Trust is relevant where exposed paths and trust relationships extend beyond assumed boundaries. |
Map repeated probing and identity misuse to discovery and credential-access tactics, then prioritise weak signals.
Key terms
- Between-reports visibility: The ability to see meaningful attacker exploration before a finding, incident, or formal report confirms the issue. It focuses on early, proof-safe indicators that show what is being probed, tested, or repeatedly targeted across assets and identity trust relationships.
- Proof-safe signal: An investigation signal that is reliable enough to trigger action without requiring a full compromise or a confirmed vulnerability. In practice, this means evidence that can be acted on safely while still being early enough to reduce attacker advantage.
- Reality gap: The difference between what a security team has documented and what is actually reachable, exposed, or exploitable in the environment. This gap widens when ownership, identity trust, and external exposure are managed separately.
- Mobile Identity Trust Boundary: The point at which a mobile device stops being a passive endpoint and starts acting as part of the identity assurance process. When apps can read approvals, automate dialogs, or steal codes, the phone itself becomes part of authentication and must be governed as such.
What's in the full article
INTIGRITI's full article covers the operational detail this post intentionally leaves for the source:
- How the vendor defines between-reports visibility in practical operational terms
- Examples of earlier signal layers that security teams can use before the next confirmed report
- The product and workflow context behind proof-safe investigation signals
- The follow-on direction the vendor says it is taking next for reporting and visibility
👉 INTIGRITI's full article expands on the signal model, current blind spots, and what comes next.
Deepen your knowledge
The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It helps practitioners connect identity controls to broader security and risk programmes.
Published by the NHIMG editorial team on August 18, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org