TL;DR: Exposure management is moving from generic severity scoring to environment-specific validation, with the article arguing that reachability, identity, and compensating controls should decide what gets fixed first rather than theoretical exploitability. That shift matters because it turns backlog reduction into attack-path interruption, not ticket volume management.
NHIMG editorial — based on content published by XM Cyber: Exposure management is shifting from theory to validated risk
By the numbers:
- Only 5.7% of organisations have full visibility into their service accounts.
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface.
- 90% of IT leaders say properly managing NHIs is essential for a successful zero-trust implementation.
Questions worth separating out
Q: How should security teams prioritise exposures when business risk and technical severity conflict?
A: Prioritise by business criticality, exploitability, and attack path, not by severity score alone.
Q: Why do service accounts and other NHIs complicate GRC implementation?
A: NHIs complicate GRC because they often outnumber human accounts, change outside normal HR-driven lifecycle processes, and carry access that is easy to overlook in reviews.
Q: What breaks when organisations still rely on severity-only vulnerability management?
A: They fix the wrong things first.
Practitioner guidance
- Validate exploitability before remediation Build prioritisation workflows that test reachability, privilege gain, and compensating controls before elevating a finding to urgent status.
- Map identity into every exposure path Incorporate service accounts, API keys, tokens, and delegated roles into attack-path modelling so risk reflects the permissions an attacker would inherit after compromise.
- Prioritise choke points over volume Identify the fixes that break multiple attack paths at once, such as removing standing privilege, tightening segmentation, or eliminating exposed secrets from code and pipelines.
What's in the full article
XM Cyber's full article covers the operational detail this post intentionally leaves for the source:
- How the vendor frames reachability and validation inside exposure management workflows.
- The environmental factors the article uses to distinguish theoretical from exploitable risk.
- Examples of how attack paths are prioritised when identity and control context are added.
- The practical differences between generic CVSS-style scoring and environment-specific validation.
👉 Read XM Cyber's analysis of validated exposure management and attack-path prioritisation →
Exposure management and validated risk: are your controls keeping up?
Explore further
Validated exposure is now an identity problem, not just a vulnerability problem. The article’s central argument is correct because exploitability depends on access paths, and access paths are governed by identity, privilege, and control-plane reality. In environments full of service accounts, tokens, and delegated permissions, a generic severity score misses the most important question: can an attacker actually use this weakness here? Practitioners should treat identity reachability as part of exposure management, not a separate IAM concern.
A question worth separating out:
Q: How should security teams measure whether exposure management is actually reducing risk?
A: Measure whether validated attack paths, privileged access paths, and high-risk exposures are being removed, then confirm those fixes with retesting. Counts of alerts or scans only show activity. A useful metric changes when the control state changes, especially for identity-related risk.
👉 Read our full editorial: Exposure management is shifting from theory to validated risk