By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: SafeBreachPublished January 28, 2026

TL;DR: Exposure validation is moving closer to identity, automation, and AI governance, not just attack simulation, according to SafeBreach. The company’s 2025 review says it expanded from breach and attack simulation into CTEM, added AI-driven analysis features, introduced MCP-based AI agent access to simulation data, and integrated PAM workflows for password rotation, while also reporting nine new CVEs and coverage for nine CISA alerts.


At a glance

What this is: SafeBreach’s 2025 review describes a shift from BAS toward CTEM, with new AI features, MCP-based agent access, and tighter PAM integration.

Why it matters: For IAM and NHI practitioners, the key issue is that validation platforms are beginning to touch AI agent access, secret handling, and privileged workflow automation.

👉 Read SafeBreach’s 2025 year-in-review on CTEM, AI features, and exposure validation


Context

Continuous threat exposure management only works when validation is tied to real attack paths, credential handling, and remediation workflows. As AI features and automation enter exposure platforms, the identity question becomes whether the systems that analyse risk are themselves governed as privileged actors. That matters for NHI governance, agentic AI oversight, and human access control alike.

This review is a vendor year-in-review, but the operational question is broader than product milestones. It shows how exposure validation is converging with privileged access management, AI-assisted analysis, and simulation-driven prioritisation, which pushes identity governance deeper into security operations rather than leaving it at the edge of IAM programmes.


Key questions

Q: How should security teams govern AI use when users, APIs, and agents all generate different telemetry?

A: Start by separating the governance problem into distinct control domains. Human prompts, service API calls, and agentic workflows need different evidence, different owners, and different enforcement points. A single dashboard rarely gives enough context to govern all three, so teams should build policy around the path where each action begins, not only around the logs it leaves behind.

Q: Why do exposure validation tools need identity and privilege controls?

A: Because the tools increasingly touch live attack paths, privileged workflows, and remediation data. Without scope limits, audit trails, and clear ownership, they can become a high-trust operational layer that is hard to govern. Identity controls make sure the platform sees only what it needs and can only do what it is supposed to do.

Q: When does password rotation automation create more risk than it reduces?

A: It creates more risk when rotation is disconnected from inventory accuracy, service dependencies, and offboarding state. In that situation, you can break applications, miss hidden credential copies, or leave stale access alive elsewhere. Rotation only reduces risk when the full lifecycle is visible and coordinated.

Q: What should organisations do when CTEM findings do not lead to remediation?

A: They should treat that as a governance failure, not a tooling issue. If exposure validation identifies a real attack path but no owner, deadline, or control change follows, the programme is not reducing risk. The fix is to bind findings to accountable teams, remediation SLAs, and tracked closure criteria.


Technical breakdown

How CTEM changes the role of exposure validation

Continuous Threat Exposure Management, or CTEM, extends validation beyond isolated tests into an ongoing cycle of discovery, prioritisation, validation, and mobilisation. In practice, that means security teams need evidence about which exposures are exploitable, how they chain together, and which remediations actually reduce attack paths. The technical shift is from static control checking to repeatable simulation against live infrastructure and control stacks. That creates stronger operational feedback, but it also increases dependency on reliable asset identity, access boundaries, and safe test execution.

Practical implication: teams should map exposure validation outputs to remediation workflows, asset inventories, and privilege boundaries, not treat them as standalone test results.

What MCP access means for AI agents and simulation data

Model Context Protocol, or MCP, gives AI agents a standard way to connect to tools and data sources. In this context, it means an AI system can query simulation results and combine them with other sources for analysis. That is useful, but it also turns the AI layer into a governed integration point rather than a passive assistant. Once an agent can access security telemetry, the core controls become authentication, authorisation, logging, and scope limitation. If those are weak, the agent can become an untracked intermediary for sensitive operational data.

Practical implication: treat MCP-connected agents as privileged integrations and apply explicit access scopes, logging, and change control before exposing security telemetry.

Why PAM integration matters for password rotation workflows

Privileged Access Management systems govern elevated credentials, but many environments still rely on manual password updates that create inconsistency and delay. When a platform integrates with PAM to automate password rotation, the technical benefit is not just convenience. It reduces the window in which a credential can remain valid after exposure, reuse, or staff turnover. The deeper issue is synchronisation across systems. If rotation happens without coordinated inventory and dependency awareness, services break or stale credentials remain active in shadow paths. Effective integration therefore depends on lifecycle visibility as much as on rotation mechanics.

Practical implication: align rotation automation with inventory accuracy, dependency mapping, and offboarding processes before relying on it operationally.


Threat narrative

Attacker objective: The attacker aims to turn known exposure paths into real compromise by moving from initial access to privileged execution and downstream impact.

  1. Entry occurs through exposed or testable attack paths that simulation platforms try to emulate before attackers do.
  2. Escalation happens when privileged workflows, credential exposure, or lateral movement gaps are validated but not remediated.
  3. Impact is reduced if the organisation uses exposure findings to close attack paths before they are exploited in production.

NHI Mgmt Group analysis

Exposure validation is becoming an identity governance problem, not just a security testing problem. Once validation platforms start touching PAM, attack paths, and AI-assisted analysis, they sit much closer to identity decision-making than traditional BAS tools. That changes the governance question from whether a simulation ran to whether the platform itself is authorised to observe, model, and prioritise privileged access. Practitioners should treat exposure validation as part of control assurance, not a separate technical silo.

AI-assisted security analysis creates a new governance surface for security tooling itself. If an AI agent can query simulation data through MCP, the agent becomes part of the trusted operational chain. That introduces an access-control question for the AI layer, and it maps directly to NHI governance because the agent behaves like a non-human consumer of privileged telemetry. Practitioners should assume this pattern will spread, and they should govern the agent’s access like any other machine identity.

Attack-path simulation is only useful when it is tied to lifecycle action. The value of emulating lateral movement and credential harvesting is not the simulation result itself, but the ability to fix the control gap before it becomes a breach. That pushes teams toward tighter integration between exposure data, PAM, and offboarding workflows. Practitioners should measure whether their validation process changes access decisions, not just reporting dashboards.

CTEM is moving identity control decisions closer to SOC and engineering workflows. That is a practical shift because remediation prioritisation increasingly depends on which accounts, secrets, and privileged paths are actually exploitable. It also means identity teams can no longer assume their governance model ends at access reviews. Practitioners should expect more overlap between exposure management, IAM, and operational response, and plan the handoffs accordingly.

Attack simulation platforms now need their own least-privilege model. Once a platform can trigger tests, analyse telemetry, and connect to adjacent systems, it becomes a high-trust operational component. That makes scope control, auditability, and separation of duties essential. Practitioners should review the platform as if it were a privileged NHI consumer, because functionally that is what it has become.

What this signals

Exposure validation is converging with NHI governance because the same privileged paths that attackers abuse are now the paths simulation platforms must model. That means teams should assess whether their CTEM programme can trace a finding all the way to identity ownership, rotation, and offboarding. In our research, 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, which is a reminder that visibility without lifecycle action rarely changes outcomes, according to The 2024 ESG Report: Managing Non-Human Identities.

AI-assisted analysis inside security tooling will force more explicit governance of machine-to-machine access. If an agent can query simulation results, the enterprise has created a new non-human consumer of sensitive operational data, which should be governed like any other privileged integration. Teams should expect policy, logging, and revocation requirements to expand as these assistants move from convenience features to embedded workflow components.

The most useful next step is to connect CTEM to identity assurance rather than keep it in a separate validation lane. That means prioritising attack paths that involve credentials, secrets, and privilege escalation, then ensuring remediation ownership sits with IAM, PAM, and cloud platform teams rather than only with security operations.


For practitioners

  • Map exposure findings to identity controls Link simulation output to specific IAM, PAM, and secret-management owners so attack paths trigger named remediation actions rather than generic risk tickets.
  • Govern AI agents as privileged integrations If AI assistants or MCP-connected agents can access security telemetry, define their scope, logging, approval path, and revocation process before production use.
  • Tie rotation automation to lifecycle data Automate password rotation only when inventory, dependency mapping, and offboarding data are current enough to prevent service disruption or stale access.
  • Use validation to test real attack chains Prioritise simulations that emulate credential harvesting, lateral movement, and privilege escalation so remediation efforts align with the paths attackers actually use.

Key takeaways

  • SafeBreach’s 2025 review shows CTEM, AI analysis, and PAM automation converging in ways that pull identity governance into exposure management.
  • AI agents connected through MCP create a new privileged access problem, because the analysis layer itself becomes a governed non-human consumer of telemetry.
  • Security teams should tie validation results to lifecycle ownership, or simulation will inform dashboards without reducing attack paths.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5, CIS Controls v8, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0DE.CM-7Exposure validation and attack-path testing support continuous monitoring of security control effectiveness.
NIST SP 800-53 Rev 5SI-4Attack simulation and detection validation align with monitoring for malicious activity.
CIS Controls v8CIS-8 , Audit Log ManagementThe review emphasises telemetry, parsers, and validation data that depend on trustworthy logs.
NIST Zero Trust (SP 800-207)The review touches identity, telemetry access, and privileged workflow boundaries.
NIST AI RMFGOVERNAI-assisted analysis and MCP-connected agents create governance obligations for the tool chain.

Use validation results to verify monitoring coverage and close gaps in control effectiveness.


Key terms

  • Continuous Threat Exposure Management: Continuous Threat Exposure Management is the ongoing process of finding which assets, identities, and paths are actually reachable from the current environment. It moves risk assessment away from static inventories and toward live exposure, so security teams can prioritise what an attacker or misuse path can reach now.
  • Model Context Protocol: Model Context Protocol is an open protocol that lets AI agents connect to tools and data sources. It expands what an agent can reach, so governance has to cover not only the model and its prompts, but also every system that can receive or return agent-driven data.
  • Attack-path validation: Attack-path validation is the practice of proving whether an attacker can move from one weakness to another until they reach meaningful impact. It goes beyond scanning by testing how exposures connect across identity, network, cloud, and application layers under realistic adversarial conditions.
  • Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.

What's in the full article

SafeBreach's full review covers the operational detail this post intentionally leaves for the source:

  • Breakdown of the new exposure validation platform components and how Validate and Propagate are intended to work together
  • Specific AI-assisted capabilities such as remediation suggestions, troubleshooting assistants, and AI-generated scenarios
  • Examples of PAM integration and password rotation automation across connected environments
  • Details on the 2026 CTEM roadmap and the additional phases the vendor says it will address

👉 SafeBreach’s full review covers the platform roadmap, AI capabilities, and research highlights in more implementation detail.

Deepen your knowledge

NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, secrets management, and identity lifecycle control. It is designed for practitioners who need to connect identity discipline to operational security outcomes across modern programmes.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org