Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Context-driven exposure management: are your controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Security teams still lose to simple exposures even with more telemetry, because knowing a vulnerability exists is not the same as knowing what is business-critical, who can fix it, and what the blast radius is, according to Tonic and cited research including Verizon DBIR and Mandiant M-Trends. The shift is from static findings to continuously evaluated, context-rich exposure decisions that security can defend and IT can actually execute.

NHIMG editorial — based on content published by Tonic: context-driven exposure management and the move from the Department of No to the Department of Know

By the numbers:

Questions worth separating out

Q: How should security teams prioritise exposures when asset inventories are incomplete?

A: They should prioritise by exploitability, reachability, and business impact rather than by inventory completeness alone.

Q: Why do vulnerabilities become identity risks so quickly in modern environments?

A: Because many systems do not just process data, they also carry credentials, tokens, certificates, and service accounts that control other systems.

Q: What do security teams get wrong about false positives in exposure management?

A: They often treat false positives as a scanning problem instead of a decision problem.

Practitioner guidance

  • Build attack-path based prioritisation Rank exposures by the shortest path they create to critical systems, sensitive data, or privileged identities.
  • Fuse identity and exposure telemetry Correlate IAM, asset, cloud, and vulnerability data in one workflow so you can see which identities can reach which assets and through what dependencies.
  • Define ownership at the point of prioritisation Attach each high-risk exposure to a named owner, a remediation option set, and the operational tradeoff before the ticket is issued.

What's in the full article

Tonic's full article covers the operational detail this post intentionally leaves for the source:

  • How the exposure management workflow translates fragmented telemetry into a prioritised remediation queue.
  • The practical distinctions between inventory, exposure, exploitability, and business-criticality in live operations.
  • Why agentic systems are being used to maintain continuously updated risk context across changing environments.
  • The decision model for assigning owners and remediation tradeoffs to high-impact exposures.

👉 Read Tonic's analysis of context-driven exposure management and the Department of Know →

Context-driven exposure management: are your controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Context-driven exposure management is really identity-aware exposure management. The article is framed around vulnerabilities, but the practical risk is often created by identities that define what is reachable and what can be abused. Service accounts, API connections, and privileged access paths turn technical issues into exploitable business exposure. For identity teams, the lesson is that exposure triage must include privilege and reachability, not just asset severity.

A question worth separating out:

Q: Which frameworks support contextual exposure prioritisation?

A: NIST CSF and NIST SP 800-53 both support context-based risk decisions, while identity-heavy exposure paths often map well to OWASP NHI guidance and Zero Trust principles. The key is to translate the framework into operational prioritisation, ownership, and continuous reassessment instead of treating it as a reporting exercise.

👉 Read our full editorial: Context-driven exposure management is replacing blunt security decisions



   
ReplyQuote
Share: