Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Exposure management is replacing patch-only thinking: what teams should act on


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 13010
Topic starter  

TL;DR: The 2026 Verizon DBIR shows exploitation of vulnerabilities rose to 31% of initial access while credential abuse fell to 13%, and only 26% of CISA Known Exploited Vulnerabilities were fully remediated in 2025, according to Verizon. The message is clear: prioritisation must shift from severity-first vulnerability management to exposure management that accounts for exploitability, reachability, ownership, and business impact.

NHIMG editorial — based on content published by Nucleus: analysis of the 2026 Verizon DBIR and the move from vulnerability management to exposure management

By the numbers:

Questions worth separating out

Q: How should security teams prioritise vulnerabilities when remediation capacity is limited?

A: Prioritise by exposure, business criticality, and the identities attached to the affected asset.

Q: Why do privileged identities change vulnerability management decisions?

A: Privileged identities turn a technical weakness into a viable breach path.

Q: What do teams get wrong about third-party exposure?

A: They often treat vendor access as a procurement issue instead of an ongoing security control.

Practitioner guidance

  • Build exposure prioritisation around attack paths Rank vulnerabilities by exploitability, reachability, and the privilege or data paths they open, then route the highest-risk items to the correct asset and identity owners first.
  • Include identities in remediation queues Add service accounts, API keys, OAuth grants, and privileged accounts to the same remediation workflow as host and application findings so access paths are fixed alongside the vulnerable asset.
  • Track third-party access as exposure Inventory vendor-connected identities and delegated permissions, then review them for least privilege, offboarding gaps, and credential lifecycle issues whenever a new exposure is discovered.

What's in the full article

Nucleus’s full article covers the operational detail this post intentionally leaves for the source:

  • The DBIR findings and page-level evidence behind the 31% initial-access shift and the remediation timing data.
  • The survival-analysis detail on how long KEV vulnerabilities remain open after detection across large datasets.
  • The third-party exposure breakdown, including cloud authentication and permission misconfiguration findings.
  • The reasoning Nucleus uses to translate vulnerability data into exposure-management decision models.

👉 Read Nucleus’s analysis of the 2026 DBIR shift from vulnerability management to exposure management →

Exposure management is replacing patch-only thinking: what teams should act on?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 12594
 

Exposure management is now an identity problem as much as a vulnerability problem. The DBIR shows that exploitable weaknesses are only one part of the path attackers use. Once initial access exists, the next controls that matter are privilege scope, credential lifecycle, and third-party trust boundaries. That is why NHI governance and PAM now sit inside exposure management rather than beside it. Practitioners should treat access paths as part of remediation, not as a separate review cycle.

A question worth separating out:

Q: How do organisations know if indirect exposure monitoring is actually working?

A: They should test whether suspicious multi-hop flows generate alerts early enough to support investigation before funds are dispersed. A working control has coherent thresholds, consistent category treatment, and reliable entity attribution. If alerts only appear after value has already moved through several layers, the monitoring programme is late rather than effective.

👉 Read our full editorial: Exposure management overtakes vulnerability management in breach paths



   
ReplyQuote
Share: