By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: NucleusPublished December 15, 2025

TL;DR: Cisco’s end-of-life for Kenna underscores a broader shift: security teams now face cloud misconfigurations, identity exposures, vendor risk, and app vulnerabilities in one expanding attack surface, according to Nucleus. The decisive challenge is no longer counting issues but operationalising continuous prioritisation and remediation across the full exposure graph.


At a glance

What this is: This is a perspective piece arguing that exposure management has replaced vulnerability management as the strategic security program, with identity, cloud, and third-party exposure now central to prioritisation.

Why it matters: It matters because IAM, NHI, and platform security teams increasingly need shared context for identity exposures, privileged access, and remediation workflows rather than separate point tools and static backlogs.

By the numbers:

👉 Read Nucleus's perspective on why exposure management replaces vulnerability management


Context

Exposure management begins where traditional vulnerability management stops. Once security teams must account for misconfigurations, identity exposures, third-party access, and continuously changing cloud estates, raw vulnerability counts no longer describe the real risk picture. The article’s central claim is that prioritisation has become the programme, not just a step inside it, and that matters directly for identity governance because identity exposures often determine whether technical flaws become reachable.

The identity angle is genuine, not incidental. Identity exposures, service account sprawl, over-privileged access, and third-party connectivity now sit alongside CVEs as enterprise exposure drivers. That means IAM, PAM, and NHI governance can no longer operate as isolated control planes if the security programme is meant to reduce exposure rather than merely report it.


Key questions

Q: What fails when teams rank exposure only by vulnerability severity?

A: Severity-only ranking misses whether a weakness is actually reachable through identity, configuration, or external access. The result is a backlog that looks disciplined but still leaves exploitable paths open. Security teams need to add permission context, asset criticality, and business exposure into prioritisation so that fixes follow attackability, not just scanner output.

Q: Why do identity weaknesses change vulnerability management outcomes?

A: Identity weaknesses change outcomes because attackers rarely need a perfect exploit if they can combine a modest flaw with privilege, delegation, or exposed credentials. That is why IAM, PAM, and NHI controls matter to vulnerability management. They shape whether a defect stays isolated or becomes part of a working attack path.

Q: What do security teams get wrong about exposure management?

A: They often treat it as a reporting layer above vulnerability management instead of a system that changes remediation decisions. If the programme does not route work, track ownership, and verify closure, it produces better dashboards without reducing risk. Exposure management has to operationalise action, not just aggregation.

Q: How should organisations connect remediation with identity governance?

A: They should make identity remediation part of the exposure workflow, not an afterthought. That means privilege reduction, secret rotation, access review, and offboarding checks must be linked to the same remediation queue that handles technical vulnerabilities. When access is the path to impact, governance and remediation need a shared operating model.


Technical breakdown

How exposure management differs from vulnerability management

Vulnerability management focuses on known software flaws and the backlog created by scanning. Exposure management broadens the scope to include anything that increases attack reach: misconfigurations, exposed identities, unsafe third-party connections, and weak remediation orchestration. The technical shift is from point-in-time findings to continuous correlation across assets, identities, threats, and business context. In practice, that means a vulnerable service with no reachable path should not be treated the same as an exposed identity that can be abused immediately. The architecture therefore depends on normalisation, enrichment, and prioritisation across domains rather than scanner output alone.

Practical implication: teams should treat exposure scoring as a cross-domain pipeline, not a vulnerability dashboard.

Why identity exposures change prioritisation outcomes

Identity exposure changes the attackability of almost every other weakness. A patchable flaw may remain low priority until a privileged account, service token, or third-party OAuth grant makes it reachable. That is why modern exposure programmes need identity context alongside asset and vulnerability context. The critical technical point is that reachability is not only network-based; it is also permission-based. If the identity layer is over-permissioned or poorly governed, attackers can convert a medium-severity flaw into a high-confidence path to impact. This is where IAM, PAM, and NHI data become prioritisation inputs rather than separate governance reports.

Practical implication: include privileged identity and token data in remediation triage before ranking exposure work.

What closed-loop remediation means for security operations

Closed-loop remediation means the system does more than identify exposure. It routes work, tracks ownership, validates fixes, and updates risk status when the environment changes. In mature models, this requires integration across security, IT, DevOps, and cloud operations so that the programme can act on exposures in near real time. Without that loop, exposure management becomes another reporting layer. The underlying architecture must therefore support continuous discovery, deduplication, workflow orchestration, and verification of remediation outcomes. That is what separates an operational exposure platform from a prioritisation tool.

Practical implication: measure whether exposure findings reach owners, close, and revalidate, not just whether they are scored.


NHI Mgmt Group analysis

Exposure management is now an identity problem as much as a vulnerability problem. Once attackers can use credentials, tokens, OAuth grants, and over-privileged service accounts to turn technical weaknesses into reachable paths, identity becomes part of exposure math. That changes the operating model for IAM and PAM teams, which can no longer sit outside vulnerability prioritisation. The field should treat identity context as a core input to remediation decisions, not a downstream control report.

Prioritisation without reachability context creates a false sense of control. The article is right to frame raw issue counts as inadequate, because backlog volume says little about exploitability. But the deeper governance issue is that many programmes still prioritise by severity alone, then discover that the real path to impact came through permissions, not the CVE itself. Reachability bias: the tendency to prioritise findings that look severe while missing the identity or access condition that makes them exploitable. Practitioners should tie exposure ranking to reachable identity pathways, not just scanner severity.

The market is moving from reporting systems to action systems. Exposure management only matters if it changes what gets fixed, by whom, and in what order. That pushes vendors and practitioners toward orchestration, ownership, and validation rather than static analytics. For identity governance, the same pattern applies to NHI and human access alike: if a platform cannot close the loop on privilege, secrets, and third-party access, it is not reducing exposure. Practitioners should evaluate whether their programme can execute, not just observe.

Security programmes need a shared control plane for vulnerabilities, identities, and configuration drift. The article’s real insight is that exposures now span multiple operational domains, which makes siloed tooling structurally weak. IAM, cloud, DevOps, and security operations all influence whether a weakness is exploitable. That means exposure management should be measured by how well it correlates those domains into one decision model. Practitioners should build governance around unified context, or else the most dangerous exposure will remain the least visible.

What this signals

Exposure management will increasingly be judged by whether it can see identity paths as clearly as technical flaws. If the programme cannot correlate privileged access, third-party connections, and misconfiguration data, it will continue to overstate control and understate attackability. The practical signal for security leaders is whether remediation decisions are being made from unified context or from separate team-specific backlogs.

Exposure reachability bias: the next governance failure is not missing more vulnerabilities, but missing which ones are reachable through identity. That shifts the focus toward shared operating models across IAM, cloud, and vulnerability teams, with continuous verification as the baseline. The NIST Cybersecurity Framework 2.0 provides a useful way to organise that change across govern, identify, protect, detect, respond, and recover.

For identity programmes, the implication is straightforward: service accounts, OAuth grants, and privileged access are now exposure objects, not just administration artefacts. Teams should expect remediation demand to rise where identity visibility is weak and lifecycle controls are inconsistent. A programme that cannot prove what it owns, who can use it, and when it is removed will struggle to reduce exposure at enterprise scale.


For practitioners

  • Map identity context into exposure prioritisation Feed privileged accounts, service accounts, and OAuth grants into remediation scoring so that reachability reflects permissions as well as technical severity. Use this to elevate exposures that are immediately exploitable through identity pathways. See the NHI Lifecycle Management Guide and NIST Cybersecurity Framework 2.0 for control mapping.
  • Separate counts from risk-bearing exposures Replace backlog reports that only list vulnerabilities with exposure views that correlate asset criticality, exploitability, identity permissions, and external reachability. The goal is to identify what can be used, not merely what exists.
  • Operationalise closed-loop remediation ownership Assign fixes to security, IT, cloud, or DevOps owners inside a workflow that tracks verification, not just ticket creation. Where identity is involved, include secret rotation, privilege reduction, and offboarding checks as part of closure.
  • Build exposure review around third-party and NHI visibility Use the 85% full-visibility gap in OAuth-connected vendors as a governance warning and review where unmanaged external access may be widening your exposure graph. Pair that with lifecycle controls from the NHI Lifecycle Management Guide to reduce hidden access paths.

Key takeaways

  • Exposure management reframes security from counting vulnerabilities to managing every reachable path into the enterprise.
  • Identity exposures matter because permissions, tokens, and third-party access often determine whether a weakness is actually exploitable.
  • The programmes that win will connect prioritisation to closed-loop remediation, not just to better scoring.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5, CIS Controls v8 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-4Identity exposures directly affect whether vulnerabilities are reachable.
NIST SP 800-53 Rev 5AC-6Least privilege determines whether exposed systems are actually reachable.
CIS Controls v8CIS-5 , Account ManagementAccount sprawl and stale access are part of modern exposure management.
NIST AI RMFMANAGEThe article is about operationalising risk into action, which aligns with AI RMF manage functions.

Use MANAGE thinking to build remediation workflows that convert risk insight into action.


Key terms

  • Exposure management: Exposure management is the practice of identifying which assets are reachable by attackers and reducing that reach before exploitation occurs. For collaboration systems like SharePoint, it is not enough to know that a patch exists, because public accessibility changes the speed and likelihood of attack.
  • Reachability analysis: Reachability analysis checks whether a vulnerability can actually be exploited in the application’s real code paths and dependency graph. It helps teams distinguish theoretical findings from issues that an attacker can reach, which makes prioritisation far more accurate for both AppSec and identity risk management.
  • Closed-Loop Remediation: A governance process that does not stop at finding risk. It removes or reduces access, confirms the change in the source systems, and keeps evidence that the risky condition stayed fixed. For NHIs, this is the difference between inventory and actual risk reduction.
  • Identity Exposure Window: An identity exposure window is the period between when a credential or account becomes risky and when governance actually removes or contains it. The longer that window stays open, the more likely attackers can reuse the identity, escalate access, or turn a leak into a breach.

What's in the full article

Nucleus's full article covers the operational detail this post intentionally leaves for the source:

  • How the vendor frames exposure management as an operating model rather than a reporting layer
  • Implementation detail on unifying vulnerability, identity, and configuration signals into one workflow
  • Practical examples of closed-loop remediation and ownership handoffs across security and IT
  • The vendor’s view of how Kenna’s end-of-life shapes the migration path to exposure management

👉 The full Nucleus article expands on the shift from prioritisation theory to exposure operations.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It helps practitioners connect identity lifecycle controls to broader security operations and governance.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org