Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Between-reports visibility: what security teams are missing now


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 17031
Topic starter  

TL;DR: Security teams can still miss what attackers are exploring between confirmed scans and reports because scanners see surfaces, not intent, according to INTIGRITI. As AI compresses discovery and exploitation timelines, the gap between documented scope and what is actually exposed becomes a governance problem, not just a tooling problem.

NHIMG editorial — based on content published by INTIGRITI: The between-reports problem and why security teams miss what attackers see

By the numbers:

  • Lack of credential rotation is cited as the top cause of NHI-related attacks by 45% of organisations, ahead of inadequate monitoring and logging at 37% and over-privileged accounts at 37%.

Questions worth separating out

Q: What breaks when security teams rely only on scanning and pre-runtime checks?

A: Scanning and pre-runtime checks can identify weaknesses, but they do not stop a live AI-driven attack once execution begins.

Q: Why do external exposure and identity trust need to be reviewed together?

A: Because many real-world exposure paths are created by trust relationships, not just by open services.

Q: How do teams know if between-reports visibility is improving?

A: Look for earlier, more specific investigation triggers, not just more alerts.

Practitioner guidance

  • Implement pre-report signal collection Add sources that capture exploration patterns, repeated probing, and weak external signals before a finding is confirmed.
  • Reconcile identity trust with exposed assets Review OAuth connections, SSO boundaries, service accounts, and externally reachable admin paths in the same workflow as asset ownership.
  • Shorten escalation paths for weak signals Define what constitutes an actionable pre-confirmation signal and who must respond before the next report cycle.

What's in the full article

INTIGRITI's full article covers the operational detail this post intentionally leaves for the source:

  • How the vendor defines between-reports visibility in practical operational terms
  • Examples of earlier signal layers that security teams can use before the next confirmed report
  • The product and workflow context behind proof-safe investigation signals
  • The follow-on direction the vendor says it is taking next for reporting and visibility

👉 Read INTIGRITI's analysis of the between-reports visibility gap →

Between-reports visibility: what security teams are missing now?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 16230
 

Between-reports visibility is now a governance gap, not a tooling gap. Security teams have invested heavily in scans, inventories, and dashboards, yet attackers still operate in the interval between confirmed outputs. That interval is where intent, repetition, and weak signals accumulate before a formal finding exists. The practical conclusion is that exposure management must account for pre-report exploration, not just confirmed vulnerabilities.

A question worth separating out:

Q: Who is accountable when exposure drifts between reporting cycles?

A: Accountability should sit with the owners of the asset, the identity trust relationship, and the response process that turns weak signals into action. Frameworks such as NIST CSF and NIST SP 800-53 support that accountability model because they tie monitoring, access control, and response together instead of treating them as isolated tasks.

👉 Read our full editorial: Between-reports visibility is becoming the new security gap



   
ReplyQuote
Share: