TL;DR: Security teams still lose to simple exposures even with more telemetry, because knowing a vulnerability exists is not the same as knowing what is business-critical, who can fix it, and what the blast radius is, according to Tonic and cited research including Verizon DBIR and Mandiant M-Trends. The shift is from static findings to continuously evaluated, context-rich exposure decisions that security can defend and IT can actually execute.
At a glance
What this is: This is an analysis of why vulnerability management is failing and how context-driven exposure management changes prioritisation from raw alerts to business-aware action.
Why it matters: It matters to IAM and security practitioners because exposure decisions depend on identity reachability, privilege chains, and operational ownership, not just asset lists.
By the numbers:
- 34%.
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities.
👉 Read Tonic's analysis of context-driven exposure management and the Department of Know
Context
Primary keyword: context-driven exposure management is gaining traction because organisations have more telemetry than understanding. The article argues that vulnerability scanners, CNAPP, EDR, SIEM, IAM, asset inventories, and logs still leave teams unable to answer the practical questions that drive safe decisions, especially where identities determine reachability and blast radius.
That gap matters for identity programmes because exposure is rarely just a technical flaw. Service accounts, OAuth-connected apps, and privileged pathways turn a low-level issue into a material path to sensitive systems, which is why a terrain-aware view is more useful than a static inventory.
The result is a governance problem as much as an operations problem. Security cannot prioritise remediation credibly if it cannot explain business impact, access paths, and ownership in the same decision cycle; that is the typical failure mode the article describes.
Key questions
Q: How should security teams prioritise exposures when asset inventories are incomplete?
A: They should prioritise by exploitability, reachability, and business impact rather than by inventory completeness alone. The practical move is to combine vulnerability data with identity paths, network exposure, and ownership so teams can focus on the few issues that materially expand blast radius. Incomplete inventory is a reason to improve context, not a reason to stop prioritising.
Q: Why do vulnerabilities become identity risks so quickly in modern environments?
A: Because many systems do not just process data, they also carry credentials, tokens, certificates, and service accounts that control other systems. Once an attacker reaches the vulnerable asset, those identities can provide lateral movement, privilege escalation, or persistence. That is why vulnerability management and identity governance must be linked rather than run as separate programmes.
Q: What do security teams get wrong about false positives in exposure management?
A: They often treat false positives as a scanning problem instead of a decision problem. The real issue is that unvalidated findings consume analyst time, reduce trust in scoring, and delay the highest-value fixes. Validation should be used to separate potentially exploitable exposure from theoretical issues before remediation effort is committed.
Q: Which frameworks support contextual exposure prioritisation?
A: NIST CSF and NIST SP 800-53 both support context-based risk decisions, while identity-heavy exposure paths often map well to OWASP NHI guidance and Zero Trust principles. The key is to translate the framework into operational prioritisation, ownership, and continuous reassessment instead of treating it as a reporting exercise.
Technical breakdown
Why vulnerability lists fail to show real exposure
A vulnerability list records discrete findings, but exposure is relational. Whether a flaw matters depends on reachability, privilege, data sensitivity, compensating controls, and the surrounding identity graph. Two identical CVEs can have very different risk if one sits behind strong segmentation and the other is reachable through an over-privileged service account or third-party integration. Context-driven exposure management tries to fuse these signals into an operational picture rather than a static queue of issues. That is why discovery alone rarely changes outcomes: teams already know there are problems, but they cannot always determine which problems create an exploitable path.
Practical implication: map findings to reachability and privilege paths before assigning remediation priority.
How agentic systems change exposure evaluation
Agentic systems are being used here as continuous evaluators, not autonomous decision-makers. Their job is to observe changes in cloud, identity, and infrastructure signals, correlate them across tools, and update which exposures are currently reachable or business-critical. In practical terms, this turns exposure management into a living control loop rather than a periodic review process. The value is not that the system finds more issues, but that it can keep pace with environmental drift, integration changes, and shifting exploit relevance. This is especially important where identity pathways determine whether a technical issue becomes a real path to impact.
Practical implication: build continuous correlation between identity, asset, and threat signals, not point-in-time review cycles.
Why blast radius matters more than finding count
Blast radius is the business question hidden inside exposure management. Security teams need to know not only whether something is vulnerable, but which assets, identities, data sets, and workflows become reachable if it is abused. That framing changes prioritisation from raw count reduction to path reduction. It also gives IT a clearer remediation choice set, because the task becomes shrinking attack pathways with minimal operational disruption rather than chasing every alert equally. In mature programmes, this is where exposure management stops being a reporting layer and becomes a decision engine.
Practical implication: prioritise attack-path reduction for the systems and identities that expand blast radius the most.
Threat narrative
Attacker objective: The attacker objective is to turn a single exposed weakness into a shorter path to business-critical systems or sensitive data.
- Entry occurs through unaddressed exposures that attackers can reach before teams have contextualised their business impact.
- Escalation follows when exposed systems connect to identities, privileges, or integrations that were assumed to be lower risk than they are in practice.
- Impact happens when the attacker uses that path to reach critical systems, data, or operational workflows faster than remediation can close the gap.
NHI Mgmt Group analysis
Context-driven exposure management is really identity-aware exposure management. The article is framed around vulnerabilities, but the practical risk is often created by identities that define what is reachable and what can be abused. Service accounts, API connections, and privileged access paths turn technical issues into exploitable business exposure. For identity teams, the lesson is that exposure triage must include privilege and reachability, not just asset severity.
Blast-radius knowledge is the missing control, not more findings. Security stacks already surface huge volumes of telemetry, but that does not answer which exposures actually matter in a live environment. The governance gap is decision quality: if teams cannot explain the attack path, ownership, and business consequence in one view, remediation will stay slow and contested. Practitioners should treat blast-radius analysis as a control objective, not a dashboard feature.
Agentic evaluation is becoming the operating model for exposure prioritisation. The article points toward systems that continuously correlate signals and update risk context as environments change. That model aligns with modern identity governance because standing assumptions age quickly in cloud and NHI-heavy environments. The field is moving toward continuous evaluation of reachability, privilege, and exploitability, which means periodic review alone is no longer enough.
Department of Know is a governance model, not a slogan. The article’s core argument is that security earns faster remediation only when it can explain why a control matters in operational terms. That is consistent with NIST CSF thinking around identifying, protecting, and responding based on current context, not static inventories. Teams should view contextual decision-making as the mechanism that turns prevention into enforceable risk reduction.
Exposure management will increasingly converge with identity governance. Once organisations can see how identities, workloads, and integrations shape attack paths, the line between vulnerability management and IAM becomes thinner. That convergence matters because the highest-value remediation often targets access path quality rather than software defects alone. Practitioners should prepare for shared ownership between security operations and identity teams.
What this signals
Context-driven exposure management will push identity teams to work more closely with vulnerability and cloud operations because the priority is shifting from finding issues to understanding which identities make those issues exploitable. That is where blast radius becomes a governance metric, not a technical afterthought.
Exposure-path governance: the emerging control problem is not whether telemetry exists, but whether organisations can continuously explain how an exposure becomes a business risk. That requires linking identity adjacency, reachability, and ownership in the same operating model, especially where service accounts and integrations extend the attack surface.
For practitioners, the next step is to formalise decision quality. If a team cannot show which identities, assets, and workflows are implicated by an exposure, remediation will remain noisy and contested. The organisations that win here will be the ones that can convert context into a repeatable prioritisation process, not just a better dashboard.
For practitioners
- Build attack-path based prioritisation Rank exposures by the shortest path they create to critical systems, sensitive data, or privileged identities. Use reachability, identity adjacency, and business criticality in the same scoring model so remediation work reflects actual blast radius rather than raw CVSS volume.
- Fuse identity and exposure telemetry Correlate IAM, asset, cloud, and vulnerability data in one workflow so you can see which identities can reach which assets and through what dependencies. This is especially important for service accounts and third-party integrations that extend exposure beyond the asset inventory.
- Define ownership at the point of prioritisation Attach each high-risk exposure to a named owner, a remediation option set, and the operational tradeoff before the ticket is issued. That makes the output actionable for IT and prevents security from producing findings that cannot be closed efficiently.
- Treat exposure context as a continuous control Re-evaluate exposure whenever reachability, privilege, deployment state, or threat relevance changes. Static review cycles miss cloud drift and evolving integration paths, so the control has to update with the environment rather than the calendar.
Key takeaways
- Security teams do not fail from a lack of telemetry, but from a lack of context that turns findings into defensible decisions.
- Identity relationships matter because they determine which exposures are merely present and which ones are actually exploitable.
- Context-driven exposure management succeeds when it reduces blast radius, clarifies ownership, and updates continuously as environments change.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | ID.RA-1 | Risk identification is central to deciding which exposures matter in context. |
| NIST SP 800-53 Rev 5 | RA-5 | Vulnerability scanning is foundational, but it must feed contextual remediation decisions. |
| OWASP Non-Human Identity Top 10 | NHI-03 | Identity-linked exposures often involve stale or over-privileged non-human identities. |
| NIST AI RMF | MANAGE | Agentic evaluation and continuous reassessment map to operational risk management. |
| MITRE ATT&CK | TA0007 , Discovery; TA0006 , Credential Access | The article focuses on how attackers discover and exploit reachable weaknesses. |
Map exposures to current risk context and update priority when reachability or business impact changes.
Key terms
- Context-driven exposure management: A security approach that prioritises remediation using current business, identity, and reachability context rather than raw vulnerability counts. It combines telemetry from multiple systems to show which exposures are actually exploitable and which create the greatest operational blast radius.
- Blast Radius: The potential scope of damage if a specific credential or identity is compromised. Identities with broad permissions have a larger blast radius and represent a higher priority for least-privilege enforcement and security controls.
- Agentic Soc: An agentic SOC is a security operations model where AI systems assist with triage, investigation, and response using tool access and execution authority. The control challenge is not just accuracy, but governance of what the machine can see, decide, and do.
- Attack path: A sequence of identities, permissions, systems, and data stores that an attacker can traverse after obtaining trusted access. In practice, attack paths matter more than single accounts because they show how a low-risk identity can become a route to high-value exposure.
What's in the full article
Tonic's full article covers the operational detail this post intentionally leaves for the source:
- How the exposure management workflow translates fragmented telemetry into a prioritised remediation queue.
- The practical distinctions between inventory, exposure, exploitability, and business-criticality in live operations.
- Why agentic systems are being used to maintain continuously updated risk context across changing environments.
- The decision model for assigning owners and remediation tradeoffs to high-impact exposures.
Deepen your knowledge
NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and identity lifecycle fundamentals. It helps practitioners connect identity controls to broader security decision-making across modern enterprise programmes.
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org