Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security What should teams do first when their cybersecurity…
Cyber Security

What should teams do first when their cybersecurity programme is behind the threat landscape?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 20, 2026 Domain: Cyber Security

Teams should start by mapping their risk profile and identifying the most likely paths an attacker would use. From there, prioritize employee training on phishing, increase testing of exposed weaknesses, and seek specialist help for gaps that internal teams cannot close quickly. The first goal is to reduce the most obvious exposure while building a repeatable security improvement process.

Start with the attack paths that are most likely to matter

When a programme is behind the threat landscape, the first move is to narrow the problem to the paths an attacker would most likely use, not the controls the team most wants to improve. That means identifying exposed entry points, weak authentication points, overprivileged access, and the systems whose compromise would create the widest blast radius. The point is to make risk reduction concrete and sequenced.

This is why a risk profile is more useful than a generic backlog. It tells teams where the environment is most exposed today, which weaknesses are most likely to be exploited next, and which gaps deserve immediate work even if they are not the oldest issues on the list. A focused view also prevents teams from spending scarce effort on low-consequence items while material exposures remain open.

For a practical benchmark on where attacker leverage often concentrates, NHIMG’s Ultimate Guide to Non-Human Identities notes that 97% of NHIs carry excessive privileges, 96% of organisations store secrets outside secrets managers, and only 5.7% have full visibility into their service accounts. Those figures are not a substitute for local assessment, but they do show why privilege, secret handling, and visibility usually belong near the top of the first-pass review.

Reduce obvious exposure before trying to solve everything

Once the most likely attack paths are mapped, the next priority is to remove the easiest wins for an adversary. In practice, that usually means tightening phishing resistance, closing exposed weaknesses with the highest exploitation likelihood, and fixing anything that gives an attacker immediate foothold or persistence. If the team cannot close a gap quickly, it should at least reduce reachability, privilege, or exposure while the longer fix is being built.

Training matters here, but only when it is tied to the actual exposure profile. If phishing is a likely path, training should reinforce the behaviours that block credential theft and suspicious approval flows. If exposed services or known weaknesses are the problem, testing and remediation should be driven by whether the issue is externally reachable and exploitable, not by whether it looks severe in the abstract.

That same logic appears in the broader threat landscape guidance from ENISA Threat Landscape and the CISA Known Exploited Vulnerabilities Catalog, which both support prioritising what is actively dangerous or credibly exploitable over what is merely present. For teams that need an operational severity signal, FIRST EPSS helps estimate exploitation likelihood, while FIRST CVSS is better used as a severity input than as the sole prioritisation rule.

Build a repeatable improvement loop, not a one-time cleanup

The real goal is not to close every gap at once. It is to create a durable sequence: identify the most likely attack paths, fix the highest-risk exposures, verify the control improvement, and then repeat. That cycle matters because a programme that is already behind usually cannot catch up by working issue-by-issue without a stable method for prioritisation, validation, and escalation.

Teams should also treat specialist help as part of the process, not as a failure condition. If the internal team cannot close a gap quickly enough, bring in outside support for the work that materially reduces exposure, especially where the issue affects identity, access, or exposed attack surface and needs fast remediation. Good governance here means knowing what must be owned internally, what can be outsourced, and what should be escalated because the residual exposure is too high.

Practitioner takeaway: The first useful move is not broad remediation, it is disciplined triage around the attacker paths most likely to succeed, followed by rapid reduction of the exposures that give those paths real leverage.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM — Risk Management StrategyThe question is about prioritising action based on the programme's threat exposure.
ID.RA — Risk AssessmentMapping the risk profile is the first step in this question.
PR.AC — Identity Management, Authentication and Access ControlExcessive access and obvious exposure are central to the recommended first-pass reduction.
Recommendation — Use risk-based prioritisation to sequence remediation around the most likely attacker paths. Assess and rank exposures by likelihood and impact before setting the next remediation wave. Tighten access controls where excessive privilege expands the blast radius of compromise.
CIS Controls v87 — Continuous Vulnerability ManagementThe answer emphasises testing and fixing exposed weaknesses first.
14 — Security Awareness and Skills TrainingPhishing training is a stated early action for reducing attacker success.
6 — Access Control ManagementThe answer prioritises reducing privileged exposure and reachability.
Recommendation — Prioritise active vulnerability discovery and remediation for externally exposed weaknesses. Target awareness training at phishing behaviours that most often enable initial compromise. Review and reduce access paths that give attackers immediate foothold or lateral movement.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 20, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org