Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

External attack surface blind spots: what IAM teams should notice


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18936
Topic starter  

TL;DR: External attack surface management breaks when organisations rely on known inventories and manual testing, because the highest-risk assets are often the ones no one can see, according to CYCOGNITO and its conversation with Richard Stiennon of IT-Harvest. Mean time to remediation is now the decisive variable, and AI is compressing attacker timelines faster than current discovery and response models can keep up.

NHIMG editorial — based on content published by CYCOGNITO: External attack surface blind spots and AI-driven exposure risk in conversation with Richard Stiennon

By the numbers:

  • When AWS credentials are exposed publicly, attackers attempt access within an average of 17 minutes and as quickly as 9 minutes in some cases.
  • 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems, inappropriately sharing sensitive data, and revealing access credentials.

Questions worth separating out

Q: How should security teams manage unknown internet-facing assets?

A: Security teams should treat unknown internet-facing assets as governance exceptions, not just missing inventory.

Q: Why do blind spots create more risk than known vulnerabilities?

A: Blind spots create more risk because defenders can only prioritise what they know exists.

Q: How do you know if attack surface management is actually working?

A: Look for fewer unknown internet-facing assets, faster detection of newly exposed services, and clearer ownership for public endpoints.

Practitioner guidance

  • Measure exposure by remediation speed, not inventory size. Track mean time to remediation for critical external exposures and separate it from general vulnerability ageing.
  • Create an owner-resolved asset exception process. Any internet-facing asset that cannot be tied to a business owner, technical owner, and remediation path within the same workflow should be treated as an exposure exception rather than a discovery success.
  • Map external assets to identity-bearing dependencies. For each exposed application or service, identify the service accounts, API keys, tokens, and delegated access paths that make it reachable, then route those dependencies into identity governance and rotation reviews.

What's in the full article

CYCOGNITO's full article covers the operational detail this post intentionally leaves for the source:

  • The video discussion on how external attack surface discovery differs from vulnerability scanning in practice.
  • The conversation on AI-driven testing approaches for scale, including how creative testing changes exposure validation.
  • The guidance on measuring mean time to remediation for critical issues and using it as a leadership metric.
  • The full transcript context around blind spots in subsidiaries, third parties, and internet-facing assets.

👉 Read CYCOGNITO's full discussion on external attack surface management and AI-driven exposure risk →

External attack surface blind spots: what IAM teams should notice?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 18527
 

External exposure is now an identity problem as much as a scanning problem: internet-facing assets are often governed by secrets, service accounts, and delegated access paths that sit outside standard access review. That means the organisation can be technically visible and still operationally blind. IAM, PAM, and NHI governance all depend on asset ownership being known before entitlement risk can be managed. The practitioner conclusion is simple: unknown assets are unmanaged identities in disguise.

A question worth separating out:

Q: Who is accountable when an exposed asset becomes the entry point for a breach?

A: Accountability should sit with the team that owns the asset and the control function that governs its exposure, which often includes cloud, application, and identity owners together. In practice, frameworks like the NIST Cybersecurity Framework and NHI governance expect clear ownership, because unresolved exposure is a governance failure as much as a technical one.

👉 Read our full editorial: External attack surface blind spots are outpacing remediation



   
ReplyQuote
Share: