By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: NucleusPublished June 2, 2026

TL;DR: The 2026 Verizon DBIR shows exploitation of vulnerabilities rose to 31% of initial access while credential abuse fell to 13%, and only 26% of CISA Known Exploited Vulnerabilities were fully remediated in 2025, according to Verizon. The message is clear: prioritisation must shift from severity-first vulnerability management to exposure management that accounts for exploitability, reachability, ownership, and business impact.


At a glance

What this is: Verizon’s 2026 DBIR argues that vulnerability exploitation now leads initial access, and that exposure management must replace patch-only prioritisation.

Why it matters: For IAM, NHI, and broader security programmes, the report reinforces that access context, privilege paths, and third-party exposure can matter as much as the vulnerability itself.

By the numbers:

👉 Read Nucleus’s analysis of the 2026 DBIR shift from vulnerability management to exposure management


Context

Exposure management starts with a simple distinction: vulnerability management tells you what is broken, while exposure management tells you what is most likely to become part of an attack path. The Verizon DBIR makes that distinction operational by showing that exploitation now outranks credential abuse as the leading initial access vector, which means prioritisation can no longer rely on severity scores alone.

That shift matters to identity practitioners because exploitable weaknesses rarely stay isolated. They intersect with privileged accounts, third-party integrations, remote access, and service credentials, which is where NHI governance, IAM, and PAM controls become part of exposure reduction rather than separate hygiene tasks.


Key questions

Q: How should security teams prioritise vulnerabilities when remediation capacity is limited?

A: Prioritise by exposure, business criticality, and the identities attached to the affected asset. A remotely reachable flaw on a system with privileged access or sensitive data deserves earlier attention than a technically severe issue on an isolated low-value system. Tie severity scoring to ownership, exploitability, and blast radius so remediation decisions reflect real risk, not just scanner output.

Q: Why do privileged identities change vulnerability management decisions?

A: Privileged identities turn a technical weakness into a viable breach path. If a reachable vulnerability sits near service accounts, admin roles, or delegated access, the attacker’s payoff rises sharply. Teams should therefore evaluate vulnerabilities in the context of the identities and permissions they can expose, not as isolated host findings.

Q: What do teams get wrong about third-party exposure?

A: They often treat vendor access as a procurement issue instead of an ongoing security control. Third-party identities, OAuth links, and cloud permissions can create direct attack paths, so they need the same lifecycle, least-privilege, and offboarding discipline as internal access.

Q: How do organisations know if indirect exposure monitoring is actually working?

A: They should test whether suspicious multi-hop flows generate alerts early enough to support investigation before funds are dispersed. A working control has coherent thresholds, consistent category treatment, and reliable entity attribution. If alerts only appear after value has already moved through several layers, the monitoring programme is late rather than effective.


Technical breakdown

Why exploitability now outranks severity

A vulnerability with a high severity score is not automatically the most dangerous issue in an enterprise environment. Exploitability depends on whether attack code exists, whether the asset is reachable, whether mitigations are in place, and whether the system sits on a path to privileged access or sensitive data. That is why modern prioritisation has to combine scanner output, threat intelligence, exposure context, and business criticality. In practice, a lower-scored but actively exploited weakness on an internet-facing asset can matter far more than a critical finding buried behind multiple layers of control.

Practical implication: rank remediation by exploitability and reachability, not by CVSS alone.

How exposure management changes the remediation model

Exposure management treats remediation as a decision problem, not a backlog problem. The goal is to reduce the most exploitable and business-relevant attack paths first, which requires ownership data, asset context, identity context, and knowledge of how systems connect. This is especially important where service accounts, remote access, OAuth links, and cloud permissions create indirect paths into critical systems. For identity teams, the lesson is that access and privilege are part of exposure, not a separate layer of governance that can be reviewed later.

Practical implication: tie remediation queues to owners, reachability, and privilege paths so fixes reduce attack-path risk.

Third-party exposure is now part of the attack surface

The DBIR’s third-party findings underline that exposure no longer ends at the perimeter of owned infrastructure. SaaS providers, cloud integrations, vendors, and managed services can all introduce reachable paths through credentials, permissions, tokens, or misconfigurations. When those relationships are connected to identity systems, the governance problem widens further because offboarding, least privilege, and credential lifecycle controls become shared responsibilities. This is where IAM and NHI controls directly affect external exposure rather than just internal administration.

Practical implication: include third-party identities, tokens, and delegated access in exposure reviews and offboarding controls.


Threat narrative

Attacker objective: The attacker’s objective is to turn one reachable weakness into reliable access to high-value systems or data.

  1. Entry occurs when attackers exploit an exposed vulnerability or abuse reachable third-party access to gain an initial foothold in the environment.
  2. Escalation follows through credential abuse, excessive permissions, or weak privilege boundaries that let the attacker move from low-level access toward administrative control.
  3. Impact comes from using that access path to reach critical systems, deploy ransomware, or exfiltrate data after the exposure has already been converted into an attack path.

NHI Mgmt Group analysis

Exposure management is now an identity problem as much as a vulnerability problem. The DBIR shows that exploitable weaknesses are only one part of the path attackers use. Once initial access exists, the next controls that matter are privilege scope, credential lifecycle, and third-party trust boundaries. That is why NHI governance and PAM now sit inside exposure management rather than beside it. Practitioners should treat access paths as part of remediation, not as a separate review cycle.

Over-reliance on severity creates remediation debt. CVSS still has value, but it does not tell teams whether an issue is reachable, weaponised, or tied to a privileged identity. Exposure management is the better operating model because it collapses the gap between what is technically vulnerable and what is actually exploitable in context. Exposure triage debt: this is the growing backlog created when teams know the finding exists but cannot decide which exposed path to remove first. Security leaders should measure how quickly they convert visibility into risk reduction.

Third-party relationships are now part of the control plane. The report’s third-party findings point to a simple reality: delegated access, SaaS integrations, and vendor-hosted data create attack paths that traditional asset inventories miss. That makes identity governance for external access a core exposure-management function, not a procurement afterthought. Teams should re-evaluate whether OAuth connections, service accounts, and partner permissions are governed with the same rigor as internal privileged access.

Patch velocity is not the same as exposure reduction. Verizon’s data shows many organisations cannot patch fast enough to outpace attacker use, which means the useful question is which exposures reduce the most real-world attack potential when fixed. That shifts the discipline from queue management to attack-path interruption. Practitioners should align vulnerability workflows with reachability, privilege, and business impact so remediation effort changes the breach probability, not just the ticket count.

Identity context turns exposure from a technical issue into a governance issue. When a vulnerability sits on a system that also hosts service credentials, federated access, or privileged automation, the blast radius expands beyond the asset itself. That is where NHI visibility, least privilege, and lifecycle controls become decisive. Teams that can map vulnerability data to identity paths will reduce exposure more effectively than teams that treat identities and weaknesses as separate programmes.

What this signals

Exposure management will increasingly merge vulnerability workflows with identity governance, because the attack path is rarely a host issue alone. Security leaders should expect remediation programmes to become more cross-functional, with IAM, PAM, cloud, and application owners sharing responsibility for reducing reachable risk. The teams that can connect exploitability to privilege will make better decisions than teams that still treat scans as isolated task lists.

Attack-path triage: this is the operational shift organisations now need, where the question is not how many findings exist but which findings sit on a usable route to high-value access. That requires measuring reachability, delegated access, and business impact together. For practitioners building out this model, the 52 NHI Breaches Analysis is useful because it shows how identity weaknesses become breach paths in the real world.


For practitioners

  • Build exposure prioritisation around attack paths Rank vulnerabilities by exploitability, reachability, and the privilege or data paths they open, then route the highest-risk items to the correct asset and identity owners first.
  • Include identities in remediation queues Add service accounts, API keys, OAuth grants, and privileged accounts to the same remediation workflow as host and application findings so access paths are fixed alongside the vulnerable asset.
  • Track third-party access as exposure Inventory vendor-connected identities and delegated permissions, then review them for least privilege, offboarding gaps, and credential lifecycle issues whenever a new exposure is discovered.
  • Measure time-to-risk-reduction, not ticket closure Use metrics that show how quickly a finding is removed from an exploitable path, rather than how quickly the ticket is closed, so remediation reflects actual attack-path reduction.

Key takeaways

  • Vulnerability exploitation has become the leading breach entry point, which makes severity-only triage too narrow for modern attack paths.
  • The remediation gap is measurable, with most organisations still leaving known exploited vulnerabilities open long enough for attackers to act.
  • Exposure management works only when vulnerability data, identity paths, third-party access, and business impact are prioritised together.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack surface, NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, and ISO/IEC 27001:2022 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKTA0001 , Initial Access; TA0006 , Credential Access; TA0008 , Lateral MovementThe article focuses on attack paths that begin with exploitation and continue through privilege and movement.
NIST CSF 2.0ID.RA-1Risk identification and prioritisation are central to the exposure-management argument.
NIST SP 800-53 Rev 5RA-5Vulnerability monitoring and scoring underpin the article’s remediation discussion.
CIS Controls v8CIS-7 , Continuous Vulnerability ManagementThe article directly addresses the limitations of vulnerability-only programmes.
ISO/IEC 27001:2022A.8.8Technical vulnerability management is a direct fit for the article’s remediation focus.

Map high-risk exposures to initial access and lateral movement tactics, then prioritise controls that break the path early.


Key terms

  • Exposure management: Exposure management is the practice of identifying which assets are reachable by attackers and reducing that reach before exploitation occurs. For collaboration systems like SharePoint, it is not enough to know that a patch exists, because public accessibility changes the speed and likelihood of attack.
  • Attack path: A sequence of identities, permissions, systems, and data stores that an attacker can traverse after obtaining trusted access. In practice, attack paths matter more than single accounts because they show how a low-risk identity can become a route to high-value exposure.
  • Known Exploited Vulnerability: A Known Exploited Vulnerability is a flaw that has confirmed active exploitation in the wild and is tracked for urgent remediation. In governance terms, KEV status turns patching from a general hygiene task into a time-bound operational obligation.
  • Third-Party Credential Exposure: Third-party credential exposure is the condition where vendor, contractor, or partner credentials appear in breach data, malware logs, or other compromise sources. In practice, the risk is not just theft, but the fact that the account may still be valid and trusted across connected systems.

What's in the full article

Nucleus’s full article covers the operational detail this post intentionally leaves for the source:

  • The DBIR findings and page-level evidence behind the 31% initial-access shift and the remediation timing data.
  • The survival-analysis detail on how long KEV vulnerabilities remain open after detection across large datasets.
  • The third-party exposure breakdown, including cloud authentication and permission misconfiguration findings.
  • The reasoning Nucleus uses to translate vulnerability data into exposure-management decision models.

👉 The full Nucleus post unpacks the DBIR data, third-party exposure findings, and remediation implications in more detail.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management in a way that supports broader identity programmes. It helps practitioners connect identity lifecycle controls to the wider security decisions their teams already make.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 1, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org