TL;DR: A U.S. manufacturer cut remediation from weeks to hours, reduced exposures from High to Medium in 40 days, eliminated 94 attack paths, and standardised weekly internal and external testing after moving beyond patching to continuous validation, according to Horizon3.ai. The shift shows that proving exposure is closed, not just patched, is now the operational test that matters.
NHIMG editorial — based on content published by Horizons.ai: From Patch Tuesday to Pentest Wednesday®: Proof That Redefined Security for a Manufacturer
By the numbers:
- The manufacturer reduced exposures from High to Medium in 40 days at a key site.
- The team eliminated 94 exploitable attack paths.
- The manufacturer achieved a 100% reduction in network-level compromise scenarios.
Questions worth separating out
Q: What breaks when patching is done without exploitability validation?
A: Patching without exploitability validation breaks the assumption that a vulnerability is actually closed.
Q: Why do manufacturing environments need continuous validation more than annual pentests?
A: Manufacturing environments accumulate risk through acquisitions, ageing infrastructure, and long-lived services that change between scheduled tests.
Q: How do teams know if a vulnerability is truly exploitable?
A: They validate it in the live environment using safe testing that shows whether an attacker can reach the condition, trigger it, and move beyond it.
Practitioner guidance
- Tie remediation to verified retesting Require a retest after every critical patch, especially for internet-facing services and inherited systems, so the team can confirm the exposure is actually closed.
- Map attack paths across identity and network layers Use offensive validation to trace how exposed services, Active Directory relationships, and privileged routes connect into a full compromise path.
- Prioritise KEV-driven validation windows Treat known exploited vulnerabilities as immediate testing triggers, not just patch queue items, and validate the fix before adversaries can sweep the environment.
What's in the full article
Horizons.ai's full blog covers the operational detail this post intentionally leaves for the source:
- Step-by-step examples of how Rapid Response testing was used to validate a Citrix exposure before broad weaponisation.
- Operational detail on how weekly internal and external testing was standardised across inherited environments and acquisitions.
- Specific examples of NodeZero Tripwires placement and the attacker behaviours they were designed to surface.
- Details on how vulnerability findings were tied to business impact through the Vulnerability Management Hub.
👉 Read Horizons.ai's post on continuous validation for critical vulnerability remediation →
Patch validation in manufacturing: are your controls keeping up?
Explore further
Patching without proof creates remediation theatre: the organisation may believe risk has been reduced while the attack path remains viable. Continuous validation closes that gap by testing whether the fix actually changes attacker reachability in the production environment. For identity and access teams, that means remediation must be measured by path elimination, not ticket closure. The practical conclusion is that verified exposure closure belongs in the security operating model.
A few things that frame the scale:
- 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
- Lack of credential rotation is cited as the top cause of NHI-related attacks by 45% of organisations, according to The State of Non-Human Identity Security.
A question worth separating out:
Q: Who is accountable when a patched application is still exploitable in production?
A: Accountability sits with the owners of the application, the security team setting prioritisation, and the business leaders who accept residual risk while manual fixes are pending. For regulated or high-value environments, the governance question is whether exposure windows were tracked and escalated fast enough to prevent unauthorized execution and data theft.
👉 Read our full editorial: Why patching without validation still leaves manufacturers exposed