TL;DR: Traditional vulnerability management still helps with structured discovery, but ArmorCode argues it cannot see the exposures that now drive real risk, including identity issues, misconfigurations, and attack paths that chain low-severity findings into compromise. The shift is from CVSS-only backlogs to continuous, context-rich prioritisation that changes what teams fix first and why.
At a glance
What this is: ArmorCode’s analysis argues that exposure management is replacing CVE-centric vulnerability management because modern risk now includes identities, misconfigurations, shadow AI, and chained attack paths.
Why it matters: For IAM practitioners, this matters because over-privileged accounts, dormant credentials, and excessive permissions are now part of the same risk picture as software flaws and must be governed together.
By the numbers:
- Only 5.7% of organisations have full visibility into their service accounts.
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface.
👉 Read ArmorCode's analysis of exposure management versus vulnerability management
Context
Exposure management is the response to a simple problem: periodic vulnerability scanning no longer captures the full attack surface. Modern enterprises now run cloud workloads, third-party APIs, AI-generated code, and identity estates that span many platforms, so a CVE list alone misses the exposures that actually drive breach risk, including identity and privilege issues.
That gap matters to IAM and NHI programmes because access entitlements, service accounts, dormant credentials, and over-privileged identities are now part of the same prioritisation problem as code flaws and cloud misconfigurations. The typical legacy model is increasingly inadequate for organisations that need continuous, business-aware risk decisions rather than scan-driven backlogs.
The article frames this as a shift from finding flaws to understanding exposure, and that starting point is now typical rather than exceptional across mature security programmes.
Key questions
Q: What breaks when vulnerability management does not include cloud and identity context?
A: Teams lose the ability to distinguish an exploitable weakness from a theoretical one. A high-severity issue in a locked-down service is not the same as a medium-severity issue behind a public API or over-privileged access path. Without context, remediation effort is often misallocated.
Q: Why do NHIs complicate exposure management?
A: NHIs multiply risk because they can be invisible to legacy scans, highly privileged, and spread across cloud, SaaS, and automation workflows. If those identities are not governed continuously, even a moderate technical flaw can become a fast route to data loss or privilege abuse. Identity state changes whether an exposure is theoretical or actionable.
Q: How do teams know if exposure prioritisation is actually working?
A: They should see high-risk external assets move to remediation faster than low-impact findings, with fewer unknown internet-facing systems and tighter links between exposure alerts and change tickets. If a critical edge device can sit in queue for days, prioritisation is failing.
Q: Who is accountable when exposure management misses an identity-driven risk?
A: Accountability usually sits with the team that owns risk governance across application, cloud, and identity domains, not with scanners alone. If service accounts or access entitlements are excluded from prioritisation, the failure is a governance gap, not just a tooling gap. That is why exposure programmes need clear ownership for identity-linked blast radius.
Technical breakdown
Why CVE-centric scanning misses identity and exposure risk
Traditional vulnerability management is built around scheduled scans, CVEs, and CVSS scores. That works for known software defects, but it does not model whether an asset is reachable, whether a flaw is being exploited, or whether the risk is really coming from a misconfiguration, exposed credential, or over-privileged identity. In practice, many of the most damaging enterprise exposures never appear on a CVE list at all. This is why vulnerability data alone creates a false sense of completeness. Modern exposure management adds context from asset criticality, reachability, exploit intelligence, and identity state so teams can see what an attacker could actually use, not just what scanners can enumerate.
Practical implication: Treat CVE output as one signal among many, and fold identity posture and reachability into the same prioritisation workflow.
How attack path mapping changes remediation order
Attack path mapping connects small issues into meaningful compromise routes. A medium-severity flaw can become urgent if it sits on an internet-facing asset, combines with an over-privileged account, or provides a route to sensitive data. This is different from flat severity ranking because it models how adversaries chain exposures. In exposure management, the question becomes which issues collapse the largest number of paths, not which findings merely look severe in isolation. That approach reduces backlog noise and makes remediation decisions more defensible because the ranking reflects likely attacker behaviour, not only scanner output or vendor scoring differences.
Practical implication: Prioritise remediation around chained exposure routes and choke points instead of working findings top-down by CVSS.
Why unified exposure platforms care about identity states
The article’s core technical point is that exposure is cross-domain. Scanner feeds from SAST, DAST, SCA, cloud tools, and infrastructure checks must be normalised into a shared model, but that model is incomplete if it ignores identity context. Over-privileged service accounts, dormant credentials, and excessive permissions change the blast radius of every other finding. That is where IAM and NHI governance intersect with exposure management: identity state determines whether a flaw is merely present or actually exploitable. Continuous correlation is the control plane that turns scattered findings into actionable risk.
Practical implication: Map identity entitlements and NHI privilege into exposure scoring so remediation reflects blast radius, not just defect count.
Threat narrative
Attacker objective: The attacker objective is to turn fragmented exposure, especially identity weakness and reachable misconfiguration, into a route to high-value systems or data.
- Entry begins with exposed or weakly governed assets such as cloud workloads, third-party APIs, or credentials that are not captured by traditional CVE-centric scanning.
- Escalation occurs when a low or medium-severity issue combines with excessive permissions, reachability, or a toxic configuration cluster that opens an attack path.
- Impact follows when the adversary uses the chained exposure to reach sensitive data, privileged systems, or a business-critical workload.
NHI Mgmt Group analysis
Exposure management is becoming the operating model because CVE-driven programs cannot represent real enterprise risk. Scanner output still matters, but it is only a fragment of the exposure picture once cloud, SaaS, identity, and AI-generated code all contribute to attack surface. Security teams now need a model that can compare technical severity with business context, reachability, and identity posture. That is the shift from counting findings to governing exposure, and it is now the baseline for mature programmes.
Identity is no longer a side input to exposure scoring, it is a multiplier on every other weakness. Over-privileged service accounts, dormant credentials, and excessive permissions determine whether a flaw is exploitable at scale or trapped behind a narrow blast radius. This is where IAM and NHI governance intersect directly with exposure management, because the same vulnerability can carry very different risk depending on who or what can use it. Practitioners should treat identity state as a first-class risk variable, not a separate hygiene track.
Chained risk is the more useful concept than isolated severity. The most dangerous finding is often not the highest CVSS score, but the one that links reachability, privilege, and data access into a path an attacker can actually follow. Exploitability cluster: a combination of individually moderate issues that becomes materially dangerous when correlated across asset, identity, and business context. Teams that can identify these clusters will make better remediation decisions and reduce backlog pressure faster.
Unified correlation is now a governance requirement, not a tooling preference. The article’s model reflects a broader market reality: security teams must normalise findings once, score them once, and route them once if they want consistent decisions across AppSec, cloud, infrastructure, and identity domains. That means exposure programmes should be judged on decision quality and speed of containment, not on the number of raw findings they ingest.
AI-generated code and shadow AI widen the gap between discovery and governance. As AI-assisted development accelerates change, the attack surface grows in places legacy scanning was never designed to watch continuously. That creates a parallel identity problem where machine and application behaviour blur, so governance teams need tighter visibility into both code provenance and the identities that can deploy or invoke it. Practitioners should prepare for exposure management to absorb more identity-adjacent risk over time.
What this signals
Exposure management will increasingly absorb identity governance work that once sat in separate IAM queues. When service accounts, API keys, and cloud entitlements influence remediation priority, IAM teams need tighter integration with AppSec and cloud posture workflows, not just periodic access reviews.
Privilege-weighted exposure: the next useful operating model will score findings by how much access they unlock, not only by how severe they look. That makes NHI lifecycle controls, especially offboarding, rotation, and ownership mapping, part of exposure management rather than a separate hygiene exercise.
Programmes that cannot correlate identity state with technical reachability will continue to over-invest in noisy findings and under-invest in the routes that matter. The practical test is simple: if a finding cannot be tied to an owner, a reachable path, and a privilege boundary, it is not ready for remediation prioritisation.
For practitioners
- Map identity and NHI exposure into the same risk queue Bring over-privileged service accounts, dormant credentials, and excessive permissions into the same prioritisation model as CVEs and cloud findings so blast radius is visible in one place.
- Replace severity-only triage with exposure-based ranking Score findings using reachability, exploitability, business criticality, and toxic combinations so remediation follows attacker paths rather than scanner volume.
- Normalise scanner output before assigning ownership Deduplicate SAST, DAST, SCA, container, cloud, and infrastructure findings into one governed workflow so teams stop paying the reconciliation tax multiple times.
- Use identity controls to shrink remediation blast radius Reduce the impact of every exposure by tightening privilege, removing dormant access, and reviewing service account scope before the next remediation cycle.
- Track exposure decisions, not just findings Measure how quickly teams identify choke points, close attack paths, and reduce time-to-remediate for the exposures that matter most to the business.
Key takeaways
- Vulnerability management still finds defects, but it cannot by itself represent the identity and exposure risks that now shape enterprise compromise.
- The scale problem is not just the number of CVEs, it is the amount of hidden identity and configuration risk that sits outside CVE lists altogether.
- Teams that unify identity state, reachability, and business criticality will make better remediation decisions and reduce the attack paths that matter most.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | Identity exposures and excessive permissions are central to the article's risk model. |
| NIST CSF 2.0 | PR.AC-4 | Least-privilege access is a core control for identity-driven exposure reduction. |
| NIST SP 800-53 Rev 5 | AC-6 | The article repeatedly highlights over-privilege and blast-radius reduction. |
| MITRE ATT&CK | TA0006 , Credential Access; TA0008 , Lateral Movement | The article's attack-path framing depends on credential abuse and movement through chained exposures. |
| CIS Controls v8 | CIS-5 , Account Management | Dormant credentials and ownership gaps are directly relevant to the article's identity exposure theme. |
Align exposure scoring with access control reviews and reduce privilege before remediating lower-value flaws.
Key terms
- Exposure management: Exposure management is the practice of identifying which assets are reachable by attackers and reducing that reach before exploitation occurs. For collaboration systems like SharePoint, it is not enough to know that a patch exists, because public accessibility changes the speed and likelihood of attack.
- Reconciliation Tax: The manual effort required to combine duplicate alerts, normalise severity, and make sense of overlapping scanner outputs. It consumes analyst time, slows remediation, and often hides the small set of exposures that matter most.
- Toxic Access Combination: A toxic access combination is a set of permissions that becomes dangerous when granted together, even if each entitlement looks acceptable on its own. In identity governance, these combinations matter because they can enable misuse, separation-of-duties failures, or broader compromise.
- Attack Path Mapping: Attack path mapping is the process of tracing how an adversary could chain exposures into a route to a sensitive asset. It helps security teams focus on choke points, because removing one linked issue can collapse several potential compromise routes at once.
What's in the full article
ArmorCode's full blog covers the operational detail this post intentionally leaves for the source:
- How its Unified Vulnerability Management pipeline normalises SAST, DAST, SCA, cloud, and infrastructure findings into one workflow
- The specific scoring inputs used to combine CVSS, EPSS, CISA KEV, reachability, and business criticality
- How automated routing assigns findings to owners without manual triage across AppSec, CloudSec, and InfraSec
- Where Anya's agentic AI is used to reduce alert noise and accelerate remediation workflows
Deepen your knowledge
The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It is designed for practitioners building identity controls that work across modern enterprise programmes.
Published by the NHIMG editorial team on August 19, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org