TL;DR: Continuous validation helped a distributed equipment rental company replace point-in-time pentests to uncover exploitable exposure faster, validate an SSH key leak within eight hours, and turn suspected Cisco weakness and Active Directory password issues into measurable remediation, according to Horizons.ai. The practical lesson is that exposure management now depends on evidence, retesting, and identity control changes, not assessment cadence alone.
NHIMG editorial — based on content published by Horizons.ai: Patch Tuesday to Pentest Wednesday: How an Equipment Rental Company Is Turning Continuous Testing Into Continuous Exposure Management
By the numbers:
- More findings in 12 hours than a third-party engagement found in roughly 30 days.
Questions worth separating out
Q: How should security teams handle continuous exposure management when environments change daily?
A: Security teams should use continuous validation to supplement scheduled testing, because point-in-time assessments quickly become stale in dynamic environments.
A: Weak passwords and poor hygiene increase the chance that attackers can guess, reuse, or steal credentials and then move into other systems.
Q: What are the signs that exposure management is still too reactive?
A: The clearest signs are when teams only learn about risk during a pentest, struggle to track asset and configuration changes, and spend time chasing low-value findings.
Practitioner guidance
- Build continuous validation into exposure management Use ongoing testing to confirm whether newly introduced changes create real attack paths, then feed the results into your CTEM pipeline and remediation workflow.
- Treat SSH keys and password policy as attack-surface controls Review exposed keys, weak credential patterns, and reset workflows together so identity material is governed as part of the live attack surface, not a separate admin task.
- Retest after every high-risk identity change Revalidate after password policy changes, service-desk process updates, or credential remediation so you can prove the exposure has actually been reduced.
What's in the full article
Horizons.ai's full blog covers the operational detail this post intentionally leaves for the source:
- How the CTEM attack surface management pipeline ingests telemetry into Splunk and uses it operationally
- What the team saw in the SSH key exposure case and how the evidence was validated over time
- The remediation workflow behind the Active Directory password changes and later retesting
- How the Cisco IOS XE validation translated into remediation and mitigation decisions
👉 Read Horizons.ai's blog on continuous exposure management and CTEM →
Continuous exposure management: are your controls keeping up?
Explore further
Continuous exposure management is becoming an identity governance problem, not just a scanning problem. The article shows that password policy, SSH keys, and service-desk handling can create attack paths faster than periodic review can catch them. For IAM and PAM teams, the relevant question is no longer whether access exists, but whether the organisation can prove when it became risky and when it was reduced. That is a governance shift from static review to continuous validation.
A few things that frame the scale:
- The average estimated time to remediate a leaked secret is 27 days, despite 75% of organisations expressing strong confidence in their secrets management capabilities, according to The State of Secrets in AppSec.
- Organisations maintain an average of 6 distinct secrets manager instances, creating fragmentation that undermines centralised control, according to The State of Secrets in AppSec.
A question worth separating out:
Q: How do IAM and PAM teams fit into exposure management programmes?
A: IAM and PAM teams should own the access-side exposure signals, including password policy, reset workflows, credential lifecycle, and privileged authentication paths. Those controls often determine whether a weakness becomes exploitable. The right model is shared ownership, where security testing validates access risk and identity teams drive the changes that remove it.
👉 Read our full editorial: Continuous exposure management needs evidence, not periodic pentests