Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Pentests are missing the exposure gap between assessments


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19563
Topic starter  

TL;DR: The exposure window between assessments is shrinking as asset change and new attack paths emerge faster than manual testing can keep up, according to Hadrian. The practical issue is not whether pentests still matter, but whether they can support continuous exposure management in modern environments.

NHIMG editorial — based on content published by Hadrian: Six Months Later: The Vulnerability Window Is Collapsing

Questions worth separating out

Q: How should security teams handle exposure risk between penetration tests?

A: They should treat exposure as a continuous condition, not a quarterly event.

Q: Why do standing privileges make exposure gaps more dangerous?

A: Standing privileges turn a small technical issue into a broader compromise path because the attacker does not need to win authorization again after finding the entry point.

Q: How do you know if continuous exposure testing is actually working?

A: Look for shorter time to discovery, fewer high-risk findings that persist across test cycles, and faster handoff from detection to remediation.

Practitioner guidance

  • Measure the exposure window, not just the vulnerability count. Track the time between asset change, vulnerability discovery, and remediation closure so you can see where risk accumulates between assessments.
  • Correlate pentest findings with identity and secret ownership. Require each exploitable finding to map to an owner for access, privilege, or secret remediation, not only to an infrastructure team.
  • Increase validation cadence for high-churn assets. Run continuous or near-continuous exposure checks on cloud workloads, externally reachable services, and any system that changes frequently.

What's in the full article

Hadrian's full blog covers the operational detail this post intentionally leaves for the source:

  • How the agentic-powered testing workflow prioritises findings across changing assets and services
  • What the platform does differently for continuous exposure monitoring and automated validation
  • Examples of how high-risk risks are surfaced and triaged for remediation teams
  • The practical scan and reporting flow that supports faster reassessment after environment changes

👉 Read Hadrian's analysis of the collapsing vulnerability window and agentic pentesting →

Pentests are missing the exposure gap between assessments?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19154
 

Continuous exposure management is replacing the old pentest-only mindset. The article reflects a broader market shift: organisations are realising that point-in-time validation cannot keep pace with continuous change. That does not diminish pentesting, but it changes its role from primary assurance mechanism to one component of a live exposure programme. For identity teams, the lesson is clear: access drift and secret drift now matter as much as software drift, so exposure measurement must include IAM and NHI state.

A question worth separating out:

Q: Who should own remediation when ethical hackers find identity-related weaknesses?

A: The security team should coordinate, but ownership should land with the control domain that failed. For access and secrets issues, that usually means IAM, platform, or application owners working from a defined remediation path. Clear accountability prevents external findings from becoming long-lived backlog items.

👉 Read our full editorial: The vulnerability window is collapsing between pentests and real risk



   
ReplyQuote
Share: