Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Attack-path control for vulnerability management: are your metrics keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18004
Topic starter  

TL;DR: With over 48,000 CVEs published in 2025 and attackers exploiting them in about 20 hours, Seemplicity argues that vulnerability management now needs AI-driven prioritisation, continuous discovery, and attack-path analysis because scan volume alone no longer reflects real risk. The deciding control is not patch throughput but the ability to reduce exposure paths before adversaries traverse them.

NHIMG editorial — based on content published by Seemplicity: How to Use AI for Vulnerability Management

By the numbers:

Questions worth separating out

Q: How should security teams prioritise vulnerabilities when exploit timelines are shrinking?

A: Prioritisation should combine exploitability, reachability, internet exposure, identity proximity, and business criticality.

Q: Why do vulnerability scans fail to reflect real exposure in modern environments?

A: Because scans are snapshots, while modern environments are dynamic.

Q: What breaks when teams measure patch volume instead of attack-path reduction?

A: Patch volume can rise even when the most dangerous routes remain open.

Practitioner guidance

  • Implement continuous exposure discovery Track ephemeral assets, short-lived environments, and internet-facing changes continuously rather than waiting for the next scan cycle.
  • Prioritise by attack-path reduction Rank remediation work by how much it reduces viable paths to crown-jewel assets, not by how many CVEs it closes.
  • Combine exploitability and context signals Use KEV status, proof-of-concept availability, reachability, and business criticality in the same workflow.

What's in the full article

Seemplicity's full blog covers the operational detail this post intentionally leaves for the source:

  • A practical framework for consolidating vulnerability, asset, and exposure data into one prioritisation workflow
  • Step-by-step guidance for using AI to rank attack paths rather than isolated CVEs
  • Examples of how teams can translate exposure reduction into leadership reporting
  • Metrics that move beyond patch counts toward measurable risk reduction

👉 Read Seemplicity's blog on using AI for vulnerability management →

Attack-path control for vulnerability management: are your metrics keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 17593
 

Exposure-path management is becoming the real unit of vulnerability governance. Counting CVEs no longer tells practitioners which issues can actually be used to reach sensitive assets. The meaningful control question is whether the organisation can see and remove the shortest paths between exposure and impact. That makes path analysis, not backlog size, the governance metric that matters.

A question worth separating out:

Q: How do security teams know if AI is improving vulnerability management?

A: AI is working when it improves decision quality, not just throughput. Look for faster identification of exposed assets, better prioritisation of exploitable findings, and fewer critical paths remaining after remediation. If the output is just a bigger queue processed faster, the programme has not changed.

👉 Read our full editorial: AI-driven vulnerability management needs attack-path control, not more scans



   
ReplyQuote
Share: