By NHI Mgmt Group Editorial TeamDomain: Breaches & IncidentsSource: Horizons.aiPublished September 9, 2026

TL;DR: Continuous validation helped a distributed equipment rental company replace point-in-time pentests to uncover exploitable exposure faster, validate an SSH key leak within eight hours, and turn suspected Cisco weakness and Active Directory password issues into measurable remediation, according to Horizons.ai. The practical lesson is that exposure management now depends on evidence, retesting, and identity control changes, not assessment cadence alone.


At a glance

What this is: This is a practitioner case study showing how continuous exposure management replaced periodic pentesting with ongoing validation, faster discovery, and measurable remediation.

Why it matters: It matters because IAM, PAM, NHI, and broader security teams need current evidence of exploitable exposure, especially where password policy, service accounts, and lateral movement risk change faster than scheduled tests.

By the numbers:

👉 Read Horizons.ai's blog on continuous exposure management and CTEM


Context

Continuous exposure management is a response to a basic governance problem: environments change faster than periodic security assessments can keep up. In practice, that means the security team may know an issue existed on test day but not whether it became exploitable the next day, which is especially relevant when identity controls, SSH keys, and privileged access paths are changing continuously. For identity-heavy environments, the gap between exposure creation and exposure discovery is where risk accumulates.

The article shows that exposure is not only a vulnerability management problem. It is also an identity and privilege problem when password quality, service-desk practices, and SSH credentials can open paths for lateral movement. That is why continuous validation matters for IAM and PAM teams, not just vulnerability teams. The starting position described here is increasingly common in large distributed enterprises, where a point-in-time pentest no longer provides a durable risk picture.


Key questions

Q: How should security teams handle continuous exposure management when environments change daily?

A: Security teams should use continuous validation to supplement scheduled testing, because point-in-time assessments quickly become stale in dynamic environments. The key is to connect discovery, exploit validation, remediation, and retesting in one loop so that changes in credentials, configuration, or access paths are measured as current risk, not historical risk.

Q: Why do weak passwords and poor password practices still create so much breach risk in enterprise environments?

A: Weak passwords and poor hygiene increase the chance that attackers can guess, reuse, or steal credentials and then move into other systems. Risk rises when credentials are shared, never rotated, or left outside central control. In practice, the control gap is less about password length alone and more about governance, visibility, and enforcement.

Q: What are the signs that exposure management is still too reactive?

A: The clearest signs are when teams only learn about risk during a pentest, struggle to track asset and configuration changes, and spend time chasing low-value findings. Another signal is when remediation is driven by static reports instead of current attack surface data. If exposure is only visible after an assessment, the programme is still operating reactively.

Q: How do IAM and PAM teams fit into exposure management programmes?

A: IAM and PAM teams should own the access-side exposure signals, including password policy, reset workflows, credential lifecycle, and privileged authentication paths. Those controls often determine whether a weakness becomes exploitable. The right model is shared ownership, where security testing validates access risk and identity teams drive the changes that remove it.


Technical breakdown

Why point-in-time pentests miss changing exposure

A pentest is a controlled snapshot of reachable attack paths at a moment in time. It can validate whether a weakness is exploitable, but it does not continuously re-evaluate the environment as configurations, credentials, and services change. Continuous exposure management closes that gap by repeatedly testing the live environment and correlating findings with attack feasibility. In this model, validation is not just discovery. It is evidence generation for prioritisation, remediation, and retesting. That is why it fits modern infrastructure, where a harmless change in one hour can become a lateral movement path the next.

Practical implication: Use continuous validation to supplement, not replace, scheduled assessments when exposure changes faster than test cycles.

How credential and password weaknesses become attack paths

The article links password quality, service-desk handling, and weak SSH credentials to exploitable access. That is a classic credential abuse pattern: once an attacker can authenticate, the problem shifts from finding a foothold to expanding privileges or moving laterally. Identity controls matter because the attack path often begins with reusable credentials or poorly governed authentication practices rather than a software flaw. In other words, the exposed asset is not only the account. It is the trust relationship created when identity material is weak, reused, or poorly controlled across systems.

Practical implication: Treat password policy, service-desk reset handling, and SSH credential governance as attack-surface controls, not administrative hygiene.

Why evidence-based remediation changes the security model

The strongest part of the case study is the feedback loop. The team did not stop at finding exposure. It retested after changes and measured whether the risk actually dropped. That is the operational difference between tracking activity and reducing exposure. Continuous measurement turns identity and infrastructure changes into governable outcomes, such as fewer similar passwords, fewer exploitable keys, and fewer confirmed attack paths. It also gives security leaders a defensible way to show improvement without relying on assumptions about control effectiveness.

Practical implication: Build retesting into remediation so you can verify that identity and infrastructure changes actually reduce exploitable exposure.


Threat narrative

Attacker objective: The attacker objective is to turn newly exposed credentials or misconfigurations into authenticated access and broader internal movement.

  1. Entry began when an exposed SSH key pair or weak credentials created an authentication path into the environment.
  2. Escalation occurred when those credentials or adjacent weaknesses could be used to reach broader systems or lateral movement opportunities.
  3. Impact was the creation of validated attack paths that required remediation before they could be exploited operationally.
  • Cisco DevHub NHI breach — IntelBroker exploited exposed Cisco credentials, API tokens and keys in DevHub.
  • Coupang Signing Key Breach — Unrevoked signing key credentials expose 33.7 million records after employee offboarding failure at Coupang.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Continuous exposure management is becoming an identity governance problem, not just a scanning problem. The article shows that password policy, SSH keys, and service-desk handling can create attack paths faster than periodic review can catch them. For IAM and PAM teams, the relevant question is no longer whether access exists, but whether the organisation can prove when it became risky and when it was reduced. That is a governance shift from static review to continuous validation.

Exposure latency is the named concept this case study sharpens. Exposure latency is the time between a risky change being introduced and the point at which it is discovered and remediated. The shorter that window, the lower the opportunity for credential abuse or lateral movement. In identity-heavy environments, exposure latency often matters more than the original misconfiguration because it determines how long an attacker has to act. Practitioners should treat that window as a measurable control metric.

Password weak points still behave like privilege pathways when they are operationally embedded. The article’s password findings matter because they show that identity weaknesses are rarely isolated to a single user. They spread through password reuse, service desk workflow, and recovery practices. That pattern maps directly to IAM governance, where access policy and account recovery processes can either contain or amplify exposure. Teams should treat authentication hygiene as a live control plane, not an annual cleanup exercise.

Continuous retesting is what turns remediation into evidence. The article demonstrates that a reduction in similar passwords or a remediated Cisco issue is only meaningful when the environment is tested again. That aligns with NIST Cybersecurity Framework 2.0 and the broader logic of control validation. For security leaders, the lesson is to measure whether the attack path disappeared, not whether a ticket was closed.

Attack-surface management and identity governance are converging around the same question: what can actually be exploited now? Once environments are continuously validated, the boundary between vulnerability management, IAM, and PAM narrows. Access scope, credential quality, and exploitability become one risk picture. Practitioners should expect exposure management programmes to pull identity teams into operational remediation decisions much earlier than traditional pentest workflows did.

From our research:

  • The average estimated time to remediate a leaked secret is 27 days, despite 75% of organisations expressing strong confidence in their secrets management capabilities, according to The State of Secrets in AppSec.
  • From our research: Organisations maintain an average of 6 distinct secrets manager instances, creating fragmentation that undermines centralised control, according to The State of Secrets in AppSec.
  • From our research: If you are reworking credential governance, start with NHI Lifecycle Management Guide because lifecycle visibility is the difference between exposure detection and exposure persistence.

What this signals

Exposure management is becoming a control-validation discipline for identity-heavy environments. As organisations shift from scheduled testing to continuous validation, the practical question for IAM and PAM teams is whether their controls can prove risk reduction in near real time. The hard part is not finding more issues. It is showing that remediation actually shortens the exposure window, especially where credential lifecycle and password hygiene intersect with operational change.

Machine and human identity governance are converging around the same remediation loop. Credentials, reset processes, and privileged paths now need the same evidentiary standard that vulnerability teams expect from exploit validation. The broader signal is that identity programmes will be judged less by policy existence and more by whether they can demonstrate that the attack path is gone after action. That is a governance expectation shift, not just a tooling change.

Our research suggests the control gap is usually persistence, not discovery. The 27-day remediation average shows that organisations often detect exposure faster than they eliminate it. For practitioners, the next step is to align identity lifecycle operations with continuous exposure pipelines so credentials, keys, and passwords do not remain live long enough to be reused.


For practitioners

  • Build continuous validation into exposure management Use ongoing testing to confirm whether newly introduced changes create real attack paths, then feed the results into your CTEM pipeline and remediation workflow.
  • Treat SSH keys and password policy as attack-surface controls Review exposed keys, weak credential patterns, and reset workflows together so identity material is governed as part of the live attack surface, not a separate admin task.
  • Retest after every high-risk identity change Revalidate after password policy changes, service-desk process updates, or credential remediation so you can prove the exposure has actually been reduced.
  • Measure exposure reduction, not ticket closure Track how many exploitable paths disappear after remediation and how quickly they reappear, because that is the evidence that matters for IAM and PAM governance.

Key takeaways

  • Periodic pentests are too slow for environments where exposure can change in hours, not quarters.
  • Identity controls such as passwords, SSH keys, and reset workflows are part of the exploitable attack surface.
  • Continuous retesting is what converts remediation activity into proof that exposure has actually fallen.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack surface, NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, and ISO/IEC 27001:2022 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKTA0006; TA0008 — Credential Access; Lateral MovementThe article centers on credential exposure and lateral movement paths.
Recommendation — Map exposed keys and weak credentials to TA0006 and TA0008, then validate whether the path is still exploitable.
NIST CSF 2.0PR.AC-4 — Access Permissions and AuthorisationsThe story repeatedly ties exposure to access scope and privilege control.
Recommendation — Review access permissions under PR.AC-4 and remove any standing paths that can still be exploited.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeLeast privilege is central to limiting how exposed credentials can be used.
Recommendation — Apply AC-6 to reduce privilege breadth wherever authentication material can be reused or abused.
CIS Controls v8CIS-5 — Account ManagementAccount lifecycle and password handling drive several of the article's findings.
Recommendation — Use CIS Control 5 to tighten account governance, reset handling, and credential oversight.
ISO/IEC 27001:2022A.8.2 — Privileged Access RightsPrivileged access rights are implicated when SSH keys and admin access become exposure paths.
Recommendation — Restrict and review A.8.2 privileged access rights where identity material can enable lateral movement.

Key terms

  • Continuous Threat Exposure Management: Continuous Threat Exposure Management is the ongoing process of finding which assets, identities, and paths are actually reachable from the current environment. It moves risk assessment away from static inventories and toward live exposure, so security teams can prioritise what an attacker or misuse path can reach now.
  • Exposure-to-Closure Latency: Exposure-to-closure latency is the time between identifying a security weakness and proving it has been fixed. It is a practical governance measure because it captures whether findings actually change risk, rather than simply increasing ticket volume or reporting output.
  • Credential Abuse: Credential abuse is the use of valid secrets or accounts by an unauthorised party or for unauthorised purposes. In practice, it often looks like normal authentication unless teams correlate context, privilege, and behaviour. It is one of the most persistent ways identity failures become breaches.
  • Attack Surface Validation: The process of testing whether exposed systems, identities, and access paths can actually be abused by an attacker. It goes beyond finding misconfigurations by showing whether those weaknesses translate into real compromise potential.

What's in the full article

Horizons.ai's full blog covers the operational detail this post intentionally leaves for the source:

  • How the CTEM attack surface management pipeline ingests telemetry into Splunk and uses it operationally
  • What the team saw in the SSH key exposure case and how the evidence was validated over time
  • The remediation workflow behind the Active Directory password changes and later retesting
  • How the Cisco IOS XE validation translated into remediation and mitigation decisions

👉 The full Horizons.ai post covers the SSH key case, password remediation, and Cisco validation in more operational detail.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, secrets management, and identity lifecycle control. It helps security practitioners connect identity operations to measurable risk reduction across their programmes.
NHIMG Editorial Note
Published by the NHIMG editorial team on September 11, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org